./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 8393723b Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 9e826f48819dedbf1a290c3ced69eb835c065ed69febc6d0054f416e73afcb1c --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-8393723 [2022-11-19 06:35:34,146 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-19 06:35:34,148 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-19 06:35:34,186 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-19 06:35:34,194 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-19 06:35:34,196 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-19 06:35:34,197 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-19 06:35:34,203 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-19 06:35:34,210 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-19 06:35:34,211 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-19 06:35:34,212 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-19 06:35:34,214 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-19 06:35:34,215 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-19 06:35:34,220 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-19 06:35:34,221 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-19 06:35:34,226 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-19 06:35:34,227 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-19 06:35:34,228 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-19 06:35:34,237 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-19 06:35:34,239 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-19 06:35:34,241 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-19 06:35:34,244 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-19 06:35:34,246 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-19 06:35:34,248 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-19 06:35:34,254 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-19 06:35:34,261 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-19 06:35:34,261 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-19 06:35:34,263 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-19 06:35:34,263 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-19 06:35:34,264 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-19 06:35:34,267 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-19 06:35:34,268 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-19 06:35:34,269 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-19 06:35:34,270 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-19 06:35:34,272 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-19 06:35:34,272 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-19 06:35:34,273 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-19 06:35:34,273 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-19 06:35:34,274 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-19 06:35:34,275 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-19 06:35:34,276 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-19 06:35:34,277 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-19 06:35:34,308 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-19 06:35:34,309 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-19 06:35:34,309 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-19 06:35:34,309 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-19 06:35:34,310 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-19 06:35:34,311 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-19 06:35:34,311 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-19 06:35:34,311 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-19 06:35:34,312 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-19 06:35:34,312 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-19 06:35:34,312 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-19 06:35:34,313 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-19 06:35:34,313 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-19 06:35:34,313 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-19 06:35:34,314 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-19 06:35:34,314 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-19 06:35:34,315 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-19 06:35:34,315 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-19 06:35:34,316 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-19 06:35:34,316 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-19 06:35:34,317 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-19 06:35:34,317 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-19 06:35:34,317 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-19 06:35:34,318 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-19 06:35:34,318 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-19 06:35:34,318 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-19 06:35:34,319 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-19 06:35:34,319 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-19 06:35:34,319 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-19 06:35:34,320 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-19 06:35:34,320 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-19 06:35:34,321 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-19 06:35:34,321 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 06:35:34,321 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-19 06:35:34,322 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-19 06:35:34,322 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-19 06:35:34,322 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-19 06:35:34,323 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-19 06:35:34,323 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-19 06:35:34,323 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-19 06:35:34,324 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-19 06:35:34,324 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 9e826f48819dedbf1a290c3ced69eb835c065ed69febc6d0054f416e73afcb1c [2022-11-19 06:35:34,602 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-19 06:35:34,628 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-19 06:35:34,642 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-19 06:35:34,643 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-19 06:35:34,644 INFO L275 PluginConnector]: CDTParser initialized [2022-11-19 06:35:34,646 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/../../sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c [2022-11-19 06:35:34,715 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/data/508013211/72745161c588431d9e576f12dc0760da/FLAG6a6fa6f96 [2022-11-19 06:35:35,380 INFO L306 CDTParser]: Found 1 translation units. [2022-11-19 06:35:35,381 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c [2022-11-19 06:35:35,411 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/data/508013211/72745161c588431d9e576f12dc0760da/FLAG6a6fa6f96 [2022-11-19 06:35:35,650 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/data/508013211/72745161c588431d9e576f12dc0760da [2022-11-19 06:35:35,654 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-19 06:35:35,658 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-19 06:35:35,662 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-19 06:35:35,663 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-19 06:35:35,668 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-19 06:35:35,669 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 06:35:35" (1/1) ... [2022-11-19 06:35:35,671 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@63a2d696 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:35, skipping insertion in model container [2022-11-19 06:35:35,672 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 06:35:35" (1/1) ... [2022-11-19 06:35:35,681 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-19 06:35:35,735 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-19 06:35:36,041 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c[13125,13138] [2022-11-19 06:35:36,082 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 06:35:36,099 INFO L203 MainTranslator]: Completed pre-run [2022-11-19 06:35:36,177 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/sv-benchmarks/c/product-lines/minepump_spec5_product55.cil.c[13125,13138] [2022-11-19 06:35:36,211 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 06:35:36,249 INFO L208 MainTranslator]: Completed translation [2022-11-19 06:35:36,250 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36 WrapperNode [2022-11-19 06:35:36,250 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-19 06:35:36,252 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-19 06:35:36,252 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-19 06:35:36,252 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-19 06:35:36,261 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,278 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,308 INFO L138 Inliner]: procedures = 59, calls = 107, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 235 [2022-11-19 06:35:36,309 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-19 06:35:36,310 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-19 06:35:36,310 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-19 06:35:36,310 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-19 06:35:36,321 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,321 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,325 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,325 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,333 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,339 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,341 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,343 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,346 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-19 06:35:36,347 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-19 06:35:36,347 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-19 06:35:36,348 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-19 06:35:36,349 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (1/1) ... [2022-11-19 06:35:36,356 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 06:35:36,370 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:35:36,386 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-19 06:35:36,415 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-19 06:35:36,447 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-19 06:35:36,447 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-19 06:35:36,447 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-19 06:35:36,448 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-19 06:35:36,448 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-19 06:35:36,448 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-19 06:35:36,448 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-19 06:35:36,448 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:35:36,448 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:35:36,449 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-19 06:35:36,449 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-19 06:35:36,449 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-19 06:35:36,449 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2022-11-19 06:35:36,449 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-19 06:35:36,449 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-19 06:35:36,449 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-19 06:35:36,450 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-19 06:35:36,450 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-19 06:35:36,450 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-19 06:35:36,450 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-19 06:35:36,450 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-19 06:35:36,450 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-19 06:35:36,549 INFO L235 CfgBuilder]: Building ICFG [2022-11-19 06:35:36,552 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-19 06:35:37,020 INFO L276 CfgBuilder]: Performing block encoding [2022-11-19 06:35:37,190 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-19 06:35:37,190 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-19 06:35:37,194 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:35:37 BoogieIcfgContainer [2022-11-19 06:35:37,194 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-19 06:35:37,197 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-19 06:35:37,197 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-19 06:35:37,202 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-19 06:35:37,202 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 19.11 06:35:35" (1/3) ... [2022-11-19 06:35:37,203 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@171022b4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 06:35:37, skipping insertion in model container [2022-11-19 06:35:37,204 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:35:36" (2/3) ... [2022-11-19 06:35:37,204 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@171022b4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 06:35:37, skipping insertion in model container [2022-11-19 06:35:37,204 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:35:37" (3/3) ... [2022-11-19 06:35:37,206 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product55.cil.c [2022-11-19 06:35:37,233 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-19 06:35:37,233 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-19 06:35:37,294 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-19 06:35:37,306 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@69ce83c6, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-19 06:35:37,306 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-19 06:35:37,311 INFO L276 IsEmpty]: Start isEmpty. Operand has 74 states, 46 states have (on average 1.4565217391304348) internal successors, (67), 57 states have internal predecessors, (67), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2022-11-19 06:35:37,324 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-19 06:35:37,324 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:37,325 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:37,326 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:37,332 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:37,333 INFO L85 PathProgramCache]: Analyzing trace with hash 534369434, now seen corresponding path program 1 times [2022-11-19 06:35:37,345 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:37,345 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2023899827] [2022-11-19 06:35:37,346 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:37,346 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:37,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:37,669 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:37,670 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:37,670 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2023899827] [2022-11-19 06:35:37,671 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2023899827] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:37,671 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:37,671 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-19 06:35:37,673 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [602285032] [2022-11-19 06:35:37,674 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:37,679 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-19 06:35:37,680 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:37,716 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-19 06:35:37,719 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 06:35:37,723 INFO L87 Difference]: Start difference. First operand has 74 states, 46 states have (on average 1.4565217391304348) internal successors, (67), 57 states have internal predecessors, (67), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:37,865 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:37,869 INFO L93 Difference]: Finished difference Result 146 states and 203 transitions. [2022-11-19 06:35:37,871 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-19 06:35:37,874 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-19 06:35:37,874 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:37,896 INFO L225 Difference]: With dead ends: 146 [2022-11-19 06:35:37,896 INFO L226 Difference]: Without dead ends: 69 [2022-11-19 06:35:37,900 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 06:35:37,904 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 80 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:37,906 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 80 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:35:37,925 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 69 states. [2022-11-19 06:35:37,974 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 69 to 69. [2022-11-19 06:35:37,976 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 69 states, 43 states have (on average 1.372093023255814) internal successors, (59), 53 states have internal predecessors, (59), 17 states have call successors, (17), 9 states have call predecessors, (17), 8 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2022-11-19 06:35:37,986 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 69 states to 69 states and 92 transitions. [2022-11-19 06:35:37,988 INFO L78 Accepts]: Start accepts. Automaton has 69 states and 92 transitions. Word has length 21 [2022-11-19 06:35:37,989 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:37,989 INFO L495 AbstractCegarLoop]: Abstraction has 69 states and 92 transitions. [2022-11-19 06:35:37,991 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:37,991 INFO L276 IsEmpty]: Start isEmpty. Operand 69 states and 92 transitions. [2022-11-19 06:35:37,996 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-19 06:35:37,996 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:37,997 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:37,997 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-19 06:35:37,998 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:38,000 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:38,001 INFO L85 PathProgramCache]: Analyzing trace with hash 264026590, now seen corresponding path program 1 times [2022-11-19 06:35:38,001 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:38,002 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1271696357] [2022-11-19 06:35:38,002 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:38,003 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:38,040 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:38,197 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:38,198 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:38,198 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1271696357] [2022-11-19 06:35:38,198 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1271696357] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:38,199 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:38,199 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 06:35:38,199 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [584167629] [2022-11-19 06:35:38,199 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:38,201 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 06:35:38,201 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:38,201 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 06:35:38,202 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:38,202 INFO L87 Difference]: Start difference. First operand 69 states and 92 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:38,279 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:38,279 INFO L93 Difference]: Finished difference Result 110 states and 146 transitions. [2022-11-19 06:35:38,280 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 06:35:38,280 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-19 06:35:38,281 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:38,282 INFO L225 Difference]: With dead ends: 110 [2022-11-19 06:35:38,282 INFO L226 Difference]: Without dead ends: 61 [2022-11-19 06:35:38,283 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:38,285 INFO L413 NwaCegarLoop]: 66 mSDtfsCounter, 14 mSDsluCounter, 49 mSDsCounter, 0 mSdLazyCounter, 27 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 115 SdHoareTripleChecker+Invalid, 27 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 27 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:38,285 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 115 Invalid, 27 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 27 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-19 06:35:38,287 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-19 06:35:38,294 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-19 06:35:38,295 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 38 states have (on average 1.394736842105263) internal successors, (53), 48 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-19 06:35:38,296 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 81 transitions. [2022-11-19 06:35:38,296 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 81 transitions. Word has length 22 [2022-11-19 06:35:38,296 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:38,297 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 81 transitions. [2022-11-19 06:35:38,297 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:38,297 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 81 transitions. [2022-11-19 06:35:38,298 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-19 06:35:38,301 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:38,301 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:38,301 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-19 06:35:38,302 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:38,302 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:38,302 INFO L85 PathProgramCache]: Analyzing trace with hash 729428829, now seen corresponding path program 1 times [2022-11-19 06:35:38,303 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:38,304 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [405600488] [2022-11-19 06:35:38,304 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:38,305 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:38,342 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:38,483 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:38,484 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:38,484 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [405600488] [2022-11-19 06:35:38,484 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [405600488] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:38,485 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:38,485 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 06:35:38,485 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [267439444] [2022-11-19 06:35:38,485 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:38,486 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 06:35:38,486 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:38,487 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 06:35:38,487 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:38,487 INFO L87 Difference]: Start difference. First operand 61 states and 81 transitions. Second operand has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 06:35:38,588 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:38,593 INFO L93 Difference]: Finished difference Result 179 states and 240 transitions. [2022-11-19 06:35:38,593 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 06:35:38,594 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2022-11-19 06:35:38,594 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:38,597 INFO L225 Difference]: With dead ends: 179 [2022-11-19 06:35:38,599 INFO L226 Difference]: Without dead ends: 120 [2022-11-19 06:35:38,601 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:38,604 INFO L413 NwaCegarLoop]: 89 mSDtfsCounter, 66 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 33 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 66 SdHoareTripleChecker+Valid, 153 SdHoareTripleChecker+Invalid, 33 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 33 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:38,608 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [66 Valid, 153 Invalid, 33 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 33 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:35:38,609 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 120 states. [2022-11-19 06:35:38,645 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 120 to 117. [2022-11-19 06:35:38,647 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 117 states, 72 states have (on average 1.4027777777777777) internal successors, (101), 91 states have internal predecessors, (101), 28 states have call successors, (28), 16 states have call predecessors, (28), 16 states have return successors, (28), 17 states have call predecessors, (28), 28 states have call successors, (28) [2022-11-19 06:35:38,654 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 117 states to 117 states and 157 transitions. [2022-11-19 06:35:38,654 INFO L78 Accepts]: Start accepts. Automaton has 117 states and 157 transitions. Word has length 25 [2022-11-19 06:35:38,654 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:38,655 INFO L495 AbstractCegarLoop]: Abstraction has 117 states and 157 transitions. [2022-11-19 06:35:38,655 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.333333333333333) internal successors, (19), 3 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 06:35:38,656 INFO L276 IsEmpty]: Start isEmpty. Operand 117 states and 157 transitions. [2022-11-19 06:35:38,665 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-19 06:35:38,665 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:38,666 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:38,666 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-19 06:35:38,667 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:38,668 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:38,669 INFO L85 PathProgramCache]: Analyzing trace with hash 1938685961, now seen corresponding path program 1 times [2022-11-19 06:35:38,671 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:38,671 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1372732871] [2022-11-19 06:35:38,671 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:38,671 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:38,709 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:38,922 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-19 06:35:38,923 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:38,924 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1372732871] [2022-11-19 06:35:38,925 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1372732871] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:38,925 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:38,925 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-19 06:35:38,926 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [869931355] [2022-11-19 06:35:38,926 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:38,927 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-19 06:35:38,928 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:38,929 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-19 06:35:38,930 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-19 06:35:38,930 INFO L87 Difference]: Start difference. First operand 117 states and 157 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:39,224 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:39,224 INFO L93 Difference]: Finished difference Result 322 states and 445 transitions. [2022-11-19 06:35:39,225 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-19 06:35:39,225 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2022-11-19 06:35:39,226 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:39,229 INFO L225 Difference]: With dead ends: 322 [2022-11-19 06:35:39,229 INFO L226 Difference]: Without dead ends: 207 [2022-11-19 06:35:39,230 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-19 06:35:39,232 INFO L413 NwaCegarLoop]: 79 mSDtfsCounter, 42 mSDsluCounter, 257 mSDsCounter, 0 mSdLazyCounter, 130 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 43 SdHoareTripleChecker+Valid, 336 SdHoareTripleChecker+Invalid, 140 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 130 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:39,232 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [43 Valid, 336 Invalid, 140 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 130 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 06:35:39,234 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 207 states. [2022-11-19 06:35:39,277 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 207 to 198. [2022-11-19 06:35:39,282 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 198 states, 129 states have (on average 1.310077519379845) internal successors, (169), 146 states have internal predecessors, (169), 38 states have call successors, (38), 30 states have call predecessors, (38), 30 states have return successors, (50), 33 states have call predecessors, (50), 38 states have call successors, (50) [2022-11-19 06:35:39,292 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 198 states to 198 states and 257 transitions. [2022-11-19 06:35:39,292 INFO L78 Accepts]: Start accepts. Automaton has 198 states and 257 transitions. Word has length 28 [2022-11-19 06:35:39,293 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:39,293 INFO L495 AbstractCegarLoop]: Abstraction has 198 states and 257 transitions. [2022-11-19 06:35:39,293 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:35:39,294 INFO L276 IsEmpty]: Start isEmpty. Operand 198 states and 257 transitions. [2022-11-19 06:35:39,295 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2022-11-19 06:35:39,296 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:39,296 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:39,296 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-19 06:35:39,297 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:39,298 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:39,299 INFO L85 PathProgramCache]: Analyzing trace with hash -710785848, now seen corresponding path program 1 times [2022-11-19 06:35:39,299 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:39,300 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2008201960] [2022-11-19 06:35:39,300 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:39,300 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:39,341 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:39,675 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:39,675 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:39,676 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2008201960] [2022-11-19 06:35:39,676 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2008201960] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:39,676 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:39,676 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-19 06:35:39,677 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1144079558] [2022-11-19 06:35:39,677 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:39,677 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-19 06:35:39,677 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:39,678 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-19 06:35:39,678 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-19 06:35:39,678 INFO L87 Difference]: Start difference. First operand 198 states and 257 transitions. Second operand has 7 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 06:35:40,021 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:40,027 INFO L93 Difference]: Finished difference Result 542 states and 704 transitions. [2022-11-19 06:35:40,027 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-19 06:35:40,028 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 38 [2022-11-19 06:35:40,028 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:40,038 INFO L225 Difference]: With dead ends: 542 [2022-11-19 06:35:40,038 INFO L226 Difference]: Without dead ends: 346 [2022-11-19 06:35:40,040 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=21, Invalid=35, Unknown=0, NotChecked=0, Total=56 [2022-11-19 06:35:40,045 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 162 mSDsluCounter, 184 mSDsCounter, 0 mSdLazyCounter, 156 mSolverCounterSat, 40 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 163 SdHoareTripleChecker+Valid, 294 SdHoareTripleChecker+Invalid, 196 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 40 IncrementalHoareTripleChecker+Valid, 156 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:40,047 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [163 Valid, 294 Invalid, 196 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [40 Valid, 156 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 06:35:40,049 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 346 states. [2022-11-19 06:35:40,125 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 346 to 324. [2022-11-19 06:35:40,126 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 324 states, 212 states have (on average 1.2971698113207548) internal successors, (275), 236 states have internal predecessors, (275), 60 states have call successors, (60), 49 states have call predecessors, (60), 51 states have return successors, (84), 53 states have call predecessors, (84), 60 states have call successors, (84) [2022-11-19 06:35:40,128 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 324 states to 324 states and 419 transitions. [2022-11-19 06:35:40,129 INFO L78 Accepts]: Start accepts. Automaton has 324 states and 419 transitions. Word has length 38 [2022-11-19 06:35:40,129 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:40,129 INFO L495 AbstractCegarLoop]: Abstraction has 324 states and 419 transitions. [2022-11-19 06:35:40,130 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 06:35:40,130 INFO L276 IsEmpty]: Start isEmpty. Operand 324 states and 419 transitions. [2022-11-19 06:35:40,131 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-11-19 06:35:40,131 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:40,132 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:40,132 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-19 06:35:40,132 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:40,133 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:40,133 INFO L85 PathProgramCache]: Analyzing trace with hash 1358853564, now seen corresponding path program 1 times [2022-11-19 06:35:40,133 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:40,133 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [489019842] [2022-11-19 06:35:40,133 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:40,134 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:40,150 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:40,514 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:40,514 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:40,515 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [489019842] [2022-11-19 06:35:40,515 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [489019842] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:40,515 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:40,515 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-19 06:35:40,515 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1754477236] [2022-11-19 06:35:40,516 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:40,516 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 06:35:40,516 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:40,517 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 06:35:40,517 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-19 06:35:40,517 INFO L87 Difference]: Start difference. First operand 324 states and 419 transitions. Second operand has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-19 06:35:41,416 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:41,417 INFO L93 Difference]: Finished difference Result 960 states and 1292 transitions. [2022-11-19 06:35:41,417 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 16 states. [2022-11-19 06:35:41,418 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) Word has length 41 [2022-11-19 06:35:41,418 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:41,423 INFO L225 Difference]: With dead ends: 960 [2022-11-19 06:35:41,423 INFO L226 Difference]: Without dead ends: 696 [2022-11-19 06:35:41,425 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 38 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=75, Invalid=165, Unknown=0, NotChecked=0, Total=240 [2022-11-19 06:35:41,426 INFO L413 NwaCegarLoop]: 91 mSDtfsCounter, 283 mSDsluCounter, 230 mSDsCounter, 0 mSdLazyCounter, 406 mSolverCounterSat, 111 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 296 SdHoareTripleChecker+Valid, 321 SdHoareTripleChecker+Invalid, 517 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 111 IncrementalHoareTripleChecker+Valid, 406 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:41,427 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [296 Valid, 321 Invalid, 517 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [111 Valid, 406 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-19 06:35:41,428 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 696 states. [2022-11-19 06:35:41,509 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 696 to 576. [2022-11-19 06:35:41,511 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 576 states, 385 states have (on average 1.283116883116883) internal successors, (494), 424 states have internal predecessors, (494), 101 states have call successors, (101), 76 states have call predecessors, (101), 89 states have return successors, (144), 99 states have call predecessors, (144), 101 states have call successors, (144) [2022-11-19 06:35:41,514 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 576 states to 576 states and 739 transitions. [2022-11-19 06:35:41,515 INFO L78 Accepts]: Start accepts. Automaton has 576 states and 739 transitions. Word has length 41 [2022-11-19 06:35:41,515 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:41,516 INFO L495 AbstractCegarLoop]: Abstraction has 576 states and 739 transitions. [2022-11-19 06:35:41,516 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 4.142857142857143) internal successors, (29), 7 states have internal predecessors, (29), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-19 06:35:41,516 INFO L276 IsEmpty]: Start isEmpty. Operand 576 states and 739 transitions. [2022-11-19 06:35:41,518 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-11-19 06:35:41,518 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:41,518 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:41,519 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-19 06:35:41,519 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:41,519 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:41,520 INFO L85 PathProgramCache]: Analyzing trace with hash 35483548, now seen corresponding path program 1 times [2022-11-19 06:35:41,520 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:41,520 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [206190372] [2022-11-19 06:35:41,520 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:41,521 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:41,534 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:41,559 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:35:41,559 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:41,560 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [206190372] [2022-11-19 06:35:41,560 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [206190372] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:35:41,560 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:35:41,560 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 06:35:41,561 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1776984407] [2022-11-19 06:35:41,561 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:35:41,561 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 06:35:41,561 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:41,562 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 06:35:41,562 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:41,562 INFO L87 Difference]: Start difference. First operand 576 states and 739 transitions. Second operand has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (5), 2 states have call predecessors, (5), 1 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-19 06:35:41,650 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:41,650 INFO L93 Difference]: Finished difference Result 680 states and 873 transitions. [2022-11-19 06:35:41,651 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 06:35:41,651 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (5), 2 states have call predecessors, (5), 1 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 41 [2022-11-19 06:35:41,651 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:41,653 INFO L225 Difference]: With dead ends: 680 [2022-11-19 06:35:41,654 INFO L226 Difference]: Without dead ends: 270 [2022-11-19 06:35:41,655 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:35:41,656 INFO L413 NwaCegarLoop]: 87 mSDtfsCounter, 31 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 37 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 31 SdHoareTripleChecker+Valid, 151 SdHoareTripleChecker+Invalid, 37 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 37 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:41,657 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [31 Valid, 151 Invalid, 37 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 37 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-19 06:35:41,658 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 270 states. [2022-11-19 06:35:41,709 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 270 to 270. [2022-11-19 06:35:41,710 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 270 states, 181 states have (on average 1.2320441988950277) internal successors, (223), 198 states have internal predecessors, (223), 46 states have call successors, (46), 35 states have call predecessors, (46), 42 states have return successors, (65), 47 states have call predecessors, (65), 46 states have call successors, (65) [2022-11-19 06:35:41,711 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 270 states to 270 states and 334 transitions. [2022-11-19 06:35:41,712 INFO L78 Accepts]: Start accepts. Automaton has 270 states and 334 transitions. Word has length 41 [2022-11-19 06:35:41,713 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:41,713 INFO L495 AbstractCegarLoop]: Abstraction has 270 states and 334 transitions. [2022-11-19 06:35:41,713 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (5), 2 states have call predecessors, (5), 1 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2022-11-19 06:35:41,713 INFO L276 IsEmpty]: Start isEmpty. Operand 270 states and 334 transitions. [2022-11-19 06:35:41,716 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 74 [2022-11-19 06:35:41,717 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:41,717 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:41,717 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-19 06:35:41,717 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:41,718 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:41,718 INFO L85 PathProgramCache]: Analyzing trace with hash 1146335313, now seen corresponding path program 1 times [2022-11-19 06:35:41,718 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:41,718 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [463013088] [2022-11-19 06:35:41,719 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:41,719 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:41,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:41,972 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 10 proven. 13 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2022-11-19 06:35:41,972 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:41,972 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [463013088] [2022-11-19 06:35:41,972 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [463013088] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:35:41,973 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1953969953] [2022-11-19 06:35:41,973 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:41,973 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:35:41,974 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:35:41,978 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:35:42,008 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-19 06:35:42,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:42,109 INFO L263 TraceCheckSpWp]: Trace formula consists of 337 conjuncts, 8 conjunts are in the unsatisfiable core [2022-11-19 06:35:42,117 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:35:42,341 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 23 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-19 06:35:42,342 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:35:42,647 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 14 proven. 8 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-19 06:35:42,647 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1953969953] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:35:42,647 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1329707734] [2022-11-19 06:35:42,675 INFO L159 IcfgInterpreter]: Started Sifa with 44 locations of interest [2022-11-19 06:35:42,675 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:35:42,680 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:35:42,687 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:35:42,688 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:35:47,892 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 127 for LOIs [2022-11-19 06:35:47,916 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-19 06:35:48,860 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 57 for LOIs [2022-11-19 06:35:49,016 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 06:35:49,043 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 41 for LOIs [2022-11-19 06:35:49,051 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:35:57,504 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '7527#(and (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |old(~pumpRunning~0)|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| |timeShift_getWaterLevel_#res#1|) (<= |old(~pumpRunning~0)| 2147483647) (= 1 ~systemActive~0) (<= 2 |old(~waterLevel~0)|) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| 2)) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (<= 2 |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1|) (= |#NULL.base| 0))' at error location [2022-11-19 06:35:57,505 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:35:57,505 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:35:57,505 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 14 [2022-11-19 06:35:57,505 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1795307975] [2022-11-19 06:35:57,506 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:35:57,506 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-11-19 06:35:57,507 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:35:57,507 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-11-19 06:35:57,508 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=288, Invalid=1692, Unknown=0, NotChecked=0, Total=1980 [2022-11-19 06:35:57,508 INFO L87 Difference]: Start difference. First operand 270 states and 334 transitions. Second operand has 14 states, 12 states have (on average 8.083333333333334) internal successors, (97), 13 states have internal predecessors, (97), 8 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (21), 10 states have call predecessors, (21), 8 states have call successors, (21) [2022-11-19 06:35:58,575 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:35:58,575 INFO L93 Difference]: Finished difference Result 454 states and 567 transitions. [2022-11-19 06:35:58,576 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 19 states. [2022-11-19 06:35:58,576 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 12 states have (on average 8.083333333333334) internal successors, (97), 13 states have internal predecessors, (97), 8 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (21), 10 states have call predecessors, (21), 8 states have call successors, (21) Word has length 73 [2022-11-19 06:35:58,577 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:35:58,579 INFO L225 Difference]: With dead ends: 454 [2022-11-19 06:35:58,579 INFO L226 Difference]: Without dead ends: 311 [2022-11-19 06:35:58,586 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 254 GetRequests, 185 SyntacticMatches, 9 SemanticMatches, 60 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1337 ImplicationChecksByTransitivity, 9.1s TimeCoverageRelationStatistics Valid=510, Invalid=3272, Unknown=0, NotChecked=0, Total=3782 [2022-11-19 06:35:58,587 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 411 mSDsluCounter, 392 mSDsCounter, 0 mSdLazyCounter, 437 mSolverCounterSat, 265 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 411 SdHoareTripleChecker+Valid, 507 SdHoareTripleChecker+Invalid, 702 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 265 IncrementalHoareTripleChecker+Valid, 437 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-19 06:35:58,587 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [411 Valid, 507 Invalid, 702 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [265 Valid, 437 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-19 06:35:58,588 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 311 states. [2022-11-19 06:35:58,614 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 311 to 309. [2022-11-19 06:35:58,615 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 309 states, 204 states have (on average 1.1911764705882353) internal successors, (243), 224 states have internal predecessors, (243), 53 states have call successors, (53), 45 states have call predecessors, (53), 51 states have return successors, (66), 53 states have call predecessors, (66), 53 states have call successors, (66) [2022-11-19 06:35:58,617 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 309 states to 309 states and 362 transitions. [2022-11-19 06:35:58,617 INFO L78 Accepts]: Start accepts. Automaton has 309 states and 362 transitions. Word has length 73 [2022-11-19 06:35:58,617 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:35:58,618 INFO L495 AbstractCegarLoop]: Abstraction has 309 states and 362 transitions. [2022-11-19 06:35:58,618 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 12 states have (on average 8.083333333333334) internal successors, (97), 13 states have internal predecessors, (97), 8 states have call successors, (21), 5 states have call predecessors, (21), 8 states have return successors, (21), 10 states have call predecessors, (21), 8 states have call successors, (21) [2022-11-19 06:35:58,618 INFO L276 IsEmpty]: Start isEmpty. Operand 309 states and 362 transitions. [2022-11-19 06:35:58,619 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2022-11-19 06:35:58,620 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:35:58,620 INFO L195 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:35:58,631 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-19 06:35:58,826 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:35:58,827 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:35:58,827 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:35:58,827 INFO L85 PathProgramCache]: Analyzing trace with hash -2064584164, now seen corresponding path program 1 times [2022-11-19 06:35:58,827 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:35:58,827 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2015896935] [2022-11-19 06:35:58,827 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:58,828 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:35:58,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:59,206 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 35 proven. 3 refuted. 0 times theorem prover too weak. 35 trivial. 0 not checked. [2022-11-19 06:35:59,208 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:35:59,209 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2015896935] [2022-11-19 06:35:59,209 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2015896935] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:35:59,209 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1649626457] [2022-11-19 06:35:59,209 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:35:59,210 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:35:59,210 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:35:59,215 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:35:59,234 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-19 06:35:59,335 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:35:59,338 INFO L263 TraceCheckSpWp]: Trace formula consists of 407 conjuncts, 18 conjunts are in the unsatisfiable core [2022-11-19 06:35:59,342 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:35:59,591 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 66 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-19 06:35:59,592 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:36:00,001 INFO L134 CoverageAnalysis]: Checked inductivity of 73 backedges. 48 proven. 3 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-19 06:36:00,001 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1649626457] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:36:00,001 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [111618234] [2022-11-19 06:36:00,008 INFO L159 IcfgInterpreter]: Started Sifa with 46 locations of interest [2022-11-19 06:36:00,009 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:36:00,009 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:36:00,010 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:36:00,010 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:36:02,647 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 56 for LOIs [2022-11-19 06:36:02,657 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-19 06:36:02,986 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 26 for LOIs [2022-11-19 06:36:03,027 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 06:36:03,048 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 56 for LOIs [2022-11-19 06:36:03,059 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:36:08,945 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '9340#(and (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (= ~head~0.offset 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| |timeShift_getWaterLevel_#res#1|) (<= |#NULL.offset| 0) (= 1 ~systemActive~0) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (<= 0 ~methaneLevelCritical~0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= ~head~0.base 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| 2)) (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (<= 2 |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1|) (= |#NULL.base| 0))' at error location [2022-11-19 06:36:08,945 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:36:08,945 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:36:08,945 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 9] total 20 [2022-11-19 06:36:08,945 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [734599079] [2022-11-19 06:36:08,945 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:36:08,946 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2022-11-19 06:36:08,946 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:36:08,947 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2022-11-19 06:36:08,948 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=287, Invalid=2065, Unknown=0, NotChecked=0, Total=2352 [2022-11-19 06:36:08,949 INFO L87 Difference]: Start difference. First operand 309 states and 362 transitions. Second operand has 20 states, 20 states have (on average 5.65) internal successors, (113), 20 states have internal predecessors, (113), 9 states have call successors, (23), 5 states have call predecessors, (23), 8 states have return successors, (24), 10 states have call predecessors, (24), 9 states have call successors, (24) [2022-11-19 06:36:11,044 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:36:11,045 INFO L93 Difference]: Finished difference Result 913 states and 1163 transitions. [2022-11-19 06:36:11,045 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2022-11-19 06:36:11,045 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 5.65) internal successors, (113), 20 states have internal predecessors, (113), 9 states have call successors, (23), 5 states have call predecessors, (23), 8 states have return successors, (24), 10 states have call predecessors, (24), 9 states have call successors, (24) Word has length 96 [2022-11-19 06:36:11,046 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:36:11,049 INFO L225 Difference]: With dead ends: 913 [2022-11-19 06:36:11,050 INFO L226 Difference]: Without dead ends: 598 [2022-11-19 06:36:11,057 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 341 GetRequests, 259 SyntacticMatches, 8 SemanticMatches, 74 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2163 ImplicationChecksByTransitivity, 7.0s TimeCoverageRelationStatistics Valid=663, Invalid=5037, Unknown=0, NotChecked=0, Total=5700 [2022-11-19 06:36:11,060 INFO L413 NwaCegarLoop]: 72 mSDtfsCounter, 552 mSDsluCounter, 509 mSDsCounter, 0 mSdLazyCounter, 1211 mSolverCounterSat, 374 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 555 SdHoareTripleChecker+Valid, 581 SdHoareTripleChecker+Invalid, 1585 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 374 IncrementalHoareTripleChecker+Valid, 1211 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:36:11,060 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [555 Valid, 581 Invalid, 1585 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [374 Valid, 1211 Invalid, 0 Unknown, 0 Unchecked, 1.1s Time] [2022-11-19 06:36:11,062 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 598 states. [2022-11-19 06:36:11,125 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 598 to 386. [2022-11-19 06:36:11,126 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 386 states, 256 states have (on average 1.15625) internal successors, (296), 279 states have internal predecessors, (296), 63 states have call successors, (63), 56 states have call predecessors, (63), 66 states have return successors, (83), 67 states have call predecessors, (83), 63 states have call successors, (83) [2022-11-19 06:36:11,129 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 386 states to 386 states and 442 transitions. [2022-11-19 06:36:11,129 INFO L78 Accepts]: Start accepts. Automaton has 386 states and 442 transitions. Word has length 96 [2022-11-19 06:36:11,129 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:36:11,130 INFO L495 AbstractCegarLoop]: Abstraction has 386 states and 442 transitions. [2022-11-19 06:36:11,130 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 5.65) internal successors, (113), 20 states have internal predecessors, (113), 9 states have call successors, (23), 5 states have call predecessors, (23), 8 states have return successors, (24), 10 states have call predecessors, (24), 9 states have call successors, (24) [2022-11-19 06:36:11,130 INFO L276 IsEmpty]: Start isEmpty. Operand 386 states and 442 transitions. [2022-11-19 06:36:11,133 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2022-11-19 06:36:11,133 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:36:11,133 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:36:11,145 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-19 06:36:11,339 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2022-11-19 06:36:11,340 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:36:11,340 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:36:11,340 INFO L85 PathProgramCache]: Analyzing trace with hash 1893254194, now seen corresponding path program 1 times [2022-11-19 06:36:11,340 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:36:11,340 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1612986088] [2022-11-19 06:36:11,340 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:36:11,341 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:36:11,379 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:36:11,651 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 41 proven. 0 refuted. 0 times theorem prover too weak. 43 trivial. 0 not checked. [2022-11-19 06:36:11,651 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:36:11,651 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1612986088] [2022-11-19 06:36:11,651 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1612986088] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:36:11,652 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:36:11,652 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-19 06:36:11,652 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [614103807] [2022-11-19 06:36:11,652 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:36:11,653 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-19 06:36:11,653 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:36:11,653 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-19 06:36:11,654 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2022-11-19 06:36:11,654 INFO L87 Difference]: Start difference. First operand 386 states and 442 transitions. Second operand has 5 states, 5 states have (on average 10.8) internal successors, (54), 5 states have internal predecessors, (54), 4 states have call successors, (11), 2 states have call predecessors, (11), 2 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-19 06:36:12,046 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:36:12,046 INFO L93 Difference]: Finished difference Result 988 states and 1136 transitions. [2022-11-19 06:36:12,047 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-19 06:36:12,047 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 10.8) internal successors, (54), 5 states have internal predecessors, (54), 4 states have call successors, (11), 2 states have call predecessors, (11), 2 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) Word has length 101 [2022-11-19 06:36:12,048 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:36:12,052 INFO L225 Difference]: With dead ends: 988 [2022-11-19 06:36:12,053 INFO L226 Difference]: Without dead ends: 768 [2022-11-19 06:36:12,054 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-19 06:36:12,054 INFO L413 NwaCegarLoop]: 123 mSDtfsCounter, 141 mSDsluCounter, 134 mSDsCounter, 0 mSdLazyCounter, 204 mSolverCounterSat, 11 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 141 SdHoareTripleChecker+Valid, 257 SdHoareTripleChecker+Invalid, 215 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 11 IncrementalHoareTripleChecker+Valid, 204 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 06:36:12,056 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [141 Valid, 257 Invalid, 215 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [11 Valid, 204 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 06:36:12,057 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 768 states. [2022-11-19 06:36:12,144 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 768 to 766. [2022-11-19 06:36:12,146 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 766 states, 509 states have (on average 1.1532416502946954) internal successors, (587), 552 states have internal predecessors, (587), 124 states have call successors, (124), 112 states have call predecessors, (124), 132 states have return successors, (164), 134 states have call predecessors, (164), 124 states have call successors, (164) [2022-11-19 06:36:12,149 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 766 states to 766 states and 875 transitions. [2022-11-19 06:36:12,150 INFO L78 Accepts]: Start accepts. Automaton has 766 states and 875 transitions. Word has length 101 [2022-11-19 06:36:12,150 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:36:12,150 INFO L495 AbstractCegarLoop]: Abstraction has 766 states and 875 transitions. [2022-11-19 06:36:12,151 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 10.8) internal successors, (54), 5 states have internal predecessors, (54), 4 states have call successors, (11), 2 states have call predecessors, (11), 2 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) [2022-11-19 06:36:12,151 INFO L276 IsEmpty]: Start isEmpty. Operand 766 states and 875 transitions. [2022-11-19 06:36:12,159 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 105 [2022-11-19 06:36:12,160 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:36:12,160 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:36:12,160 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2022-11-19 06:36:12,161 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:36:12,161 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:36:12,162 INFO L85 PathProgramCache]: Analyzing trace with hash -934254643, now seen corresponding path program 1 times [2022-11-19 06:36:12,162 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:36:12,162 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1036491869] [2022-11-19 06:36:12,162 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:36:12,162 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:36:12,194 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:36:13,466 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 10 proven. 46 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2022-11-19 06:36:13,466 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:36:13,466 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1036491869] [2022-11-19 06:36:13,466 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1036491869] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:36:13,466 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1500817156] [2022-11-19 06:36:13,466 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:36:13,467 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:36:13,467 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:36:13,468 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:36:13,479 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-19 06:36:13,603 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:36:13,606 INFO L263 TraceCheckSpWp]: Trace formula consists of 427 conjuncts, 34 conjunts are in the unsatisfiable core [2022-11-19 06:36:13,610 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:36:14,176 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 25 proven. 57 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:36:14,176 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:36:15,208 INFO L134 CoverageAnalysis]: Checked inductivity of 84 backedges. 54 proven. 5 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2022-11-19 06:36:15,208 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1500817156] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:36:15,208 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [231296989] [2022-11-19 06:36:15,211 INFO L159 IcfgInterpreter]: Started Sifa with 49 locations of interest [2022-11-19 06:36:15,211 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:36:15,212 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:36:15,212 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:36:15,212 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:36:21,145 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 153 for LOIs [2022-11-19 06:36:21,193 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 48 for LOIs [2022-11-19 06:36:21,908 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 27 for LOIs [2022-11-19 06:36:21,953 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 27 for LOIs [2022-11-19 06:36:21,977 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 23 for LOIs [2022-11-19 06:36:21,979 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 32 for LOIs [2022-11-19 06:36:21,983 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 34 for LOIs [2022-11-19 06:36:21,987 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:36:32,309 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '14695#(and (<= ~methaneLevelCritical~0 1) (= |timeShift_getWaterLevel_~retValue_acc~7#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |old(~pumpRunning~0)|) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| |timeShift_getWaterLevel_#res#1|) (<= |old(~pumpRunning~0)| 2147483647) (<= |#NULL.offset| 0) (= 1 ~systemActive~0) (<= 0 ~head~0.base) (= |timeShift_getWaterLevel_~retValue_acc~7#1| ~waterLevel~0) (<= 0 ~methaneLevelCritical~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| 2)) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= 0 (+ |timeShift_getWaterLevel_~retValue_acc~7#1| 2147483648)) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 06:36:32,309 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:36:32,309 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:36:32,309 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [20, 13, 11] total 36 [2022-11-19 06:36:32,310 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [760695804] [2022-11-19 06:36:32,310 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:36:32,311 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 36 states [2022-11-19 06:36:32,311 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:36:32,312 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 36 interpolants. [2022-11-19 06:36:32,314 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=495, Invalid=4617, Unknown=0, NotChecked=0, Total=5112 [2022-11-19 06:36:32,314 INFO L87 Difference]: Start difference. First operand 766 states and 875 transitions. Second operand has 36 states, 34 states have (on average 5.352941176470588) internal successors, (182), 35 states have internal predecessors, (182), 19 states have call successors, (39), 9 states have call predecessors, (39), 14 states have return successors, (38), 19 states have call predecessors, (38), 18 states have call successors, (38) [2022-11-19 06:36:37,218 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:36:37,219 INFO L93 Difference]: Finished difference Result 1914 states and 2269 transitions. [2022-11-19 06:36:37,219 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 45 states. [2022-11-19 06:36:37,220 INFO L78 Accepts]: Start accepts. Automaton has has 36 states, 34 states have (on average 5.352941176470588) internal successors, (182), 35 states have internal predecessors, (182), 19 states have call successors, (39), 9 states have call predecessors, (39), 14 states have return successors, (38), 19 states have call predecessors, (38), 18 states have call successors, (38) Word has length 104 [2022-11-19 06:36:37,222 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:36:37,223 INFO L225 Difference]: With dead ends: 1914 [2022-11-19 06:36:37,224 INFO L226 Difference]: Without dead ends: 0 [2022-11-19 06:36:37,231 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 396 GetRequests, 276 SyntacticMatches, 9 SemanticMatches, 111 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4950 ImplicationChecksByTransitivity, 13.2s TimeCoverageRelationStatistics Valid=1425, Invalid=11231, Unknown=0, NotChecked=0, Total=12656 [2022-11-19 06:36:37,232 INFO L413 NwaCegarLoop]: 132 mSDtfsCounter, 1733 mSDsluCounter, 1180 mSDsCounter, 0 mSdLazyCounter, 2712 mSolverCounterSat, 1170 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1734 SdHoareTripleChecker+Valid, 1312 SdHoareTripleChecker+Invalid, 3882 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1170 IncrementalHoareTripleChecker+Valid, 2712 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.3s IncrementalHoareTripleChecker+Time [2022-11-19 06:36:37,232 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1734 Valid, 1312 Invalid, 3882 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1170 Valid, 2712 Invalid, 0 Unknown, 0 Unchecked, 2.3s Time] [2022-11-19 06:36:37,233 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-19 06:36:37,234 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-19 06:36:37,234 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-19 06:36:37,234 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-19 06:36:37,235 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 104 [2022-11-19 06:36:37,235 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:36:37,235 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-19 06:36:37,237 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 36 states, 34 states have (on average 5.352941176470588) internal successors, (182), 35 states have internal predecessors, (182), 19 states have call successors, (39), 9 states have call predecessors, (39), 14 states have return successors, (38), 19 states have call predecessors, (38), 18 states have call successors, (38) [2022-11-19 06:36:37,237 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-19 06:36:37,237 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-19 06:36:37,241 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-19 06:36:37,251 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Ended with exit code 0 [2022-11-19 06:36:37,451 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2022-11-19 06:36:37,453 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-19 06:36:56,048 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 871 878) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,048 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 871 878) no Hoare annotation was computed. [2022-11-19 06:36:56,048 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 778 784) no Hoare annotation was computed. [2022-11-19 06:36:56,049 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 778 784) the Hoare annotation is: true [2022-11-19 06:36:56,049 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 666 677) the Hoare annotation is: (let ((.cse0 (not (= ~waterLevel~0 1))) (.cse10 (not (<= ~waterLevel~0 0))) (.cse6 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse7 (<= 1 ~methaneLevelCritical~0)) (.cse8 (and (not (<= (+ |old(~methaneLevelCritical~0)| 1) 0)) (not (<= 1 |old(~methaneLevelCritical~0)|)))) (.cse9 (<= (+ ~methaneLevelCritical~0 1) 0)) (.cse13 (not (<= 2 ~waterLevel~0))) (.cse2 (not (= ~pumpRunning~0 1))) (.cse14 (not (<= ~waterLevel~0 2))) (.cse11 (not (= ~pumpRunning~0 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (<= |old(~methaneLevelCritical~0)| 0))) (.cse4 (and (<= ~methaneLevelCritical~0 0) (<= 0 ~methaneLevelCritical~0))) (.cse5 (not (<= 0 |old(~methaneLevelCritical~0)|))) (.cse12 (not (< ~waterLevel~0 3)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (or .cse0 .cse7 .cse1 .cse8 .cse9 .cse2 .cse6) (or .cse10 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (or .cse10 .cse7 .cse1 .cse8 .cse9 .cse2 .cse6) (or .cse7 .cse11 .cse1 .cse8 .cse9 .cse12) (or .cse7 .cse1 .cse8 .cse9 .cse13 .cse2 .cse14) (or .cse1 .cse13 .cse2 .cse14 .cse3 .cse4 .cse5) (or .cse11 .cse1 .cse3 .cse4 .cse5 .cse12))) [2022-11-19 06:36:56,049 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 666 677) no Hoare annotation was computed. [2022-11-19 06:36:56,050 INFO L895 garLoopResultBuilder]: At program point L1018(line 1018) the Hoare annotation is: (let ((.cse2 (not (= 0 ~systemActive~0))) (.cse8 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse15 (= ~pumpRunning~0 1)) (.cse1 (= ~pumpRunning~0 0)) (.cse9 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse7 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| ~waterLevel~0)) (.cse3 (= ~waterLevel~0 1)) (.cse12 (<= 1 ~switchedOnBeforeTS~0)) (.cse13 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse14 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= 1 ~systemActive~0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 .cse2) (or .cse0 .cse4 .cse2 .cse5) (or .cse0 .cse6 (and .cse1 .cse7 .cse8) (not (< |old(~waterLevel~0)| 3))) (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (let ((.cse11 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse10))) (or (and .cse1 .cse9 .cse7 (or (and (not .cse10) .cse8) .cse11) .cse12 .cse13) (not (<= |old(~waterLevel~0)| 1)) .cse6 .cse14 (and .cse9 (<= ~waterLevel~0 0) .cse7 (or .cse11 .cse8) .cse12 .cse13 .cse15) (not (<= 1 |old(~switchedOnBeforeTS~0)|))))) (or (and .cse9 .cse7 .cse3 .cse12 .cse13 .cse15) .cse6 (and .cse1 .cse9 .cse7 .cse3 .cse12 .cse13) .cse14 .cse4 .cse5) (or .cse0 .cse6 .cse4 .cse5))) [2022-11-19 06:36:56,050 INFO L895 garLoopResultBuilder]: At program point L857(line 857) the Hoare annotation is: (let ((.cse1 (not (= 1 ~systemActive~0))) (.cse3 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse1 .cse2) (or .cse1 .cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (not (< |old(~waterLevel~0)| 3))) (or .cse1 .cse3 .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,051 INFO L899 garLoopResultBuilder]: For program point L1018-1(line 1018) no Hoare annotation was computed. [2022-11-19 06:36:56,051 INFO L895 garLoopResultBuilder]: At program point L857-1(lines 838 862) the Hoare annotation is: (let ((.cse7 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (= 1 ~systemActive~0))) (.cse4 (= ~pumpRunning~0 1)) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= ~pumpRunning~0 0)) (.cse0 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse13 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse11 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse12 (not (= |old(~pumpRunning~0)| 0)))) (and (let ((.cse1 (= ~waterLevel~0 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) .cse5 .cse6 .cse7 (and .cse8 .cse0 .cse1 .cse2 .cse3) (not (<= 2 |old(~waterLevel~0)|)))) (let ((.cse9 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse10 (< 0 |old(~waterLevel~0)|))) (or (not (= |old(~waterLevel~0)| 1)) .cse5 (and .cse8 .cse9 .cse10 .cse0 .cse2 .cse3) .cse6 (and .cse9 .cse10 .cse0 .cse2 .cse3 .cse4) .cse11)) (or .cse12 (and .cse8 .cse13) .cse5 (and (<= 2 ~waterLevel~0) .cse13 .cse4) .cse7) (or .cse5 (and .cse0 .cse13 .cse2 .cse3 .cse4) .cse6 (and .cse8 .cse0 .cse13 .cse2 .cse3) (not (<= |old(~waterLevel~0)| 0)) .cse11) (or .cse12 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,051 INFO L899 garLoopResultBuilder]: For program point L758-2(lines 754 776) no Hoare annotation was computed. [2022-11-19 06:36:56,052 INFO L895 garLoopResultBuilder]: At program point L561(line 561) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (< |old(~waterLevel~0)| 3))) (.cse3 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse2) (or .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse3 .cse0 .cse2) (or .cse3 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,052 INFO L899 garLoopResultBuilder]: For program point L846(lines 846 854) no Hoare annotation was computed. [2022-11-19 06:36:56,052 INFO L895 garLoopResultBuilder]: At program point L1003(line 1003) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse2 (and .cse9 (= ~pumpRunning~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= ~pumpRunning~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse10 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse11 (not (< |old(~waterLevel~0)| 3))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (not (= 0 ~systemActive~0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse2 .cse5) (or .cse6 .cse7 (and .cse8 (or .cse9 (= ~waterLevel~0 1)))) (or .cse0 .cse1 .cse10 .cse3 .cse11) (or .cse6 (and .cse8 .cse9) .cse0 .cse11) (or .cse6 .cse0 .cse10 .cse3 .cse11) (or .cse6 .cse9 .cse4 .cse7 .cse5)))) [2022-11-19 06:36:56,053 INFO L895 garLoopResultBuilder]: At program point L1003-1(line 1003) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 0)) (.cse5 (not (< |old(~waterLevel~0)| 3))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 0 ~systemActive~0))) (.cse4 (not (= 1 ~systemActive~0))) (.cse6 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse7 (<= 1 |timeShift___utac_acc__Specification5_spec__2_#t~ret52#1|)) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse9 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 .cse1 (and .cse2 (or .cse3 (= ~waterLevel~0 1)))) (or .cse0 (and .cse2 .cse3) .cse4 .cse5) (or .cse4 .cse6 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse3 .cse7) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) .cse5) (or .cse0 .cse3 .cse8 .cse1 .cse9) (or .cse4 .cse6 (and .cse3 .cse7 (= ~pumpRunning~0 1)) .cse8 .cse9))) [2022-11-19 06:36:56,053 INFO L895 garLoopResultBuilder]: At program point L842(lines 842 859) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (= ~waterLevel~0 1) .cse2 .cse3) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse4 (and (= ~pumpRunning~0 0) .cse5) .cse0 (not (< |old(~waterLevel~0)| 3))) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) .cse5) .cse2 .cse3) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse4 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,053 INFO L899 garLoopResultBuilder]: For program point L1020(lines 1020 1030) no Hoare annotation was computed. [2022-11-19 06:36:56,054 INFO L899 garLoopResultBuilder]: For program point L1016(lines 1016 1033) no Hoare annotation was computed. [2022-11-19 06:36:56,054 INFO L895 garLoopResultBuilder]: At program point L1016-1(lines 1008 1036) the Hoare annotation is: (let ((.cse11 (= 1 ~systemActive~0))) (let ((.cse12 (not (<= |old(~waterLevel~0)| 2))) (.cse13 (not (<= 2 |old(~waterLevel~0)|))) (.cse10 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse6 (<= 1 ~switchedOnBeforeTS~0)) (.cse7 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse5 (= ~waterLevel~0 1)) (.cse2 (not (= 0 ~systemActive~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse9 (not .cse11)) (.cse14 (< 1 |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1|)) (.cse4 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| ~waterLevel~0)) (.cse15 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (= ~pumpRunning~0 1))) (and (or .cse0 .cse1 .cse2) (or (and .cse3 .cse4 .cse5 .cse6 .cse7 .cse8) .cse9 .cse10 (and .cse1 .cse11 .cse3 .cse4 .cse5 .cse6 .cse7) .cse12 .cse13) (or (and .cse14 (<= |timeShift___utac_acc__Specification5_spec__3_~tmp~10#1| 2) .cse15) .cse0 .cse12 .cse2 .cse13) (let ((.cse17 (< 0 |old(~waterLevel~0)|))) (let ((.cse16 (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse17))) (or (not (<= |old(~waterLevel~0)| 1)) .cse9 .cse10 (and .cse3 (<= ~waterLevel~0 0) .cse4 (or .cse16 .cse15) .cse6 .cse7 .cse8) (not (<= 1 |old(~switchedOnBeforeTS~0)|)) (and .cse1 .cse11 .cse3 .cse4 (or (and (not .cse17) .cse15) .cse16) .cse6 .cse7)))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse5 .cse2) (or .cse0 (and .cse1 .cse11 .cse4 .cse15) .cse9 (and .cse14 .cse4 .cse15 .cse8) (not (< |old(~waterLevel~0)| 3)))))) [2022-11-19 06:36:56,054 INFO L899 garLoopResultBuilder]: For program point L1021(lines 1021 1027) no Hoare annotation was computed. [2022-11-19 06:36:56,055 INFO L895 garLoopResultBuilder]: At program point L765-1(lines 765 771) the Hoare annotation is: (let ((.cse12 (not (= |old(~waterLevel~0)| 1))) (.cse4 (= ~waterLevel~0 1)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse2 (not (= 0 ~systemActive~0))) (.cse11 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (not (= 1 ~systemActive~0))) (.cse7 (= ~pumpRunning~0 1)) (.cse9 (not (= |old(~pumpRunning~0)| 1))) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse16 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (<= 1 ~switchedOnBeforeTS~0)) (.cse6 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse15 (not (<= 1 |old(~switchedOnBeforeTS~0)|)))) (and (or .cse0 .cse1 .cse2) (or (and .cse3 .cse4 .cse5 .cse6 .cse7) .cse8 .cse9 .cse10 (and .cse1 .cse3 .cse4 .cse5 .cse6) .cse11) (let ((.cse13 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse14 (< 0 |old(~waterLevel~0)|))) (or .cse12 .cse8 (and .cse1 .cse13 .cse14 .cse3 .cse5 .cse6) .cse9 (and .cse13 .cse14 .cse3 .cse5 .cse6 .cse7) .cse15)) (or .cse0 .cse12 .cse4 .cse2) (or .cse0 (and .cse1 .cse16) .cse8 (and (<= 2 ~waterLevel~0) .cse16 .cse7) .cse10) (or .cse0 .cse16 .cse10 .cse2 .cse11) (or .cse8 (and .cse3 .cse16 .cse5 .cse6 .cse7) .cse9 (and .cse1 .cse3 .cse16 .cse5 .cse6) (not (<= |old(~waterLevel~0)| 0)) .cse15))) [2022-11-19 06:36:56,055 INFO L895 garLoopResultBuilder]: At program point L852(line 852) the Hoare annotation is: (let ((.cse2 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse3 (<= 1 ~switchedOnBeforeTS~0)) (.cse4 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse5 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse6 (not (= |old(~pumpRunning~0)| 0)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 (and .cse2 (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse3 .cse4 .cse5) (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse6 .cse0 (not (< |old(~waterLevel~0)| 3))) (or (and .cse2 (= ~waterLevel~0 1) .cse3 .cse4 .cse5) .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse6 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,056 INFO L895 garLoopResultBuilder]: At program point L848(line 848) the Hoare annotation is: (let ((.cse1 (or (<= |timeShift_processEnvironment_~tmp~7#1| 0) (<= |timeShift_processEnvironment_~tmp~7#1| ~methaneLevelCritical~0))) (.cse2 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (or (< 0 (+ |timeShift_processEnvironment_~tmp~7#1| 1)) (<= ~methaneLevelCritical~0 |timeShift_processEnvironment_~tmp~7#1|))) (.cse4 (= ~pumpRunning~0 1)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (not (= |old(~pumpRunning~0)| 1))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (not (<= 2 |old(~waterLevel~0)|))) (.cse8 (not (= |old(~pumpRunning~0)| 0)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and (or (<= 1 ~methaneLevelCritical~0) (<= (+ ~methaneLevelCritical~0 1) 0)) .cse1 (<= ~waterLevel~0 0) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (< 0 |old(~waterLevel~0)|)) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2 .cse3 .cse4) .cse5 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (or .cse0 .cse5 (not (<= ~methaneLevelCritical~0 0)) (not (<= 0 ~methaneLevelCritical~0)) .cse6 .cse7) (or .cse8 .cse0 (not (< |old(~waterLevel~0)| 3))) (or (and .cse1 (= ~waterLevel~0 1) .cse2 .cse3 .cse4) .cse0 .cse5 .cse6 .cse7) (or .cse8 (not (= 0 ~systemActive~0))))) [2022-11-19 06:36:56,056 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 751 777) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse2 (and .cse9 (= ~pumpRunning~0 1))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse8 (= ~pumpRunning~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse10 (<= 1 ~switchedOnBeforeTS~0)) (.cse3 (not (<= 1 |old(~switchedOnBeforeTS~0)|))) (.cse11 (not (< |old(~waterLevel~0)| 3))) (.cse6 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse7 (not (= 0 ~systemActive~0))) (.cse5 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse1 .cse4 .cse2 .cse5) (or .cse6 .cse7 (and .cse8 (or .cse9 (= ~waterLevel~0 1)))) (or .cse0 .cse1 .cse10 .cse3 .cse11) (or .cse6 (and .cse8 .cse9) .cse0 .cse11) (or .cse6 .cse0 .cse10 .cse3 .cse11) (or .cse6 .cse9 .cse4 .cse7 .cse5)))) [2022-11-19 06:36:56,056 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 751 777) no Hoare annotation was computed. [2022-11-19 06:36:56,057 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 561) no Hoare annotation was computed. [2022-11-19 06:36:56,057 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 418 447) no Hoare annotation was computed. [2022-11-19 06:36:56,057 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 418 447) the Hoare annotation is: true [2022-11-19 06:36:56,057 INFO L902 garLoopResultBuilder]: At program point L443(lines 418 447) the Hoare annotation is: true [2022-11-19 06:36:56,057 INFO L899 garLoopResultBuilder]: For program point L439(line 439) no Hoare annotation was computed. [2022-11-19 06:36:56,058 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2022-11-19 06:36:56,058 INFO L902 garLoopResultBuilder]: At program point L432-1(lines 432 436) the Hoare annotation is: true [2022-11-19 06:36:56,058 INFO L902 garLoopResultBuilder]: At program point L428-2(lines 428 442) the Hoare annotation is: true [2022-11-19 06:36:56,058 INFO L902 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: true [2022-11-19 06:36:56,058 INFO L899 garLoopResultBuilder]: For program point L424-1(line 424) no Hoare annotation was computed. [2022-11-19 06:36:56,058 INFO L899 garLoopResultBuilder]: For program point L597(lines 597 603) no Hoare annotation was computed. [2022-11-19 06:36:56,059 INFO L899 garLoopResultBuilder]: For program point L597-1(lines 597 603) no Hoare annotation was computed. [2022-11-19 06:36:56,059 INFO L899 garLoopResultBuilder]: For program point L977(lines 977 983) no Hoare annotation was computed. [2022-11-19 06:36:56,059 INFO L895 garLoopResultBuilder]: At program point L977-1(lines 977 983) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) [2022-11-19 06:36:56,059 INFO L895 garLoopResultBuilder]: At program point L622(lines 577 624) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 1)) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2))) (or (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) (< ~waterLevel~0 3) .cse2) (and .cse3 .cse1 (= 0 ~systemActive~0)) (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse4 .cse2) (and .cse3 .cse0 .cse1 .cse4))) [2022-11-19 06:36:56,059 INFO L895 garLoopResultBuilder]: At program point L589(line 589) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 1)) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (<= ~waterLevel~0 2))) (or (and .cse0 .cse1 (<= 1 ~switchedOnBeforeTS~0) (< ~waterLevel~0 3) .cse2) (and .cse3 .cse1 (= 0 ~systemActive~0)) (and (<= 2 ~waterLevel~0) .cse0 .cse1 .cse4 .cse2) (and .cse3 .cse0 .cse1 .cse4))) [2022-11-19 06:36:56,060 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-19 06:36:56,060 INFO L899 garLoopResultBuilder]: For program point L578(lines 577 624) no Hoare annotation was computed. [2022-11-19 06:36:56,060 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-19 06:36:56,060 INFO L899 garLoopResultBuilder]: For program point L607(lines 607 620) no Hoare annotation was computed. [2022-11-19 06:36:56,060 INFO L895 garLoopResultBuilder]: At program point L508(lines 508 515) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (<= ~methaneLevelCritical~0 0) (<= 0 ~methaneLevelCritical~0) (= ~waterLevel~0 1)) [2022-11-19 06:36:56,061 INFO L902 garLoopResultBuilder]: At program point L508-2(lines 508 515) the Hoare annotation is: true [2022-11-19 06:36:56,061 INFO L895 garLoopResultBuilder]: At program point L599(line 599) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2022-11-19 06:36:56,061 INFO L902 garLoopResultBuilder]: At program point L628(lines 567 632) the Hoare annotation is: true [2022-11-19 06:36:56,061 INFO L895 garLoopResultBuilder]: At program point L979(line 979) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 1 ~systemActive~0) .cse0) (and (not (= ~waterLevel~0 1)) .cse0))) [2022-11-19 06:36:56,061 INFO L899 garLoopResultBuilder]: For program point L587(lines 587 593) no Hoare annotation was computed. [2022-11-19 06:36:56,062 INFO L899 garLoopResultBuilder]: For program point L587-1(lines 587 593) no Hoare annotation was computed. [2022-11-19 06:36:56,062 INFO L895 garLoopResultBuilder]: At program point L625(lines 576 626) the Hoare annotation is: false [2022-11-19 06:36:56,062 INFO L899 garLoopResultBuilder]: For program point L613(lines 613 619) no Hoare annotation was computed. [2022-11-19 06:36:56,062 INFO L895 garLoopResultBuilder]: At program point L613-2(lines 607 620) the Hoare annotation is: (let ((.cse3 (< ~waterLevel~0 3)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0) .cse3 .cse4) (and .cse0 .cse2 (= 0 ~systemActive~0)) (and (<= 2 ~waterLevel~0) .cse1 .cse2 (<= ~waterLevel~0 2) .cse4))) [2022-11-19 06:36:56,063 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 786 810) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,063 INFO L895 garLoopResultBuilder]: At program point L800(line 800) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (= ~pumpRunning~0 0) (or (<= 2 ~waterLevel~0) (and (< 0 (+ |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 1)) (<= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)))) (not (< ~waterLevel~0 3))))) [2022-11-19 06:36:56,063 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 786 810) no Hoare annotation was computed. [2022-11-19 06:36:56,063 INFO L895 garLoopResultBuilder]: At program point L794(lines 794 802) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (= ~pumpRunning~0 0) (or (<= 2 ~waterLevel~0) (and (< 0 (+ |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 1)) (<= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0)))) (not (< ~waterLevel~0 3))))) [2022-11-19 06:36:56,064 INFO L895 garLoopResultBuilder]: At program point L790(lines 790 807) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,064 INFO L895 garLoopResultBuilder]: At program point L805(line 805) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,064 INFO L899 garLoopResultBuilder]: For program point L805-1(lines 786 810) no Hoare annotation was computed. [2022-11-19 06:36:56,064 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 654 665) no Hoare annotation was computed. [2022-11-19 06:36:56,065 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 654 665) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 1))) (.cse4 (not (= ~pumpRunning~0 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 (not (<= 2 |old(~waterLevel~0)|))) (or .cse4 .cse2 (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) (or .cse0 .cse1 .cse2 (not (<= 1 ~switchedOnBeforeTS~0)) (not (< |old(~waterLevel~0)| 3))) (or .cse4 .cse0 .cse2 .cse3))) [2022-11-19 06:36:56,065 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__lowWaterSensorENTRY(lines 812 836) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,065 INFO L895 garLoopResultBuilder]: At program point L826(line 826) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,065 INFO L895 garLoopResultBuilder]: At program point L822(line 822) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,066 INFO L899 garLoopResultBuilder]: For program point L820(lines 820 828) no Hoare annotation was computed. [2022-11-19 06:36:56,066 INFO L895 garLoopResultBuilder]: At program point L816(lines 816 833) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0))) (.cse3 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2 .cse3) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3))) [2022-11-19 06:36:56,066 INFO L895 garLoopResultBuilder]: At program point L831(line 831) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (= |old(~pumpRunning~0)| 1))) (.cse2 (not (<= 1 ~switchedOnBeforeTS~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (not (< ~waterLevel~0 3))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or (not (<= ~waterLevel~0 0)) .cse0 .cse1 .cse2))) [2022-11-19 06:36:56,066 INFO L899 garLoopResultBuilder]: For program point L831-1(lines 812 836) no Hoare annotation was computed. [2022-11-19 06:36:56,067 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__lowWaterSensorEXIT(lines 812 836) no Hoare annotation was computed. [2022-11-19 06:36:56,067 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 890 898) no Hoare annotation was computed. [2022-11-19 06:36:56,067 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 890 898) the Hoare annotation is: true [2022-11-19 06:36:56,071 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:36:56,073 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-19 06:36:56,141 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 19.11 06:36:56 BoogieIcfgContainer [2022-11-19 06:36:56,141 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-19 06:36:56,142 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-19 06:36:56,142 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-19 06:36:56,143 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-19 06:36:56,143 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:35:37" (3/4) ... [2022-11-19 06:36:56,146 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-19 06:36:56,157 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-19 06:36:56,168 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-19 06:36:56,168 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-19 06:36:56,168 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-19 06:36:56,169 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-19 06:36:56,169 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:36:56,169 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-19 06:36:56,169 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2022-11-19 06:36:56,170 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-19 06:36:56,177 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 54 nodes and edges [2022-11-19 06:36:56,181 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2022-11-19 06:36:56,182 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 6 nodes and edges [2022-11-19 06:36:56,183 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 06:36:56,183 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 06:36:56,221 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= aux-isPumpRunning()-aux)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-19 06:36:56,222 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && ((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || (((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(pumpRunning) == 1)) || (((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && (((((!(1 == systemActive) || (((((tmp <= 0 || tmp <= methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS))) [2022-11-19 06:36:56,222 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((((((pumpRunning == 0 && 1 == systemActive) && (tmp <= 0 || tmp <= methaneLevelCritical)) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((1 < tmp && tmp <= 2) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel <= 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((((((pumpRunning == 0 && 1 == systemActive) && (tmp <= 0 || tmp <= methaneLevelCritical)) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || (((1 < tmp && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3)) [2022-11-19 06:36:56,222 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 06:36:56,223 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 06:36:56,223 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(2 <= \old(waterLevel))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || (((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(pumpRunning) == 1)) || (((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) <= 2))) && (((((!(1 == systemActive) || (((((tmp <= 0 || tmp <= methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) [2022-11-19 06:36:56,223 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2022-11-19 06:36:56,224 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) [2022-11-19 06:36:56,225 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && (2 <= waterLevel || (0 < tmp + 1 && tmp <= 0)))) || !(waterLevel < 3)) [2022-11-19 06:36:56,256 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/witness.graphml [2022-11-19 06:36:56,256 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-19 06:36:56,257 INFO L158 Benchmark]: Toolchain (without parser) took 80598.86ms. Allocated memory was 132.1MB in the beginning and 509.6MB in the end (delta: 377.5MB). Free memory was 95.3MB in the beginning and 200.4MB in the end (delta: -105.1MB). Peak memory consumption was 272.0MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,257 INFO L158 Benchmark]: CDTParser took 0.28ms. Allocated memory is still 132.1MB. Free memory is still 112.5MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-19 06:36:56,258 INFO L158 Benchmark]: CACSL2BoogieTranslator took 588.08ms. Allocated memory is still 132.1MB. Free memory was 95.1MB in the beginning and 99.0MB in the end (delta: -3.9MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,258 INFO L158 Benchmark]: Boogie Procedure Inliner took 57.29ms. Allocated memory is still 132.1MB. Free memory was 99.0MB in the beginning and 96.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,259 INFO L158 Benchmark]: Boogie Preprocessor took 36.83ms. Allocated memory is still 132.1MB. Free memory was 96.5MB in the beginning and 94.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,259 INFO L158 Benchmark]: RCFGBuilder took 846.97ms. Allocated memory is still 132.1MB. Free memory was 94.9MB in the beginning and 68.6MB in the end (delta: 26.3MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,259 INFO L158 Benchmark]: TraceAbstraction took 78944.53ms. Allocated memory was 132.1MB in the beginning and 509.6MB in the end (delta: 377.5MB). Free memory was 68.1MB in the beginning and 206.7MB in the end (delta: -138.6MB). Peak memory consumption was 278.6MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,260 INFO L158 Benchmark]: Witness Printer took 114.34ms. Allocated memory is still 509.6MB. Free memory was 205.7MB in the beginning and 200.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-19 06:36:56,262 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.28ms. Allocated memory is still 132.1MB. Free memory is still 112.5MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 588.08ms. Allocated memory is still 132.1MB. Free memory was 95.1MB in the beginning and 99.0MB in the end (delta: -3.9MB). Peak memory consumption was 10.5MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 57.29ms. Allocated memory is still 132.1MB. Free memory was 99.0MB in the beginning and 96.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 36.83ms. Allocated memory is still 132.1MB. Free memory was 96.5MB in the beginning and 94.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 846.97ms. Allocated memory is still 132.1MB. Free memory was 94.9MB in the beginning and 68.6MB in the end (delta: 26.3MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. * TraceAbstraction took 78944.53ms. Allocated memory was 132.1MB in the beginning and 509.6MB in the end (delta: 377.5MB). Free memory was 68.1MB in the beginning and 206.7MB in the end (delta: -138.6MB). Peak memory consumption was 278.6MB. Max. memory is 16.1GB. * Witness Printer took 114.34ms. Allocated memory is still 509.6MB. Free memory was 205.7MB in the beginning and 200.4MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 561]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 74 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 78.8s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 10.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 18.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 3458 SdHoareTripleChecker+Valid, 5.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 3435 mSDsluCounter, 4107 SdHoareTripleChecker+Invalid, 4.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3063 mSDsCounter, 1982 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 5371 IncrementalHoareTripleChecker+Invalid, 7353 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1982 mSolverCounterUnsat, 1044 mSDtfsCounter, 5371 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1050 GetRequests, 744 SyntacticMatches, 26 SemanticMatches, 280 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8496 ImplicationChecksByTransitivity, 29.8s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=766occurred in iteration=10, InterpolantAutomatonStates: 144, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 11 MinimizatonAttempts, 370 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 43 LocationsWithAnnotation, 2294 PreInvPairs, 2716 NumberOfFragments, 3228 HoareAnnotationTreeSize, 2294 FomulaSimplifications, 11604 FormulaSimplificationTreeSizeReduction, 1.4s HoareSimplificationTime, 43 FomulaSimplificationsInter, 61687 FormulaSimplificationTreeSizeReductionInter, 17.0s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 6.3s InterpolantComputationTime, 863 NumberOfCodeBlocks, 863 NumberOfCodeBlocksAsserted, 14 NumberOfCheckSat, 1119 ConstructedInterpolants, 0 QuantifiedInterpolants, 3743 SizeOfPredicates, 28 NumberOfNonLiveVariables, 1171 ConjunctsInSsa, 60 ConjunctsInUnsatCore, 17 InterpolantComputations, 8 PerfectInterpolantSequences, 518/665 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 842]: Loop Invariant Derived loop invariant: ((((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((waterLevel == 1 && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((waterLevel <= 0 && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 790]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(1 == systemActive)) || !(waterLevel < 3)) && ((((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1)) && ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) || pumpRunning == 1) - InvariantResult [Line: 1003]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(0 == systemActive)) || (pumpRunning == 0 && (\old(waterLevel) == waterLevel || waterLevel == 1))) && (((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel) && 1 <= aux-isPumpRunning()-aux)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && ((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || ((\old(waterLevel) == waterLevel && 1 <= aux-isPumpRunning()-aux) && pumpRunning == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 1008]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && (((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || ((((((pumpRunning == 0 && 1 == systemActive) && (tmp <= 0 || tmp <= methaneLevelCritical)) && tmp == waterLevel) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((((((1 < tmp && tmp <= 2) && \old(waterLevel) == waterLevel) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) <= 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || (((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel <= 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS))) || ((((((pumpRunning == 0 && 1 == systemActive) && (tmp <= 0 || tmp <= methaneLevelCritical)) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (((pumpRunning == 0 && 1 == systemActive) && tmp == waterLevel) && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || (((1 < tmp && tmp == waterLevel) && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) < 3)) - InvariantResult [Line: 576]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 794]: Loop Invariant Derived loop invariant: ((((!(waterLevel == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS)) && (((!(waterLevel <= 0) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(1 <= switchedOnBeforeTS))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (pumpRunning == 0 && (2 <= waterLevel || (0 < tmp + 1 && tmp <= 0)))) || !(waterLevel < 3)) - InvariantResult [Line: 418]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 428]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 838]: Loop Invariant Derived loop invariant: (((((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(2 <= \old(waterLevel))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || (((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(pumpRunning) == 1)) || (((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) <= 2))) && (((((!(1 == systemActive) || (((((tmp <= 0 || tmp <= methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS)))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 577]: Loop Invariant Derived loop invariant: ((((((1 == systemActive && splverifierCounter == 0) && 1 <= switchedOnBeforeTS) && waterLevel < 3) && pumpRunning == 1) || ((pumpRunning == 0 && splverifierCounter == 0) && 0 == systemActive)) || ((((2 <= waterLevel && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && pumpRunning == 1)) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 2) - InvariantResult [Line: 561]: Loop Invariant Derived loop invariant: (((((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(1 <= \old(switchedOnBeforeTS))) || !(\old(waterLevel) < 3)) && (((!(1 == systemActive) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) < 3))) && (!(\old(pumpRunning) == 0) || !(0 == systemActive)) - InvariantResult [Line: 508]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 1 == systemActive) && methaneLevelCritical <= 0) && 0 <= methaneLevelCritical) && waterLevel == 1 - InvariantResult [Line: 977]: Loop Invariant Derived loop invariant: pumpRunning == 0 && splverifierCounter == 0 - InvariantResult [Line: 567]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 508]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 765]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) || pumpRunning == 0) || !(0 == systemActive)) && ((((((((((tmp <= 0 || tmp <= methaneLevelCritical) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1) || !(1 == systemActive)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && waterLevel == 1) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(2 <= \old(waterLevel)))) && (((((!(\old(waterLevel) == 1) || !(1 == systemActive)) || (((((pumpRunning == 0 && \old(waterLevel) == waterLevel + 1) && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(pumpRunning) == 1)) || (((((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) && (tmp <= 0 || tmp <= methaneLevelCritical)) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(1 <= \old(switchedOnBeforeTS)))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || waterLevel == 1) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || (pumpRunning == 0 && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((2 <= waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1)) || !(\old(waterLevel) <= 2))) && ((((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || !(2 <= \old(waterLevel)))) && (((((!(1 == systemActive) || (((((tmp <= 0 || tmp <= methaneLevelCritical) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp)) && pumpRunning == 1)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && (tmp <= 0 || tmp <= methaneLevelCritical)) && \old(waterLevel) == waterLevel) && 1 <= switchedOnBeforeTS) && (0 < tmp + 1 || methaneLevelCritical <= tmp))) || !(\old(waterLevel) <= 0)) || !(1 <= \old(switchedOnBeforeTS))) RESULT: Ultimate proved your program to be correct! [2022-11-19 06:36:56,306 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e3934bca-82f0-4d41-b4cc-52dda4902d42/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE