./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 8393723b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash b57a794fa6b429f14911ed2b6a28ecb30bf580e5cb37ae05e7120c2d485c2d18 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-8393723 [2022-11-19 06:37:33,215 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-19 06:37:33,216 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-19 06:37:33,235 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-19 06:37:33,236 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-19 06:37:33,237 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-19 06:37:33,238 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-19 06:37:33,240 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-19 06:37:33,241 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-19 06:37:33,242 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-19 06:37:33,243 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-19 06:37:33,244 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-19 06:37:33,245 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-19 06:37:33,246 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-19 06:37:33,247 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-19 06:37:33,248 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-19 06:37:33,249 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-19 06:37:33,250 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-19 06:37:33,252 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-19 06:37:33,254 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-19 06:37:33,256 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-19 06:37:33,257 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-19 06:37:33,258 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-19 06:37:33,259 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-19 06:37:33,263 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-19 06:37:33,263 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-19 06:37:33,264 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-19 06:37:33,265 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-19 06:37:33,265 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-19 06:37:33,266 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-19 06:37:33,267 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-19 06:37:33,267 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-19 06:37:33,268 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-19 06:37:33,269 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-19 06:37:33,270 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-19 06:37:33,270 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-19 06:37:33,271 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-19 06:37:33,271 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-19 06:37:33,272 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-19 06:37:33,273 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-19 06:37:33,273 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-19 06:37:33,274 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-19 06:37:33,313 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-19 06:37:33,315 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-19 06:37:33,315 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-19 06:37:33,316 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-19 06:37:33,316 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-19 06:37:33,317 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-19 06:37:33,317 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-19 06:37:33,317 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-19 06:37:33,317 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-19 06:37:33,317 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-19 06:37:33,318 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-19 06:37:33,319 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-19 06:37:33,319 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-19 06:37:33,319 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-19 06:37:33,319 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-19 06:37:33,320 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-19 06:37:33,320 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-19 06:37:33,320 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-19 06:37:33,321 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-19 06:37:33,321 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-19 06:37:33,321 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-19 06:37:33,321 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-19 06:37:33,322 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-19 06:37:33,322 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-19 06:37:33,322 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-19 06:37:33,322 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-19 06:37:33,322 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-19 06:37:33,323 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-19 06:37:33,323 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-19 06:37:33,323 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-19 06:37:33,323 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-19 06:37:33,324 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-19 06:37:33,332 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 06:37:33,332 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-19 06:37:33,333 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-19 06:37:33,333 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-19 06:37:33,333 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-19 06:37:33,333 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-19 06:37:33,333 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-19 06:37:33,334 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-19 06:37:33,334 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-19 06:37:33,334 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> b57a794fa6b429f14911ed2b6a28ecb30bf580e5cb37ae05e7120c2d485c2d18 [2022-11-19 06:37:33,615 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-19 06:37:33,635 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-19 06:37:33,639 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-19 06:37:33,641 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-19 06:37:33,642 INFO L275 PluginConnector]: CDTParser initialized [2022-11-19 06:37:33,643 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/../../sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c [2022-11-19 06:37:33,721 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/data/73d000c23/f91040b023184919982cb4a2595a71fe/FLAG5f2809189 [2022-11-19 06:37:34,324 INFO L306 CDTParser]: Found 1 translation units. [2022-11-19 06:37:34,324 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c [2022-11-19 06:37:34,347 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/data/73d000c23/f91040b023184919982cb4a2595a71fe/FLAG5f2809189 [2022-11-19 06:37:34,624 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/data/73d000c23/f91040b023184919982cb4a2595a71fe [2022-11-19 06:37:34,626 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-19 06:37:34,628 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-19 06:37:34,629 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-19 06:37:34,629 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-19 06:37:34,640 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-19 06:37:34,641 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 06:37:34" (1/1) ... [2022-11-19 06:37:34,642 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@63d6ce09 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:34, skipping insertion in model container [2022-11-19 06:37:34,642 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 06:37:34" (1/1) ... [2022-11-19 06:37:34,650 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-19 06:37:34,722 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-19 06:37:35,023 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c[18075,18088] [2022-11-19 06:37:35,032 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 06:37:35,048 INFO L203 MainTranslator]: Completed pre-run [2022-11-19 06:37:35,161 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/sv-benchmarks/c/product-lines/minepump_spec5_product60.cil.c[18075,18088] [2022-11-19 06:37:35,174 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 06:37:35,191 INFO L208 MainTranslator]: Completed translation [2022-11-19 06:37:35,191 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35 WrapperNode [2022-11-19 06:37:35,191 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-19 06:37:35,192 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-19 06:37:35,193 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-19 06:37:35,193 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-19 06:37:35,200 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,213 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,246 INFO L138 Inliner]: procedures = 60, calls = 106, calls flagged for inlining = 28, calls inlined = 25, statements flattened = 235 [2022-11-19 06:37:35,251 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-19 06:37:35,252 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-19 06:37:35,252 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-19 06:37:35,252 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-19 06:37:35,259 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,259 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,261 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,262 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,267 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,272 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,273 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,281 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,283 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-19 06:37:35,284 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-19 06:37:35,299 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-19 06:37:35,299 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-19 06:37:35,300 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (1/1) ... [2022-11-19 06:37:35,327 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 06:37:35,336 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:37:35,348 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-19 06:37:35,382 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-19 06:37:35,406 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-19 06:37:35,406 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-19 06:37:35,406 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-19 06:37:35,406 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-19 06:37:35,406 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-19 06:37:35,407 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-19 06:37:35,407 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-19 06:37:35,407 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:37:35,407 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:37:35,407 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-19 06:37:35,407 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-19 06:37:35,408 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-19 06:37:35,408 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-19 06:37:35,408 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-19 06:37:35,408 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-19 06:37:35,408 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-19 06:37:35,408 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-19 06:37:35,408 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-19 06:37:35,409 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-19 06:37:35,409 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-19 06:37:35,533 INFO L235 CfgBuilder]: Building ICFG [2022-11-19 06:37:35,535 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-19 06:37:35,980 INFO L276 CfgBuilder]: Performing block encoding [2022-11-19 06:37:36,106 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-19 06:37:36,107 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-19 06:37:36,109 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:37:36 BoogieIcfgContainer [2022-11-19 06:37:36,109 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-19 06:37:36,111 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-19 06:37:36,112 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-19 06:37:36,118 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-19 06:37:36,118 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 19.11 06:37:34" (1/3) ... [2022-11-19 06:37:36,119 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6aa46e37 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 06:37:36, skipping insertion in model container [2022-11-19 06:37:36,119 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 06:37:35" (2/3) ... [2022-11-19 06:37:36,119 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6aa46e37 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 06:37:36, skipping insertion in model container [2022-11-19 06:37:36,119 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:37:36" (3/3) ... [2022-11-19 06:37:36,121 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product60.cil.c [2022-11-19 06:37:36,167 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-19 06:37:36,167 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-19 06:37:36,241 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-19 06:37:36,252 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@469e98c3, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-19 06:37:36,252 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-19 06:37:36,257 INFO L276 IsEmpty]: Start isEmpty. Operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2022-11-19 06:37:36,268 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-19 06:37:36,268 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:36,269 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:36,270 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:36,277 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:36,278 INFO L85 PathProgramCache]: Analyzing trace with hash -420238116, now seen corresponding path program 1 times [2022-11-19 06:37:36,288 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:36,289 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1296264459] [2022-11-19 06:37:36,289 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:36,290 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:36,435 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:36,545 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:36,548 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:36,548 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1296264459] [2022-11-19 06:37:36,549 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1296264459] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:36,549 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:36,549 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-19 06:37:36,551 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [354515116] [2022-11-19 06:37:36,552 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:36,557 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-19 06:37:36,559 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:36,600 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-19 06:37:36,601 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 06:37:36,604 INFO L87 Difference]: Start difference. First operand has 66 states, 42 states have (on average 1.4523809523809523) internal successors, (61), 51 states have internal predecessors, (61), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:36,713 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:36,714 INFO L93 Difference]: Finished difference Result 130 states and 179 transitions. [2022-11-19 06:37:36,718 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-19 06:37:36,720 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-19 06:37:36,720 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:36,729 INFO L225 Difference]: With dead ends: 130 [2022-11-19 06:37:36,729 INFO L226 Difference]: Without dead ends: 61 [2022-11-19 06:37:36,733 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 06:37:36,736 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 68 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:36,737 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 68 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:37:36,755 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 61 states. [2022-11-19 06:37:36,776 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 61 to 61. [2022-11-19 06:37:36,777 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 61 states, 39 states have (on average 1.358974358974359) internal successors, (53), 47 states have internal predecessors, (53), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2022-11-19 06:37:36,779 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 61 states to 61 states and 80 transitions. [2022-11-19 06:37:36,780 INFO L78 Accepts]: Start accepts. Automaton has 61 states and 80 transitions. Word has length 21 [2022-11-19 06:37:36,781 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:36,781 INFO L495 AbstractCegarLoop]: Abstraction has 61 states and 80 transitions. [2022-11-19 06:37:36,781 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:36,782 INFO L276 IsEmpty]: Start isEmpty. Operand 61 states and 80 transitions. [2022-11-19 06:37:36,783 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-19 06:37:36,784 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:36,784 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:36,784 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-19 06:37:36,785 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:36,785 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:36,785 INFO L85 PathProgramCache]: Analyzing trace with hash -1532168176, now seen corresponding path program 1 times [2022-11-19 06:37:36,786 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:36,786 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1360506762] [2022-11-19 06:37:36,786 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:36,786 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:36,801 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:36,874 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:36,879 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:36,880 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1360506762] [2022-11-19 06:37:36,880 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1360506762] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:36,880 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:36,880 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 06:37:36,881 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1407334050] [2022-11-19 06:37:36,881 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:36,882 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 06:37:36,882 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:36,883 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 06:37:36,883 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:37:36,883 INFO L87 Difference]: Start difference. First operand 61 states and 80 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:36,954 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:36,955 INFO L93 Difference]: Finished difference Result 94 states and 122 transitions. [2022-11-19 06:37:36,956 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 06:37:36,957 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-19 06:37:36,958 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:36,959 INFO L225 Difference]: With dead ends: 94 [2022-11-19 06:37:36,960 INFO L226 Difference]: Without dead ends: 53 [2022-11-19 06:37:36,961 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:37:36,963 INFO L413 NwaCegarLoop]: 54 mSDtfsCounter, 14 mSDsluCounter, 38 mSDsCounter, 0 mSdLazyCounter, 26 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 92 SdHoareTripleChecker+Invalid, 26 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 26 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:36,965 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 92 Invalid, 26 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 26 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-19 06:37:36,966 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-19 06:37:36,973 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-19 06:37:36,975 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3823529411764706) internal successors, (47), 42 states have internal predecessors, (47), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-19 06:37:36,977 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 69 transitions. [2022-11-19 06:37:36,979 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 69 transitions. Word has length 22 [2022-11-19 06:37:36,979 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:36,980 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 69 transitions. [2022-11-19 06:37:36,981 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:36,981 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 69 transitions. [2022-11-19 06:37:36,983 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2022-11-19 06:37:36,984 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:36,984 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:36,985 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-19 06:37:36,985 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:36,986 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:36,991 INFO L85 PathProgramCache]: Analyzing trace with hash -1247703669, now seen corresponding path program 1 times [2022-11-19 06:37:36,991 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:36,991 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1497772220] [2022-11-19 06:37:36,991 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:36,992 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:37,029 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:37,136 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:37,136 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:37,137 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1497772220] [2022-11-19 06:37:37,137 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1497772220] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:37,137 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:37,137 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-19 06:37:37,138 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1362807714] [2022-11-19 06:37:37,138 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:37,138 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-19 06:37:37,138 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:37,139 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-19 06:37:37,139 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2022-11-19 06:37:37,139 INFO L87 Difference]: Start difference. First operand 53 states and 69 transitions. Second operand has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 06:37:37,241 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:37,242 INFO L93 Difference]: Finished difference Result 140 states and 183 transitions. [2022-11-19 06:37:37,242 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-19 06:37:37,242 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2022-11-19 06:37:37,243 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:37,244 INFO L225 Difference]: With dead ends: 140 [2022-11-19 06:37:37,244 INFO L226 Difference]: Without dead ends: 89 [2022-11-19 06:37:37,245 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2022-11-19 06:37:37,246 INFO L413 NwaCegarLoop]: 65 mSDtfsCounter, 90 mSDsluCounter, 81 mSDsCounter, 0 mSdLazyCounter, 45 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 94 SdHoareTripleChecker+Valid, 146 SdHoareTripleChecker+Invalid, 54 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 45 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:37,247 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [94 Valid, 146 Invalid, 54 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 45 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:37:37,248 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2022-11-19 06:37:37,262 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 86. [2022-11-19 06:37:37,262 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 56 states have (on average 1.375) internal successors, (77), 67 states have internal predecessors, (77), 17 states have call successors, (17), 12 states have call predecessors, (17), 12 states have return successors, (18), 13 states have call predecessors, (18), 17 states have call successors, (18) [2022-11-19 06:37:37,264 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 112 transitions. [2022-11-19 06:37:37,264 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 112 transitions. Word has length 25 [2022-11-19 06:37:37,264 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:37,265 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 112 transitions. [2022-11-19 06:37:37,265 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-19 06:37:37,265 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 112 transitions. [2022-11-19 06:37:37,266 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2022-11-19 06:37:37,291 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:37,291 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:37,291 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-19 06:37:37,292 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:37,292 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:37,292 INFO L85 PathProgramCache]: Analyzing trace with hash -355442781, now seen corresponding path program 1 times [2022-11-19 06:37:37,293 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:37,293 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [723395882] [2022-11-19 06:37:37,293 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:37,293 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:37,310 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:37,493 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-19 06:37:37,494 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:37,494 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [723395882] [2022-11-19 06:37:37,494 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [723395882] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:37,494 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:37,495 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-19 06:37:37,495 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [715912610] [2022-11-19 06:37:37,495 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:37,495 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-19 06:37:37,496 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:37,496 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-19 06:37:37,496 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-19 06:37:37,497 INFO L87 Difference]: Start difference. First operand 86 states and 112 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:37,701 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:37,701 INFO L93 Difference]: Finished difference Result 209 states and 282 transitions. [2022-11-19 06:37:37,702 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-19 06:37:37,702 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2022-11-19 06:37:37,702 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:37,704 INFO L225 Difference]: With dead ends: 209 [2022-11-19 06:37:37,704 INFO L226 Difference]: Without dead ends: 125 [2022-11-19 06:37:37,705 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-19 06:37:37,706 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 35 mSDsluCounter, 206 mSDsCounter, 0 mSdLazyCounter, 122 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 270 SdHoareTripleChecker+Invalid, 130 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 122 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:37,707 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [36 Valid, 270 Invalid, 130 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 122 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:37:37,708 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 125 states. [2022-11-19 06:37:37,727 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 125 to 118. [2022-11-19 06:37:37,736 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 118 states, 79 states have (on average 1.2911392405063291) internal successors, (102), 89 states have internal predecessors, (102), 21 states have call successors, (21), 17 states have call predecessors, (21), 17 states have return successors, (27), 20 states have call predecessors, (27), 21 states have call successors, (27) [2022-11-19 06:37:37,738 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 118 states to 118 states and 150 transitions. [2022-11-19 06:37:37,738 INFO L78 Accepts]: Start accepts. Automaton has 118 states and 150 transitions. Word has length 28 [2022-11-19 06:37:37,738 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:37,738 INFO L495 AbstractCegarLoop]: Abstraction has 118 states and 150 transitions. [2022-11-19 06:37:37,739 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 06:37:37,739 INFO L276 IsEmpty]: Start isEmpty. Operand 118 states and 150 transitions. [2022-11-19 06:37:37,740 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-19 06:37:37,740 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:37,741 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:37,741 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-19 06:37:37,741 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:37,742 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:37,742 INFO L85 PathProgramCache]: Analyzing trace with hash 1651985796, now seen corresponding path program 1 times [2022-11-19 06:37:37,742 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:37,742 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [984757375] [2022-11-19 06:37:37,742 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:37,743 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:37,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:37,823 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:37,823 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:37,824 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [984757375] [2022-11-19 06:37:37,824 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [984757375] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:37,824 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:37,825 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 06:37:37,825 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2107202364] [2022-11-19 06:37:37,828 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:37,829 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 06:37:37,830 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:37,831 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 06:37:37,831 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:37:37,831 INFO L87 Difference]: Start difference. First operand 118 states and 150 transitions. Second operand has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-19 06:37:37,906 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:37,906 INFO L93 Difference]: Finished difference Result 236 states and 300 transitions. [2022-11-19 06:37:37,907 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 06:37:37,907 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 36 [2022-11-19 06:37:37,907 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:37,909 INFO L225 Difference]: With dead ends: 236 [2022-11-19 06:37:37,909 INFO L226 Difference]: Without dead ends: 120 [2022-11-19 06:37:37,910 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 06:37:37,911 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 30 mSDsluCounter, 52 mSDsCounter, 0 mSdLazyCounter, 39 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 30 SdHoareTripleChecker+Valid, 128 SdHoareTripleChecker+Invalid, 39 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 39 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:37,919 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [30 Valid, 128 Invalid, 39 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 39 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-19 06:37:37,921 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 120 states. [2022-11-19 06:37:37,948 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 120 to 118. [2022-11-19 06:37:37,951 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 118 states, 79 states have (on average 1.2784810126582278) internal successors, (101), 89 states have internal predecessors, (101), 21 states have call successors, (21), 17 states have call predecessors, (21), 17 states have return successors, (25), 20 states have call predecessors, (25), 21 states have call successors, (25) [2022-11-19 06:37:37,954 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 118 states to 118 states and 147 transitions. [2022-11-19 06:37:37,958 INFO L78 Accepts]: Start accepts. Automaton has 118 states and 147 transitions. Word has length 36 [2022-11-19 06:37:37,958 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:37,959 INFO L495 AbstractCegarLoop]: Abstraction has 118 states and 147 transitions. [2022-11-19 06:37:37,959 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.333333333333334) internal successors, (28), 3 states have internal predecessors, (28), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2022-11-19 06:37:37,959 INFO L276 IsEmpty]: Start isEmpty. Operand 118 states and 147 transitions. [2022-11-19 06:37:37,960 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2022-11-19 06:37:37,964 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:37,965 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:37,965 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-19 06:37:37,965 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:37,966 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:37,966 INFO L85 PathProgramCache]: Analyzing trace with hash 835720044, now seen corresponding path program 1 times [2022-11-19 06:37:37,966 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:37,966 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [782935758] [2022-11-19 06:37:37,967 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:37,967 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:37,979 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:38,363 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:38,363 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:38,364 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [782935758] [2022-11-19 06:37:38,364 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [782935758] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:38,364 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:38,364 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-19 06:37:38,365 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1210403010] [2022-11-19 06:37:38,365 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:38,365 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-19 06:37:38,365 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:38,366 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-19 06:37:38,366 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2022-11-19 06:37:38,366 INFO L87 Difference]: Start difference. First operand 118 states and 147 transitions. Second operand has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-19 06:37:38,550 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:38,550 INFO L93 Difference]: Finished difference Result 369 states and 463 transitions. [2022-11-19 06:37:38,551 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2022-11-19 06:37:38,551 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 33 [2022-11-19 06:37:38,551 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:38,553 INFO L225 Difference]: With dead ends: 369 [2022-11-19 06:37:38,554 INFO L226 Difference]: Without dead ends: 253 [2022-11-19 06:37:38,555 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 4 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=20, Invalid=36, Unknown=0, NotChecked=0, Total=56 [2022-11-19 06:37:38,556 INFO L413 NwaCegarLoop]: 90 mSDtfsCounter, 119 mSDsluCounter, 157 mSDsCounter, 0 mSdLazyCounter, 150 mSolverCounterSat, 24 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 121 SdHoareTripleChecker+Valid, 247 SdHoareTripleChecker+Invalid, 174 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 24 IncrementalHoareTripleChecker+Valid, 150 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:38,557 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [121 Valid, 247 Invalid, 174 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [24 Valid, 150 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 06:37:38,558 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 253 states. [2022-11-19 06:37:38,592 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 253 to 246. [2022-11-19 06:37:38,593 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 246 states, 165 states have (on average 1.2787878787878788) internal successors, (211), 183 states have internal predecessors, (211), 44 states have call successors, (44), 37 states have call predecessors, (44), 36 states have return successors, (53), 39 states have call predecessors, (53), 44 states have call successors, (53) [2022-11-19 06:37:38,595 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 246 states to 246 states and 308 transitions. [2022-11-19 06:37:38,595 INFO L78 Accepts]: Start accepts. Automaton has 246 states and 308 transitions. Word has length 33 [2022-11-19 06:37:38,595 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:38,595 INFO L495 AbstractCegarLoop]: Abstraction has 246 states and 308 transitions. [2022-11-19 06:37:38,596 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-19 06:37:38,596 INFO L276 IsEmpty]: Start isEmpty. Operand 246 states and 308 transitions. [2022-11-19 06:37:38,597 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2022-11-19 06:37:38,597 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:38,597 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:38,598 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-19 06:37:38,598 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:38,598 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:38,598 INFO L85 PathProgramCache]: Analyzing trace with hash 650926145, now seen corresponding path program 1 times [2022-11-19 06:37:38,599 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:38,599 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [287481630] [2022-11-19 06:37:38,599 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:38,599 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:38,621 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:38,869 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:37:38,869 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:38,869 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [287481630] [2022-11-19 06:37:38,870 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [287481630] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 06:37:38,870 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 06:37:38,870 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-19 06:37:38,870 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1277207234] [2022-11-19 06:37:38,870 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 06:37:38,871 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 06:37:38,871 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:38,872 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 06:37:38,872 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-19 06:37:38,872 INFO L87 Difference]: Start difference. First operand 246 states and 308 transitions. Second operand has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 06:37:39,458 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:39,458 INFO L93 Difference]: Finished difference Result 568 states and 729 transitions. [2022-11-19 06:37:39,463 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-19 06:37:39,464 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 36 [2022-11-19 06:37:39,464 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:39,468 INFO L225 Difference]: With dead ends: 568 [2022-11-19 06:37:39,468 INFO L226 Difference]: Without dead ends: 415 [2022-11-19 06:37:39,469 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-19 06:37:39,470 INFO L413 NwaCegarLoop]: 77 mSDtfsCounter, 207 mSDsluCounter, 203 mSDsCounter, 0 mSdLazyCounter, 341 mSolverCounterSat, 81 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 212 SdHoareTripleChecker+Valid, 280 SdHoareTripleChecker+Invalid, 422 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 81 IncrementalHoareTripleChecker+Valid, 341 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:39,471 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [212 Valid, 280 Invalid, 422 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [81 Valid, 341 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-19 06:37:39,472 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 415 states. [2022-11-19 06:37:39,538 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 415 to 344. [2022-11-19 06:37:39,539 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 344 states, 234 states have (on average 1.2692307692307692) internal successors, (297), 259 states have internal predecessors, (297), 59 states have call successors, (59), 46 states have call predecessors, (59), 50 states have return successors, (74), 57 states have call predecessors, (74), 59 states have call successors, (74) [2022-11-19 06:37:39,541 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 344 states to 344 states and 430 transitions. [2022-11-19 06:37:39,542 INFO L78 Accepts]: Start accepts. Automaton has 344 states and 430 transitions. Word has length 36 [2022-11-19 06:37:39,542 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:39,542 INFO L495 AbstractCegarLoop]: Abstraction has 344 states and 430 transitions. [2022-11-19 06:37:39,543 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.7142857142857144) internal successors, (26), 7 states have internal predecessors, (26), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-19 06:37:39,543 INFO L276 IsEmpty]: Start isEmpty. Operand 344 states and 430 transitions. [2022-11-19 06:37:39,545 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 63 [2022-11-19 06:37:39,545 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:39,546 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:39,546 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-19 06:37:39,546 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:39,547 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:39,547 INFO L85 PathProgramCache]: Analyzing trace with hash -1127725577, now seen corresponding path program 1 times [2022-11-19 06:37:39,547 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:39,547 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1355637018] [2022-11-19 06:37:39,548 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:39,548 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:39,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:39,986 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 19 proven. 5 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-19 06:37:39,987 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:39,987 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1355637018] [2022-11-19 06:37:39,990 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1355637018] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:37:39,990 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [558378302] [2022-11-19 06:37:39,990 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:39,991 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:37:39,991 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:37:39,997 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:37:40,024 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-19 06:37:40,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:40,140 INFO L263 TraceCheckSpWp]: Trace formula consists of 332 conjuncts, 22 conjunts are in the unsatisfiable core [2022-11-19 06:37:40,146 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:37:40,361 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 27 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-19 06:37:40,361 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:37:40,556 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 16 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-19 06:37:40,556 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [558378302] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:37:40,556 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [37969941] [2022-11-19 06:37:40,575 INFO L159 IcfgInterpreter]: Started Sifa with 37 locations of interest [2022-11-19 06:37:40,575 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:37:40,579 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:37:40,584 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:37:40,585 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:37:43,844 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 50 for LOIs [2022-11-19 06:37:43,854 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-19 06:37:44,224 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 44 for LOIs [2022-11-19 06:37:44,231 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 06:37:44,264 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:37:48,813 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '4789#(and (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 2 |timeShift_getWaterLevel_#res#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= |old(~switchedOnBeforeTS~0)| 0))' at error location [2022-11-19 06:37:48,814 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:37:48,814 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:37:48,814 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 6, 6] total 18 [2022-11-19 06:37:48,814 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1053904993] [2022-11-19 06:37:48,814 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:37:48,815 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 18 states [2022-11-19 06:37:48,815 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:37:48,816 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 18 interpolants. [2022-11-19 06:37:48,817 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=246, Invalid=1734, Unknown=0, NotChecked=0, Total=1980 [2022-11-19 06:37:48,817 INFO L87 Difference]: Start difference. First operand 344 states and 430 transitions. Second operand has 18 states, 16 states have (on average 5.0625) internal successors, (81), 17 states have internal predecessors, (81), 6 states have call successors, (15), 5 states have call predecessors, (15), 6 states have return successors, (15), 7 states have call predecessors, (15), 6 states have call successors, (15) [2022-11-19 06:37:53,281 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:37:53,281 INFO L93 Difference]: Finished difference Result 1918 states and 2822 transitions. [2022-11-19 06:37:53,282 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 83 states. [2022-11-19 06:37:53,282 INFO L78 Accepts]: Start accepts. Automaton has has 18 states, 16 states have (on average 5.0625) internal successors, (81), 17 states have internal predecessors, (81), 6 states have call successors, (15), 5 states have call predecessors, (15), 6 states have return successors, (15), 7 states have call predecessors, (15), 6 states have call successors, (15) Word has length 62 [2022-11-19 06:37:53,282 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:37:53,294 INFO L225 Difference]: With dead ends: 1918 [2022-11-19 06:37:53,294 INFO L226 Difference]: Without dead ends: 1576 [2022-11-19 06:37:53,301 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 311 GetRequests, 189 SyntacticMatches, 1 SemanticMatches, 121 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5364 ImplicationChecksByTransitivity, 6.5s TimeCoverageRelationStatistics Valid=1362, Invalid=13644, Unknown=0, NotChecked=0, Total=15006 [2022-11-19 06:37:53,303 INFO L413 NwaCegarLoop]: 139 mSDtfsCounter, 1119 mSDsluCounter, 1207 mSDsCounter, 0 mSdLazyCounter, 2923 mSolverCounterSat, 1000 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1131 SdHoareTripleChecker+Valid, 1346 SdHoareTripleChecker+Invalid, 3923 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1000 IncrementalHoareTripleChecker+Valid, 2923 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.3s IncrementalHoareTripleChecker+Time [2022-11-19 06:37:53,305 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1131 Valid, 1346 Invalid, 3923 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1000 Valid, 2923 Invalid, 0 Unknown, 0 Unchecked, 2.3s Time] [2022-11-19 06:37:53,308 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1576 states. [2022-11-19 06:37:53,445 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1576 to 1003. [2022-11-19 06:37:53,449 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1003 states, 697 states have (on average 1.2754662840746054) internal successors, (889), 750 states have internal predecessors, (889), 160 states have call successors, (160), 138 states have call predecessors, (160), 145 states have return successors, (260), 148 states have call predecessors, (260), 160 states have call successors, (260) [2022-11-19 06:37:53,455 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1003 states to 1003 states and 1309 transitions. [2022-11-19 06:37:53,457 INFO L78 Accepts]: Start accepts. Automaton has 1003 states and 1309 transitions. Word has length 62 [2022-11-19 06:37:53,457 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:37:53,458 INFO L495 AbstractCegarLoop]: Abstraction has 1003 states and 1309 transitions. [2022-11-19 06:37:53,458 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 18 states, 16 states have (on average 5.0625) internal successors, (81), 17 states have internal predecessors, (81), 6 states have call successors, (15), 5 states have call predecessors, (15), 6 states have return successors, (15), 7 states have call predecessors, (15), 6 states have call successors, (15) [2022-11-19 06:37:53,458 INFO L276 IsEmpty]: Start isEmpty. Operand 1003 states and 1309 transitions. [2022-11-19 06:37:53,459 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 66 [2022-11-19 06:37:53,460 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:37:53,460 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:37:53,471 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-19 06:37:53,671 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:37:53,672 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:37:53,672 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:37:53,672 INFO L85 PathProgramCache]: Analyzing trace with hash -1303465807, now seen corresponding path program 1 times [2022-11-19 06:37:53,673 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:37:53,673 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1682848971] [2022-11-19 06:37:53,673 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:53,673 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:37:53,702 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:53,972 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 1 proven. 21 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-19 06:37:53,973 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:37:53,973 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1682848971] [2022-11-19 06:37:53,973 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1682848971] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:37:53,973 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [614581496] [2022-11-19 06:37:53,973 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:37:53,974 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:37:53,974 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:37:53,975 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:37:53,999 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-19 06:37:54,076 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:37:54,078 INFO L263 TraceCheckSpWp]: Trace formula consists of 324 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-19 06:37:54,080 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:37:54,130 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 14 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-19 06:37:54,130 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:37:54,212 INFO L134 CoverageAnalysis]: Checked inductivity of 26 backedges. 7 proven. 1 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2022-11-19 06:37:54,213 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [614581496] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:37:54,213 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1450166374] [2022-11-19 06:37:54,219 INFO L159 IcfgInterpreter]: Started Sifa with 42 locations of interest [2022-11-19 06:37:54,219 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:37:54,220 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:37:54,220 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:37:54,220 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:37:56,214 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 43 for LOIs [2022-11-19 06:37:56,224 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 29 for LOIs [2022-11-19 06:37:56,563 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 39 for LOIs [2022-11-19 06:37:56,569 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 73 for LOIs [2022-11-19 06:37:56,918 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 50 for LOIs [2022-11-19 06:37:56,922 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:38:01,551 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '9880#(and (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (= ~methaneLevelCritical~0 0) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483647) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |old(~pumpRunning~0)| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 2147483648)) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 06:38:01,552 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:38:01,554 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:38:01,555 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 6, 6] total 13 [2022-11-19 06:38:01,555 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2056113541] [2022-11-19 06:38:01,555 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:38:01,556 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 13 states [2022-11-19 06:38:01,556 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:38:01,556 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 13 interpolants. [2022-11-19 06:38:01,557 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=253, Invalid=1817, Unknown=0, NotChecked=0, Total=2070 [2022-11-19 06:38:01,557 INFO L87 Difference]: Start difference. First operand 1003 states and 1309 transitions. Second operand has 13 states, 11 states have (on average 6.181818181818182) internal successors, (68), 11 states have internal predecessors, (68), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) [2022-11-19 06:38:02,594 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:38:02,594 INFO L93 Difference]: Finished difference Result 1962 states and 2636 transitions. [2022-11-19 06:38:02,595 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 29 states. [2022-11-19 06:38:02,595 INFO L78 Accepts]: Start accepts. Automaton has has 13 states, 11 states have (on average 6.181818181818182) internal successors, (68), 11 states have internal predecessors, (68), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) Word has length 65 [2022-11-19 06:38:02,597 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:38:02,604 INFO L225 Difference]: With dead ends: 1962 [2022-11-19 06:38:02,604 INFO L226 Difference]: Without dead ends: 1294 [2022-11-19 06:38:02,608 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 239 GetRequests, 172 SyntacticMatches, 0 SemanticMatches, 67 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1535 ImplicationChecksByTransitivity, 5.0s TimeCoverageRelationStatistics Valid=528, Invalid=4164, Unknown=0, NotChecked=0, Total=4692 [2022-11-19 06:38:02,610 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 508 mSDsluCounter, 375 mSDsCounter, 0 mSdLazyCounter, 668 mSolverCounterSat, 326 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 512 SdHoareTripleChecker+Valid, 476 SdHoareTripleChecker+Invalid, 994 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 326 IncrementalHoareTripleChecker+Valid, 668 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-19 06:38:02,611 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [512 Valid, 476 Invalid, 994 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [326 Valid, 668 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-19 06:38:02,613 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1294 states. [2022-11-19 06:38:02,761 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1294 to 1044. [2022-11-19 06:38:02,763 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1044 states, 725 states have (on average 1.2510344827586206) internal successors, (907), 781 states have internal predecessors, (907), 168 states have call successors, (168), 146 states have call predecessors, (168), 150 states have return successors, (255), 154 states have call predecessors, (255), 168 states have call successors, (255) [2022-11-19 06:38:02,768 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1044 states to 1044 states and 1330 transitions. [2022-11-19 06:38:02,769 INFO L78 Accepts]: Start accepts. Automaton has 1044 states and 1330 transitions. Word has length 65 [2022-11-19 06:38:02,769 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:38:02,770 INFO L495 AbstractCegarLoop]: Abstraction has 1044 states and 1330 transitions. [2022-11-19 06:38:02,770 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 13 states, 11 states have (on average 6.181818181818182) internal successors, (68), 11 states have internal predecessors, (68), 4 states have call successors, (14), 3 states have call predecessors, (14), 5 states have return successors, (17), 7 states have call predecessors, (17), 4 states have call successors, (17) [2022-11-19 06:38:02,770 INFO L276 IsEmpty]: Start isEmpty. Operand 1044 states and 1330 transitions. [2022-11-19 06:38:02,773 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 95 [2022-11-19 06:38:02,774 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:38:02,774 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:38:02,791 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-19 06:38:02,983 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:38:02,983 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:38:02,983 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:38:02,984 INFO L85 PathProgramCache]: Analyzing trace with hash 1123651971, now seen corresponding path program 1 times [2022-11-19 06:38:02,984 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:38:02,984 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1375424630] [2022-11-19 06:38:02,984 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:38:02,984 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:38:03,014 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:38:03,650 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 20 proven. 33 refuted. 0 times theorem prover too weak. 26 trivial. 0 not checked. [2022-11-19 06:38:03,650 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:38:03,650 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1375424630] [2022-11-19 06:38:03,650 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1375424630] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:38:03,651 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1958975661] [2022-11-19 06:38:03,651 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:38:03,651 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:38:03,651 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:38:03,652 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:38:03,671 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-19 06:38:03,771 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:38:03,773 INFO L263 TraceCheckSpWp]: Trace formula consists of 442 conjuncts, 29 conjunts are in the unsatisfiable core [2022-11-19 06:38:03,777 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:38:04,000 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 0 proven. 60 refuted. 0 times theorem prover too weak. 19 trivial. 0 not checked. [2022-11-19 06:38:04,000 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:38:04,343 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 27 proven. 16 refuted. 0 times theorem prover too weak. 36 trivial. 0 not checked. [2022-11-19 06:38:04,343 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1958975661] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:38:04,343 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1544492792] [2022-11-19 06:38:04,346 INFO L159 IcfgInterpreter]: Started Sifa with 44 locations of interest [2022-11-19 06:38:04,346 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:38:04,346 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:38:04,347 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:38:04,347 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:38:08,790 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 144 for LOIs [2022-11-19 06:38:08,816 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 37 for LOIs [2022-11-19 06:38:09,293 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 30 for LOIs [2022-11-19 06:38:09,295 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 27 for LOIs [2022-11-19 06:38:09,320 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 50 for LOIs [2022-11-19 06:38:09,328 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 36 for LOIs [2022-11-19 06:38:09,332 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:38:17,862 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '15177#(and (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= ~methaneLevelCritical~0 1) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (<= |old(~switchedOnBeforeTS~0)| 2147483647) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= |old(~pumpRunning~0)| 0) (<= 0 ~head~0.base) (<= 0 (+ |old(~switchedOnBeforeTS~0)| 2147483648)) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= 0 ~methaneLevelCritical~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 06:38:17,867 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:38:17,867 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:38:17,867 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [16, 10, 11] total 25 [2022-11-19 06:38:17,867 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1060070590] [2022-11-19 06:38:17,868 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:38:17,868 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 25 states [2022-11-19 06:38:17,869 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:38:17,869 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 25 interpolants. [2022-11-19 06:38:17,870 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=292, Invalid=3248, Unknown=0, NotChecked=0, Total=3540 [2022-11-19 06:38:17,871 INFO L87 Difference]: Start difference. First operand 1044 states and 1330 transitions. Second operand has 25 states, 19 states have (on average 7.631578947368421) internal successors, (145), 22 states have internal predecessors, (145), 11 states have call successors, (34), 9 states have call predecessors, (34), 14 states have return successors, (33), 12 states have call predecessors, (33), 11 states have call successors, (33) [2022-11-19 06:38:20,231 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:38:20,232 INFO L93 Difference]: Finished difference Result 3150 states and 4100 transitions. [2022-11-19 06:38:20,232 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 43 states. [2022-11-19 06:38:20,233 INFO L78 Accepts]: Start accepts. Automaton has has 25 states, 19 states have (on average 7.631578947368421) internal successors, (145), 22 states have internal predecessors, (145), 11 states have call successors, (34), 9 states have call predecessors, (34), 14 states have return successors, (33), 12 states have call predecessors, (33), 11 states have call successors, (33) Word has length 94 [2022-11-19 06:38:20,233 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:38:20,244 INFO L225 Difference]: With dead ends: 3150 [2022-11-19 06:38:20,244 INFO L226 Difference]: Without dead ends: 2228 [2022-11-19 06:38:20,252 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 349 GetRequests, 250 SyntacticMatches, 3 SemanticMatches, 96 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3248 ImplicationChecksByTransitivity, 9.5s TimeCoverageRelationStatistics Valid=830, Invalid=8676, Unknown=0, NotChecked=0, Total=9506 [2022-11-19 06:38:20,253 INFO L413 NwaCegarLoop]: 56 mSDtfsCounter, 834 mSDsluCounter, 521 mSDsCounter, 0 mSdLazyCounter, 2124 mSolverCounterSat, 492 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 835 SdHoareTripleChecker+Valid, 577 SdHoareTripleChecker+Invalid, 2616 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 492 IncrementalHoareTripleChecker+Valid, 2124 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.3s IncrementalHoareTripleChecker+Time [2022-11-19 06:38:20,254 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [835 Valid, 577 Invalid, 2616 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [492 Valid, 2124 Invalid, 0 Unknown, 0 Unchecked, 1.3s Time] [2022-11-19 06:38:20,256 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 2228 states. [2022-11-19 06:38:20,455 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 2228 to 1733. [2022-11-19 06:38:20,459 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1733 states, 1196 states have (on average 1.229933110367893) internal successors, (1471), 1293 states have internal predecessors, (1471), 276 states have call successors, (276), 246 states have call predecessors, (276), 260 states have return successors, (389), 263 states have call predecessors, (389), 276 states have call successors, (389) [2022-11-19 06:38:20,466 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1733 states to 1733 states and 2136 transitions. [2022-11-19 06:38:20,467 INFO L78 Accepts]: Start accepts. Automaton has 1733 states and 2136 transitions. Word has length 94 [2022-11-19 06:38:20,468 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:38:20,468 INFO L495 AbstractCegarLoop]: Abstraction has 1733 states and 2136 transitions. [2022-11-19 06:38:20,469 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 25 states, 19 states have (on average 7.631578947368421) internal successors, (145), 22 states have internal predecessors, (145), 11 states have call successors, (34), 9 states have call predecessors, (34), 14 states have return successors, (33), 12 states have call predecessors, (33), 11 states have call successors, (33) [2022-11-19 06:38:20,469 INFO L276 IsEmpty]: Start isEmpty. Operand 1733 states and 2136 transitions. [2022-11-19 06:38:20,473 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 92 [2022-11-19 06:38:20,474 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 06:38:20,474 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:38:20,485 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-19 06:38:20,684 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-19 06:38:20,685 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 06:38:20,685 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 06:38:20,685 INFO L85 PathProgramCache]: Analyzing trace with hash -303165454, now seen corresponding path program 1 times [2022-11-19 06:38:20,685 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 06:38:20,686 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [123772649] [2022-11-19 06:38:20,686 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:38:20,686 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 06:38:20,713 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:38:21,596 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 12 proven. 45 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-19 06:38:21,597 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 06:38:21,597 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [123772649] [2022-11-19 06:38:21,597 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [123772649] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 06:38:21,597 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1084983413] [2022-11-19 06:38:21,597 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 06:38:21,597 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:38:21,597 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 06:38:21,599 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 06:38:21,630 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-19 06:38:21,716 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 06:38:21,721 INFO L263 TraceCheckSpWp]: Trace formula consists of 436 conjuncts, 34 conjunts are in the unsatisfiable core [2022-11-19 06:38:21,725 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 06:38:22,181 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 37 proven. 40 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 06:38:22,182 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 06:38:22,838 INFO L134 CoverageAnalysis]: Checked inductivity of 79 backedges. 52 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-19 06:38:22,838 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1084983413] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 06:38:22,838 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1371125630] [2022-11-19 06:38:22,840 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-19 06:38:22,841 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 06:38:22,841 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 06:38:22,841 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 06:38:22,841 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 06:38:24,668 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 25 for LOIs [2022-11-19 06:38:24,671 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-19 06:38:25,127 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 22 for LOIs [2022-11-19 06:38:25,128 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 06:38:25,160 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 35 for LOIs [2022-11-19 06:38:25,163 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 06:38:29,962 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '23339#(and (= |timeShift_getWaterLevel_~retValue_acc~11#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~head~0.offset 0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 1) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (<= |old(~pumpRunning~0)| 2147483647) (<= |#NULL.offset| 0) (= |timeShift_getWaterLevel_~retValue_acc~11#1| |timeShift_getWaterLevel_#res#1|) (= 1 ~systemActive~0) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= 0 (+ 2147483648 |timeShift_getWaterLevel_#res#1|)) (<= 0 ~methaneLevelCritical~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 06:38:29,963 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 06:38:29,963 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 06:38:29,963 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [19, 13, 11] total 33 [2022-11-19 06:38:29,963 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [136654555] [2022-11-19 06:38:29,963 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 06:38:29,964 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 33 states [2022-11-19 06:38:29,964 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 06:38:29,964 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 33 interpolants. [2022-11-19 06:38:29,966 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=462, Invalid=3698, Unknown=0, NotChecked=0, Total=4160 [2022-11-19 06:38:29,966 INFO L87 Difference]: Start difference. First operand 1733 states and 2136 transitions. Second operand has 33 states, 31 states have (on average 4.870967741935484) internal successors, (151), 32 states have internal predecessors, (151), 18 states have call successors, (31), 9 states have call predecessors, (31), 13 states have return successors, (29), 16 states have call predecessors, (29), 17 states have call successors, (29) [2022-11-19 06:38:37,093 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 06:38:37,093 INFO L93 Difference]: Finished difference Result 5185 states and 6878 transitions. [2022-11-19 06:38:37,095 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 101 states. [2022-11-19 06:38:37,095 INFO L78 Accepts]: Start accepts. Automaton has has 33 states, 31 states have (on average 4.870967741935484) internal successors, (151), 32 states have internal predecessors, (151), 18 states have call successors, (31), 9 states have call predecessors, (31), 13 states have return successors, (29), 16 states have call predecessors, (29), 17 states have call successors, (29) Word has length 91 [2022-11-19 06:38:37,096 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 06:38:37,097 INFO L225 Difference]: With dead ends: 5185 [2022-11-19 06:38:37,097 INFO L226 Difference]: Without dead ends: 0 [2022-11-19 06:38:37,114 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 444 GetRequests, 280 SyntacticMatches, 7 SemanticMatches, 157 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10208 ImplicationChecksByTransitivity, 8.8s TimeCoverageRelationStatistics Valid=3008, Invalid=22114, Unknown=0, NotChecked=0, Total=25122 [2022-11-19 06:38:37,115 INFO L413 NwaCegarLoop]: 171 mSDtfsCounter, 2537 mSDsluCounter, 1324 mSDsCounter, 0 mSdLazyCounter, 3459 mSolverCounterSat, 1925 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 2.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 2542 SdHoareTripleChecker+Valid, 1495 SdHoareTripleChecker+Invalid, 5384 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1925 IncrementalHoareTripleChecker+Valid, 3459 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.8s IncrementalHoareTripleChecker+Time [2022-11-19 06:38:37,115 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [2542 Valid, 1495 Invalid, 5384 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1925 Valid, 3459 Invalid, 0 Unknown, 0 Unchecked, 2.8s Time] [2022-11-19 06:38:37,116 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-19 06:38:37,116 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-19 06:38:37,116 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-19 06:38:37,116 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-19 06:38:37,117 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 91 [2022-11-19 06:38:37,117 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 06:38:37,118 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-19 06:38:37,118 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 33 states, 31 states have (on average 4.870967741935484) internal successors, (151), 32 states have internal predecessors, (151), 18 states have call successors, (31), 9 states have call predecessors, (31), 13 states have return successors, (29), 16 states have call predecessors, (29), 17 states have call successors, (29) [2022-11-19 06:38:37,118 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-19 06:38:37,118 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-19 06:38:37,121 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-19 06:38:37,131 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-11-19 06:38:37,327 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 06:38:37,328 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-19 06:39:35,635 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 179 186) the Hoare annotation is: (let ((.cse3 (not (= ~methaneLevelCritical~0 0)))) (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (let ((.cse5 (not (= ~pumpRunning~0 0)))) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (or .cse5 .cse3) (or .cse5 (= 2 ~waterLevel~0)) (not (= 0 ~systemActive~0))))) (.cse2 (= |old(~pumpRunning~0)| 0)) (.cse4 (not (<= ~waterLevel~0 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 .cse1 .cse2 .cse4 (not (= ~methaneLevelCritical~0 1)))))) [2022-11-19 06:39:35,635 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 179 186) no Hoare annotation was computed. [2022-11-19 06:39:35,635 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 94 100) no Hoare annotation was computed. [2022-11-19 06:39:35,636 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 94 100) the Hoare annotation is: true [2022-11-19 06:39:35,636 INFO L895 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 964 975) the Hoare annotation is: (let ((.cse10 (= 0 ~systemActive~0))) (let ((.cse11 (not (= 2 ~waterLevel~0))) (.cse7 (= ~methaneLevelCritical~0 1)) (.cse8 (not (<= ~waterLevel~0 2))) (.cse9 (not (= |old(~methaneLevelCritical~0)| 1))) (.cse3 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse5 (not .cse10)) (.cse0 (not (= |old(~methaneLevelCritical~0)| 0))) (.cse1 (not (= ~pumpRunning~0 0))) (.cse6 (not (= 1 ~systemActive~0))) (.cse2 (= |old(~methaneLevelCritical~0)| ~methaneLevelCritical~0)) (.cse4 (not (<= ~waterLevel~0 1)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse1 .cse6 .cse7 .cse8 .cse9 .cse10) (or .cse0 .cse6 .cse11 .cse2) (or .cse0 .cse1 .cse11 .cse2 .cse3 .cse5) (or .cse0 .cse6 .cse2 .cse8 .cse3) (or .cse6 .cse7 .cse8 .cse9 .cse3) (or .cse1 .cse7 .cse8 .cse9 .cse3 .cse5) (or .cse0 .cse1 .cse6 .cse2 .cse4 .cse10)))) [2022-11-19 06:39:35,636 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 964 975) no Hoare annotation was computed. [2022-11-19 06:39:35,636 INFO L902 garLoopResultBuilder]: At program point L801(line 801) the Hoare annotation is: true [2022-11-19 06:39:35,636 INFO L899 garLoopResultBuilder]: For program point L801-1(line 801) no Hoare annotation was computed. [2022-11-19 06:39:35,636 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 795 824) no Hoare annotation was computed. [2022-11-19 06:39:35,637 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 795 824) the Hoare annotation is: true [2022-11-19 06:39:35,637 INFO L902 garLoopResultBuilder]: At program point L820(lines 795 824) the Hoare annotation is: true [2022-11-19 06:39:35,637 INFO L899 garLoopResultBuilder]: For program point L816(line 816) no Hoare annotation was computed. [2022-11-19 06:39:35,637 INFO L899 garLoopResultBuilder]: For program point L809(lines 809 813) no Hoare annotation was computed. [2022-11-19 06:39:35,637 INFO L902 garLoopResultBuilder]: At program point L809-1(lines 809 813) the Hoare annotation is: true [2022-11-19 06:39:35,637 INFO L902 garLoopResultBuilder]: At program point L805-2(lines 805 819) the Hoare annotation is: true [2022-11-19 06:39:35,637 INFO L899 garLoopResultBuilder]: For program point L411(lines 411 417) no Hoare annotation was computed. [2022-11-19 06:39:35,638 INFO L895 garLoopResultBuilder]: At program point L147(line 147) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (let ((.cse7 (not (<= |old(~waterLevel~0)| 1))) (.cse13 (and .cse1 .cse2 .cse3)) (.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse9 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~methaneLevelCritical~0 1))) (.cse11 (not (<= |old(~waterLevel~0)| 2))) (.cse12 (not (= 0 ~systemActive~0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse5 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2 .cse3) .cse4 .cse5) (or .cse6 .cse7 .cse0 .cse8 .cse9) (or .cse10 .cse8 .cse11 .cse12) (or .cse10 .cse0 .cse13 .cse8 .cse11) (or .cse7 .cse10 .cse0 .cse13 .cse4) (or .cse6 .cse0 .cse8 .cse5 .cse9) (or .cse6 .cse0 .cse4 .cse11 .cse9) (or .cse10 .cse4 .cse11 .cse12) (or .cse0 .cse8 (not (= |old(~pumpRunning~0)| 1)) .cse5)))) [2022-11-19 06:39:35,638 INFO L895 garLoopResultBuilder]: At program point L147-1(lines 128 152) the Hoare annotation is: (let ((.cse24 (< 0 |old(~waterLevel~0)|)) (.cse11 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse23 (and (not .cse24) .cse11)) (.cse22 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (let ((.cse18 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse21 (or .cse23 (and .cse22 .cse24))) (.cse20 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (or .cse22 .cse23)) (.cse19 (= ~pumpRunning~0 0)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (let ((.cse4 (= ~pumpRunning~0 1)) (.cse10 (= 2 ~waterLevel~0)) (.cse12 (and .cse19 .cse11 .cse3)) (.cse0 (and .cse20 .cse19 .cse2)) (.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse16 (not (= ~methaneLevelCritical~0 1))) (.cse9 (not (= 0 ~systemActive~0))) (.cse13 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse14 (and .cse18 .cse21 .cse3)) (.cse15 (and .cse20 .cse19 .cse21)) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse17 (= |old(~switchedOnBeforeTS~0)| 0))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (not (= |old(~pumpRunning~0)| 1)) .cse6) (or .cse7 .cse5 .cse8 .cse9) (or (and .cse10 .cse11 .cse4) .cse7 .cse1 .cse12 .cse5 .cse8) (or .cse13 .cse1 .cse14 .cse15 .cse16 .cse8 .cse17) (or .cse7 (and .cse10 .cse11) .cse1 .cse12 .cse16 .cse8) (or .cse0 .cse1 (and .cse18 .cse2 .cse3) (and .cse18 .cse19) .cse16 .cse6) (or .cse7 .cse16 .cse8 .cse9) (or .cse13 .cse1 .cse5 .cse14 .cse15 .cse8 .cse17)))))) [2022-11-19 06:39:35,639 INFO L895 garLoopResultBuilder]: At program point L81-1(lines 81 87) the Hoare annotation is: (let ((.cse24 (< 0 |old(~waterLevel~0)|)) (.cse13 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse23 (and (not .cse24) .cse13)) (.cse22 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (let ((.cse18 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse21 (or .cse23 (and .cse22 .cse24))) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse20 (not (= ~switchedOnBeforeTS~0 0))) (.cse19 (= ~pumpRunning~0 0)) (.cse2 (or .cse22 .cse23))) (let ((.cse4 (= ~pumpRunning~0 1)) (.cse12 (= 2 ~waterLevel~0)) (.cse0 (and .cse20 .cse19 .cse2)) (.cse9 (not (= ~methaneLevelCritical~0 1))) (.cse6 (not (= |old(~waterLevel~0)| 2))) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (and .cse19 .cse13 .cse3)) (.cse11 (not (= 0 ~systemActive~0))) (.cse14 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse1 (not (= 1 ~systemActive~0))) (.cse5 (not (= ~methaneLevelCritical~0 0))) (.cse15 (and .cse18 .cse21 .cse3)) (.cse16 (and .cse20 .cse19 .cse21)) (.cse10 (not (<= |old(~waterLevel~0)| 2))) (.cse17 (= |old(~switchedOnBeforeTS~0)| 0))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5 (not (= |old(~pumpRunning~0)| 1)) .cse6) (or .cse7 .cse8 .cse9 .cse10 .cse11) (or (and .cse12 .cse13 .cse4) .cse7 .cse1 .cse8 .cse5 .cse10) (or .cse14 .cse1 .cse15 .cse16 .cse9 .cse10 .cse17) (or .cse7 (and .cse12 .cse13) .cse1 .cse8 .cse9 .cse10) (or .cse0 .cse1 (and .cse18 .cse2 .cse3) (and .cse18 .cse19) .cse9 .cse6) (or .cse7 .cse8 .cse5 .cse10 .cse11) (or .cse14 .cse1 .cse5 .cse15 .cse16 .cse10 .cse17)))))) [2022-11-19 06:39:35,640 INFO L895 garLoopResultBuilder]: At program point L408(line 408) the Hoare annotation is: (let ((.cse22 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse24 (< 0 |old(~waterLevel~0)|)) (.cse20 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse23 (and (not .cse24) .cse20)) (.cse19 (and .cse22 .cse24))) (let ((.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse12 (not (= ~switchedOnBeforeTS~0 0))) (.cse13 (= ~pumpRunning~0 0)) (.cse3 (or .cse23 .cse19)) (.cse4 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0))) (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse1 (and .cse12 .cse13 .cse3 .cse4)) (.cse9 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse10 (or .cse22 .cse23)) (.cse11 (not (= |old(~waterLevel~0)| 2))) (.cse17 (not (<= 2 |old(~waterLevel~0)|))) (.cse7 (not (= ~methaneLevelCritical~0 0))) (.cse8 (not (<= |old(~waterLevel~0)| 2))) (.cse16 (not (= 0 ~systemActive~0))) (.cse18 (not (<= |old(~waterLevel~0)| 1))) (.cse14 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not (= 1 ~systemActive~0))) (.cse15 (not (= ~methaneLevelCritical~0 1))) (.cse21 (and .cse13 .cse20 .cse4 .cse5))) (and (or .cse0 .cse1 (and .cse2 .cse3 .cse4 .cse5) .cse6 .cse7 .cse8 .cse9) (or .cse6 .cse7 (not (= |old(~pumpRunning~0)| 1)) (and .cse10 .cse4 .cse5 (= ~pumpRunning~0 1)) .cse11 (and .cse12 .cse13 .cse10 .cse4)) (or .cse14 .cse15 .cse8 .cse16 .cse17) (or .cse0 .cse18 .cse1 .cse6 (and .cse2 (<= ~waterLevel~0 0) (or .cse19 .cse20) .cse4 .cse5) .cse15 .cse9) (or .cse14 .cse6 (and .cse13 (<= ~waterLevel~0 1) .cse20 .cse4 .cse5) .cse7 .cse8) (or (and .cse2 (not .cse13) (= ~waterLevel~0 1) .cse4 .cse5) .cse6 (and .cse12 .cse14 .cse13 .cse10 .cse4) .cse15 .cse11) (or .cse18 .cse14 .cse15 .cse16 .cse21) (or .cse14 .cse7 .cse8 .cse16 .cse17) (or .cse14 .cse7 .cse8 .cse16 .cse21) (or .cse18 .cse14 .cse6 .cse15 .cse21)))))) [2022-11-19 06:39:35,640 INFO L899 garLoopResultBuilder]: For program point L408-1(line 408) no Hoare annotation was computed. [2022-11-19 06:39:35,640 INFO L899 garLoopResultBuilder]: For program point L74-2(lines 70 92) no Hoare annotation was computed. [2022-11-19 06:39:35,640 INFO L899 garLoopResultBuilder]: For program point L136(lines 136 144) no Hoare annotation was computed. [2022-11-19 06:39:35,640 INFO L895 garLoopResultBuilder]: At program point L933(line 933) the Hoare annotation is: (let ((.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (= 0 ~systemActive~0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse7 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3 .cse5) (or .cse0 .cse1 .cse4 .cse3) (or .cse6 .cse1 .cse2 .cse3) (or .cse6 (not (<= |old(~waterLevel~0)| 1)) .cse1 .cse4) (or .cse6 .cse1 .cse4 .cse7) (or .cse1 .cse2 .cse7) (or .cse0 .cse2 .cse3 .cse5) (or .cse1 .cse4 (not (= |old(~pumpRunning~0)| 1)) .cse7))) [2022-11-19 06:39:35,641 INFO L895 garLoopResultBuilder]: At program point L132(lines 132 149) the Hoare annotation is: (let ((.cse12 (< 0 |old(~waterLevel~0)|)) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse13 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse19 (= ~pumpRunning~0 0)) (.cse18 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse5 (or (and .cse19 .cse13) (and (not .cse19) .cse18))) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse8 (and .cse19 .cse13 .cse6)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (not (= 0 ~systemActive~0))) (.cse9 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse17 (not (<= |old(~waterLevel~0)| 1))) (.cse4 (not (= 1 ~systemActive~0))) (.cse16 (not (= ~methaneLevelCritical~0 1))) (.cse10 (not (= ~switchedOnBeforeTS~0 0))) (.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse14 (and .cse18 .cse12)) (.cse15 (= |old(~switchedOnBeforeTS~0)| 0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 (not (= |old(~pumpRunning~0)| 1)) (and .cse5 .cse6 (= ~pumpRunning~0 1)) .cse7) (or .cse0 .cse4 .cse8 .cse1 .cse2) (or .cse9 (and .cse10 .cse11 (or (and (not .cse12) .cse13) .cse14) .cse6) .cse4 .cse1 .cse2 .cse15) (or .cse4 (and .cse11 .cse5 .cse6) .cse16 .cse7) (or .cse17 .cse0 .cse4 .cse8 .cse16) (or .cse0 .cse16 .cse2 .cse3) (or .cse9 .cse17 .cse4 .cse16 (and .cse10 .cse11 (<= ~waterLevel~0 0) (or .cse14 .cse13) .cse6) .cse15)))) [2022-11-19 06:39:35,641 INFO L895 garLoopResultBuilder]: At program point L393(line 393) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse17 (= 0 ~systemActive~0)) (.cse16 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse11 (not (= ~switchedOnBeforeTS~0 0))) (.cse12 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse8 (not (<= |old(~waterLevel~0)| 1))) (.cse15 (and .cse16 .cse3)) (.cse5 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse0 (not (= 1 ~systemActive~0))) (.cse7 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse9 (not (= |old(~pumpRunning~0)| 0))) (.cse14 (and .cse16 .cse10 .cse3 .cse17)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse13 (not .cse17))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1)) .cse2 (and .cse3 (= ~pumpRunning~0 1))) (or .cse4 .cse0 .cse5 .cse6 .cse7) (or .cse8 .cse9 (and .cse10 .cse3) .cse0 .cse5) (or .cse11 .cse9 .cse0 .cse5 .cse6 .cse12) (or .cse4 .cse9 .cse5 .cse6 .cse7 .cse13) (or .cse9 .cse14 .cse5 .cse6 .cse13) (or .cse9 .cse0 .cse1 .cse6 (and .cse11 .cse10 .cse3) .cse12) (or .cse4 .cse9 .cse1 .cse6 .cse7 .cse13) (or .cse0 .cse15 .cse5 .cse2) (or .cse4 .cse8 .cse0 .cse15 .cse5) (or .cse4 .cse0 .cse1 (and .cse16 .cse3 .cse7) .cse6) (or .cse9 .cse14 .cse1 .cse6 .cse13)))) [2022-11-19 06:39:35,642 INFO L895 garLoopResultBuilder]: At program point L393-1(line 393) the Hoare annotation is: (let ((.cse20 (= 0 ~systemActive~0))) (let ((.cse10 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (not .cse20)) (.cse19 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse15 (= ~pumpRunning~0 0)) (.cse16 (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__2_#t~ret22#1|)) (.cse17 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse1 (and .cse19 .cse15 .cse16 .cse17 .cse20)) (.cse12 (not (<= 2 |old(~waterLevel~0)|))) (.cse9 (not (= |old(~waterLevel~0)| 1))) (.cse5 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (and (not (= ~switchedOnBeforeTS~0 0)) .cse19 .cse16 .cse17 .cse10 .cse4)) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse8 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse18 (not (= |old(~waterLevel~0)| 2))) (.cse13 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not (= 1 ~systemActive~0))) (.cse11 (not (= ~methaneLevelCritical~0 0))) (.cse14 (and .cse19 .cse15 .cse16 .cse17 (or .cse17 (= ~waterLevel~0 1)) .cse4))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse6 .cse7 .cse2 .cse3 .cse8) (or .cse5 .cse0 .cse9 .cse2 .cse10 .cse4) (or .cse5 .cse0 .cse9 .cse11 .cse10 .cse4) (or .cse0 .cse1 .cse11 .cse3 .cse4) (or .cse5 .cse7 .cse2 .cse3 .cse10 .cse12) (or .cse5 .cse7 .cse11 .cse3 .cse10 .cse12) (or .cse5 .cse9 .cse7 .cse11 .cse10) (or .cse13 .cse0 .cse7 .cse14 .cse2) (or .cse5 .cse9 .cse7 .cse2 .cse10) (or .cse5 .cse6 .cse7 .cse11 .cse3 .cse8) (or .cse0 .cse7 .cse11 (and .cse15 .cse16 .cse17) .cse18) (or .cse7 (and .cse19 .cse16 .cse17) .cse2 .cse18) (or .cse7 .cse11 (not (= |old(~pumpRunning~0)| 1)) .cse18 (and .cse16 .cse17 (= ~pumpRunning~0 1))) (or .cse13 .cse0 .cse7 .cse11 .cse14))))) [2022-11-19 06:39:35,642 INFO L899 garLoopResultBuilder]: For program point L410(lines 410 420) no Hoare annotation was computed. [2022-11-19 06:39:35,642 INFO L899 garLoopResultBuilder]: For program point L406(lines 406 423) no Hoare annotation was computed. [2022-11-19 06:39:35,643 INFO L895 garLoopResultBuilder]: At program point L406-1(lines 398 426) the Hoare annotation is: (let ((.cse28 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse33 (< 0 |old(~waterLevel~0)|))) (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (and .cse28 .cse33)) (.cse24 (= ~pumpRunning~0 0))) (let ((.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse31 (= 1 ~systemActive~0)) (.cse29 (= ~methaneLevelCritical~0 1)) (.cse25 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (.cse27 (= 0 ~systemActive~0)) (.cse11 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse32 (not .cse24)) (.cse15 (not (= ~methaneLevelCritical~0 0))) (.cse30 (not (= ~switchedOnBeforeTS~0 0))) (.cse26 (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~3#1| 0)) (.cse23 (or (and (not .cse33) .cse9) .cse8)) (.cse10 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0))) (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse3 (and .cse30 .cse24 .cse26 .cse23 .cse10)) (.cse6 (or .cse32 .cse15)) (.cse7 (or .cse32 (= 2 ~waterLevel~0))) (.cse13 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse18 (and .cse24 .cse26 .cse9 .cse10 .cse11)) (.cse16 (not (<= |old(~waterLevel~0)| 2))) (.cse21 (= ~pumpRunning~0 1)) (.cse17 (and .cse24 .cse9 .cse27 .cse10 .cse11)) (.cse1 (not (<= |old(~waterLevel~0)| 1))) (.cse14 (not (= |old(~pumpRunning~0)| 0))) (.cse12 (not .cse27)) (.cse19 (and .cse5 .cse24 .cse31 .cse29 .cse25 .cse9 .cse10)) (.cse2 (not .cse31)) (.cse22 (and .cse30 .cse24 .cse28 .cse26 .cse10)) (.cse4 (not .cse29)) (.cse20 (not (= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 (and .cse5 .cse6 .cse7 (<= ~waterLevel~0 0) (or .cse8 .cse9) .cse10 .cse11 .cse12) .cse13) (or .cse14 .cse15 .cse16 .cse12 .cse17) (or .cse1 .cse14 .cse2 .cse18 .cse4) (or .cse19 .cse14 .cse2 .cse4 .cse20) (or .cse2 .cse15 (not (= |old(~pumpRunning~0)| 1)) (and (= ~waterLevel~0 1) .cse10 .cse11 .cse21) .cse22 .cse20) (or .cse0 .cse2 .cse15 .cse3 .cse16 (and .cse5 .cse6 .cse7 .cse23 .cse10 .cse11 .cse12) .cse13) (or .cse14 .cse2 .cse18 .cse15 (and .cse24 .cse25 .cse9 .cse10 .cse11) .cse16 (and .cse25 .cse9 .cse10 .cse21)) (or .cse14 .cse4 .cse20 .cse12 .cse17) (or .cse1 .cse14 .cse4 (and .cse24 .cse26 .cse9 .cse27 .cse10 .cse11) .cse12) (or .cse1 .cse14 .cse15 .cse26 .cse12) (or .cse19 .cse2 (and .cse5 .cse28 .cse10 .cse11) .cse22 .cse4 .cse20)))))) [2022-11-19 06:39:35,644 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 67 93) the Hoare annotation is: (let ((.cse10 (= ~pumpRunning~0 0)) (.cse17 (= 0 ~systemActive~0)) (.cse16 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse11 (not (= ~switchedOnBeforeTS~0 0))) (.cse12 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse8 (not (<= |old(~waterLevel~0)| 1))) (.cse15 (and .cse16 .cse3)) (.cse5 (not (= ~methaneLevelCritical~0 1))) (.cse4 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse0 (not (= 1 ~systemActive~0))) (.cse7 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse9 (not (= |old(~pumpRunning~0)| 0))) (.cse14 (and .cse16 .cse10 .cse3 .cse17)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse13 (not .cse17))) (and (or .cse0 .cse1 (not (= |old(~pumpRunning~0)| 1)) .cse2 (and .cse3 (= ~pumpRunning~0 1))) (or .cse4 .cse0 .cse5 .cse6 .cse7) (or .cse8 .cse9 (and .cse10 .cse3) .cse0 .cse5) (or .cse11 .cse9 .cse0 .cse5 .cse6 .cse12) (or .cse4 .cse9 .cse5 .cse6 .cse7 .cse13) (or .cse9 .cse14 .cse5 .cse6 .cse13) (or .cse9 .cse0 .cse1 .cse6 (and .cse11 .cse10 .cse3) .cse12) (or .cse4 .cse9 .cse1 .cse6 .cse7 .cse13) (or .cse0 .cse15 .cse5 .cse2) (or .cse4 .cse8 .cse0 .cse15 .cse5) (or .cse4 .cse0 .cse1 (and .cse16 .cse3 .cse7) .cse6) (or .cse9 .cse14 .cse1 .cse6 .cse13)))) [2022-11-19 06:39:35,644 INFO L895 garLoopResultBuilder]: At program point L142(line 142) the Hoare annotation is: (let ((.cse14 (< 0 |old(~waterLevel~0)|))) (let ((.cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse13 (and (not .cse14) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse12 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse10 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (let ((.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse7 (and .cse8 (or .cse13 (and .cse12 .cse14)) .cse10)) (.cse1 (not (= 1 ~systemActive~0))) (.cse9 (or .cse12 .cse13)) (.cse4 (not (= ~methaneLevelCritical~0 0))) (.cse11 (not (= |old(~waterLevel~0)| 2))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (not (= 0 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3 .cse5) (or .cse0 .cse1 .cse4 .cse3) (or .cse6 .cse1 .cse4 .cse7 .cse3) (or .cse6 .cse1 .cse7 .cse2 .cse3) (or .cse1 (and .cse8 .cse9 .cse10) .cse2 .cse11) (or .cse1 (and .cse9 .cse10 (= ~pumpRunning~0 1)) .cse4 (not (= |old(~pumpRunning~0)| 1)) .cse11) (or .cse0 .cse2 .cse3 .cse5))))) [2022-11-19 06:39:35,644 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 67 93) no Hoare annotation was computed. [2022-11-19 06:39:35,645 INFO L895 garLoopResultBuilder]: At program point L138(line 138) the Hoare annotation is: (let ((.cse14 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse15 (< 0 |old(~waterLevel~0)|)) (.cse16 (not (= ~pumpRunning~0 0))) (.cse4 (not (= ~methaneLevelCritical~0 0)))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse6 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse8 (or .cse16 .cse4)) (.cse9 (or .cse16 (= 2 ~waterLevel~0))) (.cse11 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse10 (and .cse14 .cse15)) (.cse5 (not (= 0 ~systemActive~0))) (.cse3 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= 1 ~systemActive~0))) (.cse13 (not (= |old(~waterLevel~0)| 2))) (.cse7 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse12 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 .cse3 .cse5) (or .cse6 (not (<= |old(~waterLevel~0)| 1)) .cse1 (and .cse7 .cse8 .cse9 (<= ~waterLevel~0 0) (or .cse10 .cse11) .cse12 .cse5) .cse2) (or .cse0 .cse1 .cse4 .cse3) (or .cse1 .cse2 .cse13 (and .cse7 .cse14 .cse8 .cse9 .cse12 .cse5)) (or .cse0 .cse2 .cse3 .cse5) (or .cse6 .cse1 .cse4 (and .cse7 .cse8 .cse9 (or (and (not .cse15) .cse11) .cse10) .cse12 .cse5) .cse3) (or .cse1 .cse4 (not (= |old(~pumpRunning~0)| 1)) .cse13 (and .cse7 (= ~waterLevel~0 1) .cse12))))) [2022-11-19 06:39:35,645 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 933) no Hoare annotation was computed. [2022-11-19 06:39:35,645 INFO L895 garLoopResultBuilder]: At program point L287(line 287) the Hoare annotation is: (let ((.cse4 (= ~methaneLevelCritical~0 0)) (.cse0 (not (= ~pumpRunning~0 0)))) (let ((.cse1 (= 1 ~systemActive~0)) (.cse2 (<= ~waterLevel~0 2)) (.cse3 (let ((.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and (= 2 ~waterLevel~0) (not .cse4) .cse5 .cse6 .cse7) (and .cse0 .cse5 .cse6 .cse7))))) (or (and .cse0 .cse1 (= ~methaneLevelCritical~0 1) .cse2 .cse3) (and .cse4 .cse1 .cse2 .cse3)))) [2022-11-19 06:39:35,645 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-19 06:39:35,646 INFO L902 garLoopResultBuilder]: At program point L371(lines 308 375) the Hoare annotation is: true [2022-11-19 06:39:35,646 INFO L899 garLoopResultBuilder]: For program point L338(lines 338 344) no Hoare annotation was computed. [2022-11-19 06:39:35,646 INFO L899 garLoopResultBuilder]: For program point L338-1(lines 338 344) no Hoare annotation was computed. [2022-11-19 06:39:35,646 INFO L895 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (let ((.cse9 (= 0 ~systemActive~0))) (let ((.cse7 (= ~pumpRunning~0 0)) (.cse10 (= 2 ~waterLevel~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse6 (not .cse9)) (.cse0 (= ~methaneLevelCritical~0 0))) (let ((.cse11 (let ((.cse13 (or (not .cse0) (= ~pumpRunning~0 1)))) (or (and (not .cse7) .cse13 .cse3 (= ~waterLevel~0 1) .cse4 .cse6) (and .cse10 .cse13 .cse3 .cse4 .cse6)))) (.cse8 (<= ~waterLevel~0 2)) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (<= ~waterLevel~0 1)) (.cse2 (= 1 ~systemActive~0)) (.cse12 (= ~methaneLevelCritical~0 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse0 .cse3 .cse8 .cse9 .cse4 .cse5) (and .cse10 .cse0 .cse2 .cse11) (and .cse1 .cse2 .cse12 .cse3 .cse4 .cse5) (and .cse7 .cse2 .cse12 .cse11) (and .cse7 .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse7 .cse10 .cse0 .cse2 .cse3 .cse4) (and .cse7 .cse12 .cse3 .cse8 .cse9 .cse4 .cse5) (and .cse7 .cse1 .cse2 .cse12 .cse3 .cse4))))) [2022-11-19 06:39:35,646 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-19 06:39:35,647 INFO L899 garLoopResultBuilder]: For program point L285(lines 285 291) no Hoare annotation was computed. [2022-11-19 06:39:35,647 INFO L895 garLoopResultBuilder]: At program point L285-1(lines 285 291) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse8 (<= ~waterLevel~0 2)) (.cse2 (= ~methaneLevelCritical~0 1)) (.cse0 (= ~pumpRunning~0 0)) (.cse6 (= ~methaneLevelCritical~0 0)) (.cse1 (<= ~waterLevel~0 1)) (.cse7 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse0 .cse6 .cse1 .cse3 .cse4 .cse5) (and .cse0 .cse7 .cse2 .cse3 .cse8 .cse4) (and .cse0 .cse6 (<= 2 ~waterLevel~0) .cse3 .cse8 .cse4) (and .cse0 (= 2 ~waterLevel~0) .cse2 .cse3 .cse4) (and .cse0 .cse6 .cse1 .cse7 .cse3 .cse4))) [2022-11-19 06:39:35,647 INFO L895 garLoopResultBuilder]: At program point L880(lines 880 887) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~10#1| 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2022-11-19 06:39:35,647 INFO L895 garLoopResultBuilder]: At program point L368(lines 317 369) the Hoare annotation is: false [2022-11-19 06:39:35,647 INFO L902 garLoopResultBuilder]: At program point L880-2(lines 880 887) the Hoare annotation is: true [2022-11-19 06:39:35,648 INFO L899 garLoopResultBuilder]: For program point L356(lines 356 362) no Hoare annotation was computed. [2022-11-19 06:39:35,653 INFO L895 garLoopResultBuilder]: At program point L356-2(lines 348 363) the Hoare annotation is: (let ((.cse8 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse6 (= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse10 (<= ~waterLevel~0 2)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= ~waterLevel~0 1)) (.cse7 (= 1 ~systemActive~0)) (.cse9 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse6 .cse1 .cse7 .cse3 .cse5 .cse8) (and .cse6 .cse1 .cse7 .cse3 .cse5 (= ~pumpRunning~0 1)) (and .cse0 .cse6 .cse1 .cse3 .cse4 .cse5) (and .cse2 .cse7 .cse9 .cse3 .cse5 .cse8) (and .cse1 .cse2 .cse7 .cse3 .cse5 .cse8) (and .cse6 .cse7 .cse9 .cse3 .cse5) (and .cse0 .cse9 .cse3 .cse10 .cse4 .cse5) (and .cse0 .cse1 .cse7 .cse3 .cse10 .cse5) (and .cse0 .cse2 .cse7 .cse9 .cse3 .cse5))) [2022-11-19 06:39:35,654 INFO L899 garLoopResultBuilder]: For program point L319(lines 318 367) no Hoare annotation was computed. [2022-11-19 06:39:35,654 INFO L895 garLoopResultBuilder]: At program point L348(lines 348 363) the Hoare annotation is: (let ((.cse0 (= 2 ~waterLevel~0)) (.cse8 (= 0 ~systemActive~0)) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (= ~methaneLevelCritical~0 0)) (.cse7 (<= ~waterLevel~0 2)) (.cse6 (= ~pumpRunning~0 0)) (.cse9 (<= ~waterLevel~0 1)) (.cse2 (= 1 ~systemActive~0)) (.cse10 (= ~methaneLevelCritical~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (and .cse6 .cse1 .cse3 .cse7 .cse8 .cse4 .cse5) (and .cse0 .cse1 .cse2 .cse3 .cse4 (= ~pumpRunning~0 1)) (and .cse9 .cse2 .cse10 .cse3 .cse4 .cse5) (and .cse1 .cse9 .cse2 .cse3 .cse4 .cse5) (and .cse0 .cse2 .cse10 .cse3 .cse4) (and .cse6 .cse10 .cse3 .cse7 .cse8 .cse4 .cse5) (and .cse6 .cse1 .cse2 .cse3 .cse7 .cse4) (and .cse6 .cse9 .cse2 .cse10 .cse3 .cse4))) [2022-11-19 06:39:35,654 INFO L895 garLoopResultBuilder]: At program point L340(line 340) the Hoare annotation is: (let ((.cse7 (= ~pumpRunning~0 0)) (.cse10 (= 2 ~waterLevel~0))) (let ((.cse4 (or (not .cse7) .cse10)) (.cse8 (= ~methaneLevelCritical~0 0)) (.cse11 (<= ~waterLevel~0 1)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= ~methaneLevelCritical~0 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (<= ~waterLevel~0 2)) (.cse9 (= 0 ~systemActive~0)) (.cse5 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse2 .cse3 .cse9 .cse5 .cse6) (and .cse7 .cse0 .cse1 .cse2 .cse3 .cse5) (and .cse10 .cse8 .cse0 .cse2 .cse5) (and .cse8 .cse11 .cse0 .cse2 .cse4 .cse5 .cse6) (and .cse7 .cse8 .cse11 .cse0 .cse2 .cse5) (and .cse7 .cse1 .cse2 .cse3 .cse9 .cse5 .cse6)))) [2022-11-19 06:39:35,655 INFO L895 garLoopResultBuilder]: At program point L365(lines 318 367) the Hoare annotation is: (let ((.cse11 (= 0 ~systemActive~0)) (.cse8 (= ~methaneLevelCritical~0 0))) (let ((.cse2 (or (not .cse8) (= ~pumpRunning~0 1))) (.cse7 (not .cse11)) (.cse1 (= 2 ~waterLevel~0)) (.cse9 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse10 (<= ~waterLevel~0 1)) (.cse3 (= 1 ~systemActive~0)) (.cse4 (= ~methaneLevelCritical~0 1)) (.cse5 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse6 (= |ULTIMATE.start_main_~tmp~10#1| 1))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4 .cse5 .cse6 .cse7) (and .cse8 .cse3 .cse5 (= ~waterLevel~0 1) .cse6 .cse9) (and .cse8 .cse3 .cse5 (<= ~waterLevel~0 0) .cse6 .cse9) (and .cse1 .cse8 .cse2 .cse3 .cse5 .cse6 .cse7) (and .cse0 .cse8 .cse10 .cse5 .cse11 .cse6 .cse9) (and .cse0 .cse1 .cse8 .cse5 .cse11 .cse6 .cse9) (and .cse10 .cse3 .cse4 .cse5 .cse6 .cse9) (and .cse0 .cse8 .cse10 .cse3 .cse5 .cse6) (and .cse0 .cse1 .cse8 .cse3 .cse5 .cse6) (and .cse0 .cse4 .cse5 (<= ~waterLevel~0 2) .cse11 .cse6 .cse9) (and .cse0 .cse10 .cse3 .cse4 .cse5 .cse6)))) [2022-11-19 06:39:35,655 INFO L899 garLoopResultBuilder]: For program point L328(lines 328 334) no Hoare annotation was computed. [2022-11-19 06:39:35,655 INFO L899 garLoopResultBuilder]: For program point L328-1(lines 328 334) no Hoare annotation was computed. [2022-11-19 06:39:35,655 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 102 126) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 1)) .cse2 .cse3) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2 .cse3))) [2022-11-19 06:39:35,655 INFO L895 garLoopResultBuilder]: At program point L116(line 116) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (let ((.cse7 (not (<= ~waterLevel~0 2))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse8 (= ~switchedOnBeforeTS~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse1 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) .cse5)) (.cse3 (not (<= ~waterLevel~0 1))) (.cse4 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 (not (= 2 ~waterLevel~0)) .cse2 .cse5 .cse4) (or .cse0 .cse6 .cse7 .cse8 .cse4) (or .cse0 .cse6 .cse7 .cse5 .cse4) (or .cse0 .cse7 .cse2 .cse8 .cse4) (or .cse0 .cse6 .cse1 .cse3 .cse4)))) [2022-11-19 06:39:35,656 INFO L895 garLoopResultBuilder]: At program point L110(lines 110 118) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (let ((.cse7 (not (<= ~waterLevel~0 2))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse8 (= ~switchedOnBeforeTS~0 0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse1 (and (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) .cse5)) (.cse3 (not (<= ~waterLevel~0 1))) (.cse4 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse0 (not (= 2 ~waterLevel~0)) .cse2 .cse5 .cse4) (or .cse0 .cse6 .cse7 .cse8 .cse4) (or .cse0 .cse6 .cse7 .cse5 .cse4) (or .cse0 .cse7 .cse2 .cse8 .cse4) (or .cse0 .cse6 .cse1 .cse3 .cse4)))) [2022-11-19 06:39:35,656 INFO L895 garLoopResultBuilder]: At program point L106(lines 106 123) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 1)) .cse2 .cse3) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1 .cse2 .cse3))) [2022-11-19 06:39:35,656 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 102 126) no Hoare annotation was computed. [2022-11-19 06:39:35,656 INFO L895 garLoopResultBuilder]: At program point L121(line 121) the Hoare annotation is: (let ((.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not (= 1 ~systemActive~0))) (.cse6 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse4 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4) (or .cse5 .cse0 .cse1 .cse2 .cse4) (or .cse5 .cse0 .cse6 .cse1 .cse4) (or .cse0 .cse6 .cse1 .cse3 .cse4))) [2022-11-19 06:39:35,656 INFO L899 garLoopResultBuilder]: For program point L121-1(lines 102 126) no Hoare annotation was computed. [2022-11-19 06:39:35,657 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 952 963) no Hoare annotation was computed. [2022-11-19 06:39:35,657 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 952 963) the Hoare annotation is: (let ((.cse10 (= 0 ~systemActive~0))) (let ((.cse5 (not .cse10)) (.cse7 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse3 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse8 (not (= ~methaneLevelCritical~0 0))) (.cse1 (not (= ~pumpRunning~0 0))) (.cse9 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~methaneLevelCritical~0 1))) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 .cse1 .cse2 .cse3 .cse4 .cse5) (or .cse1 (= 2 ~waterLevel~0) .cse2 .cse3 .cse6 .cse5 .cse7) (or .cse1 .cse8 .cse3 .cse4 .cse6 .cse5) (or .cse9 .cse8 (not (= ~pumpRunning~0 1)) .cse4 .cse6 .cse7) (or .cse0 .cse9 .cse2 .cse3 .cse4) (or .cse0 .cse9 .cse8 .cse3 .cse4) (or .cse1 .cse9 .cse8 .cse4 .cse10 .cse6) (or .cse1 .cse9 .cse2 .cse4 .cse10 .cse6)))) [2022-11-19 06:39:35,657 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 198 206) no Hoare annotation was computed. [2022-11-19 06:39:35,657 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 198 206) the Hoare annotation is: true [2022-11-19 06:39:35,660 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 06:39:35,662 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-19 06:39:35,713 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 19.11 06:39:35 BoogieIcfgContainer [2022-11-19 06:39:35,713 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-19 06:39:35,714 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-19 06:39:35,714 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-19 06:39:35,714 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-19 06:39:35,715 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 06:37:36" (3/4) ... [2022-11-19 06:39:35,724 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-19 06:39:35,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-19 06:39:35,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-19 06:39:35,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-19 06:39:35,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-19 06:39:35,744 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-19 06:39:35,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 06:39:35,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-19 06:39:35,745 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-19 06:39:35,751 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 53 nodes and edges [2022-11-19 06:39:35,755 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 14 nodes and edges [2022-11-19 06:39:35,755 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-19 06:39:35,756 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 06:39:35,756 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 06:39:35,784 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || pumpRunning == switchedOnBeforeTS)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && !(0 == systemActive))) || !(methaneLevelCritical == 1))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 2))) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) && pumpRunning == 1))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && !(0 == systemActive))) [2022-11-19 06:39:35,785 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || (((\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) && pumpRunning == switchedOnBeforeTS)) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) [2022-11-19 06:39:35,787 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp___0 == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || !(methaneLevelCritical == 1)) || (((((((pumpRunning == \old(pumpRunning) && (!(pumpRunning == 0) || !(methaneLevelCritical == 0))) && (!(pumpRunning == 0) || 2 == waterLevel)) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1))) && ((((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 1 == systemActive) && methaneLevelCritical == 1) && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((waterLevel == 1 && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp___0 == 0) && tmp == waterLevel)) || !(\old(waterLevel) == 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp___0 == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || !(\old(waterLevel) <= 2)) || ((((((pumpRunning == \old(pumpRunning) && (!(pumpRunning == 0) || !(methaneLevelCritical == 0))) && (!(pumpRunning == 0) || 2 == waterLevel)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || \old(switchedOnBeforeTS) == 0)) && ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || ((((pumpRunning == 0 && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || (((tmp == 2 && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == 1))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || !(0 == systemActive)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 1)) || (((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || tmp___0 == 0) || !(0 == systemActive))) && (((((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 1 == systemActive) && methaneLevelCritical == 1) && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp___0 == 0) && tmp == waterLevel)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) [2022-11-19 06:39:35,787 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) [2022-11-19 06:39:35,787 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) [2022-11-19 06:39:35,787 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || (((\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) && pumpRunning == switchedOnBeforeTS)) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) [2022-11-19 06:39:35,788 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || !(waterLevel <= 2)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-19 06:39:35,791 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((!(1 == systemActive) || (tmp == 0 && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(1 == systemActive) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(waterLevel <= 2)) || !(methaneLevelCritical == 1)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || (tmp == 0 && pumpRunning == switchedOnBeforeTS)) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-19 06:39:35,838 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/witness.graphml [2022-11-19 06:39:35,838 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-19 06:39:35,839 INFO L158 Benchmark]: Toolchain (without parser) took 121211.48ms. Allocated memory was 113.2MB in the beginning and 1.1GB in the end (delta: 1.0GB). Free memory was 69.7MB in the beginning and 568.0MB in the end (delta: -498.4MB). Peak memory consumption was 505.2MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,840 INFO L158 Benchmark]: CDTParser took 0.23ms. Allocated memory is still 113.2MB. Free memory is still 86.7MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-19 06:39:35,840 INFO L158 Benchmark]: CACSL2BoogieTranslator took 562.47ms. Allocated memory is still 113.2MB. Free memory was 69.4MB in the beginning and 78.3MB in the end (delta: -8.8MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,840 INFO L158 Benchmark]: Boogie Procedure Inliner took 58.55ms. Allocated memory is still 113.2MB. Free memory was 78.3MB in the beginning and 76.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,841 INFO L158 Benchmark]: Boogie Preprocessor took 31.91ms. Allocated memory is still 113.2MB. Free memory was 76.2MB in the beginning and 74.4MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,841 INFO L158 Benchmark]: RCFGBuilder took 825.49ms. Allocated memory is still 113.2MB. Free memory was 74.4MB in the beginning and 46.8MB in the end (delta: 27.6MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,842 INFO L158 Benchmark]: TraceAbstraction took 119602.16ms. Allocated memory was 113.2MB in the beginning and 1.1GB in the end (delta: 1.0GB). Free memory was 46.0MB in the beginning and 574.3MB in the end (delta: -528.3MB). Peak memory consumption was 658.2MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,842 INFO L158 Benchmark]: Witness Printer took 124.53ms. Allocated memory is still 1.1GB. Free memory was 574.3MB in the beginning and 568.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-19 06:39:35,844 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.23ms. Allocated memory is still 113.2MB. Free memory is still 86.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 562.47ms. Allocated memory is still 113.2MB. Free memory was 69.4MB in the beginning and 78.3MB in the end (delta: -8.8MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 58.55ms. Allocated memory is still 113.2MB. Free memory was 78.3MB in the beginning and 76.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 31.91ms. Allocated memory is still 113.2MB. Free memory was 76.2MB in the beginning and 74.4MB in the end (delta: 1.8MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 825.49ms. Allocated memory is still 113.2MB. Free memory was 74.4MB in the beginning and 46.8MB in the end (delta: 27.6MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. * TraceAbstraction took 119602.16ms. Allocated memory was 113.2MB in the beginning and 1.1GB in the end (delta: 1.0GB). Free memory was 46.0MB in the beginning and 574.3MB in the end (delta: -528.3MB). Peak memory consumption was 658.2MB. Max. memory is 16.1GB. * Witness Printer took 124.53ms. Allocated memory is still 1.1GB. Free memory was 574.3MB in the beginning and 568.0MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 933]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 66 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 119.4s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 16.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 58.3s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 5531 SdHoareTripleChecker+Valid, 7.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 5493 mSDsluCounter, 5125 SdHoareTripleChecker+Invalid, 6.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 4164 mSDsCounter, 3866 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 9915 IncrementalHoareTripleChecker+Invalid, 13781 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 3866 mSolverCounterUnsat, 961 mSDtfsCounter, 9915 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1396 GetRequests, 913 SyntacticMatches, 11 SemanticMatches, 472 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 20392 ImplicationChecksByTransitivity, 30.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1733occurred in iteration=10, InterpolantAutomatonStates: 299, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.7s AutomataMinimizationTime, 11 MinimizatonAttempts, 1408 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 39 LocationsWithAnnotation, 5607 PreInvPairs, 7512 NumberOfFragments, 6049 HoareAnnotationTreeSize, 5607 FomulaSimplifications, 157653 FormulaSimplificationTreeSizeReduction, 20.4s HoareSimplificationTime, 39 FomulaSimplificationsInter, 372294 FormulaSimplificationTreeSizeReductionInter, 37.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 5.6s InterpolantComputationTime, 825 NumberOfCodeBlocks, 825 NumberOfCodeBlocksAsserted, 15 NumberOfCheckSat, 1118 ConstructedInterpolants, 0 QuantifiedInterpolants, 3805 SizeOfPredicates, 37 NumberOfNonLiveVariables, 1534 ConjunctsInSsa, 98 ConjunctsInUnsatCore, 19 InterpolantComputations, 7 PerfectInterpolantSequences, 421/650 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && waterLevel == 1) && tmp == 1) && pumpRunning == switchedOnBeforeTS - InvariantResult [Line: 398]: Loop Invariant Derived loop invariant: (((((((((((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp___0 == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || !(methaneLevelCritical == 1)) || (((((((pumpRunning == \old(pumpRunning) && (!(pumpRunning == 0) || !(methaneLevelCritical == 0))) && (!(pumpRunning == 0) || 2 == waterLevel)) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1))) && ((((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 1 == systemActive) && methaneLevelCritical == 1) && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || (((waterLevel == 1 && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp___0 == 0) && tmp == waterLevel)) || !(\old(waterLevel) == 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp___0 == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || !(\old(waterLevel) <= 2)) || ((((((pumpRunning == \old(pumpRunning) && (!(pumpRunning == 0) || !(methaneLevelCritical == 0))) && (!(pumpRunning == 0) || 2 == waterLevel)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || \old(switchedOnBeforeTS) == 0)) && ((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || ((((pumpRunning == 0 && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || (((tmp == 2 && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == 1))) && ((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) || !(0 == systemActive)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 1)) || (((((pumpRunning == 0 && tmp___0 == 0) && \old(waterLevel) == waterLevel) && 0 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(0 == systemActive))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(methaneLevelCritical == 0)) || tmp___0 == 0) || !(0 == systemActive))) && (((((((((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && 1 == systemActive) && methaneLevelCritical == 1) && tmp == 2) && \old(waterLevel) == waterLevel) && tmp == waterLevel) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && \old(waterLevel) == waterLevel + 1) && tmp___0 == 0) && tmp == waterLevel)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2)) - InvariantResult [Line: 318]: Loop Invariant Derived loop invariant: ((((((((((((((((pumpRunning == 0 && 2 == waterLevel) && (!(methaneLevelCritical == 0) || pumpRunning == 1)) && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive)) || (((((methaneLevelCritical == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((methaneLevelCritical == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || ((((((2 == waterLevel && methaneLevelCritical == 0) && (!(methaneLevelCritical == 0) || pumpRunning == 1)) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1) && !(0 == systemActive))) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel <= 1) && splverifierCounter == 0) && 0 == systemActive) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || ((((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && splverifierCounter == 0) && 0 == systemActive) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((waterLevel <= 1 && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel <= 1) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1)) || (((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1)) || ((((((pumpRunning == 0 && methaneLevelCritical == 1) && splverifierCounter == 0) && waterLevel <= 2) && 0 == systemActive) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((pumpRunning == 0 && waterLevel <= 1) && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) - InvariantResult [Line: 285]: Loop Invariant Derived loop invariant: (((((((((pumpRunning == 0 && waterLevel <= 1) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS) || (((((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel <= 1) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((pumpRunning == 0 && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1)) || (((((pumpRunning == 0 && methaneLevelCritical == 0) && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1)) || ((((pumpRunning == 0 && 2 == waterLevel) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1)) || (((((pumpRunning == 0 && methaneLevelCritical == 0) && waterLevel <= 1) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1) - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 933]: Loop Invariant Derived loop invariant: ((((((((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) == 2))) && ((!(1 == systemActive) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) - InvariantResult [Line: 110]: Loop Invariant Derived loop invariant: ((((((((!(1 == systemActive) || (tmp == 0 && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(1 == systemActive) || !(2 == waterLevel)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(waterLevel <= 2)) || !(methaneLevelCritical == 1)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || (tmp == 0 && pumpRunning == switchedOnBeforeTS)) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) - InvariantResult [Line: 132]: Loop Invariant Derived loop invariant: (((((((((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || ((((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1))) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && waterLevel <= 0) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 795]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 106]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || !(waterLevel <= 2)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) - InvariantResult [Line: 348]: Loop Invariant Derived loop invariant: ((((((((((((2 == waterLevel && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS) || ((((((pumpRunning == 0 && methaneLevelCritical == 0) && splverifierCounter == 0) && waterLevel <= 2) && 0 == systemActive) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((2 == waterLevel && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1) && pumpRunning == 1)) || (((((waterLevel <= 1 && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((methaneLevelCritical == 0 && waterLevel <= 1) && 1 == systemActive) && splverifierCounter == 0) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || ((((2 == waterLevel && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1)) || ((((((pumpRunning == 0 && methaneLevelCritical == 1) && splverifierCounter == 0) && waterLevel <= 2) && 0 == systemActive) && tmp == 1) && pumpRunning == switchedOnBeforeTS)) || (((((pumpRunning == 0 && methaneLevelCritical == 0) && 1 == systemActive) && splverifierCounter == 0) && waterLevel <= 2) && tmp == 1)) || (((((pumpRunning == 0 && waterLevel <= 1) && 1 == systemActive) && methaneLevelCritical == 1) && splverifierCounter == 0) && tmp == 1) - InvariantResult [Line: 81]: Loop Invariant Derived loop invariant: (((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || (((\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) && pumpRunning == switchedOnBeforeTS)) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 805]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 308]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 393]: Loop Invariant Derived loop invariant: (((((((((((((((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(pumpRunning) == 0)) || !(\old(waterLevel) == 1)) || !(methaneLevelCritical == 0)) || pumpRunning == switchedOnBeforeTS) || !(0 == systemActive))) && ((((!(\old(pumpRunning) == 0) || ((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && 0 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || pumpRunning == switchedOnBeforeTS)) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && !(0 == systemActive))) || !(methaneLevelCritical == 1))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || !(methaneLevelCritical == 1)) || pumpRunning == switchedOnBeforeTS)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((((!(switchedOnBeforeTS == 0) && pumpRunning == \old(pumpRunning)) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS) && !(0 == systemActive))) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && ((((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) == 2))) && (((!(1 == systemActive) || ((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && ((((!(1 == systemActive) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) || ((pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) && pumpRunning == 1))) && ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || (((((pumpRunning == \old(pumpRunning) && pumpRunning == 0) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && !(0 == systemActive))) - InvariantResult [Line: 128]: Loop Invariant Derived loop invariant: (((((((((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || (((\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel)) && pumpRunning == switchedOnBeforeTS) && pumpRunning == 1)) || !(methaneLevelCritical == 0)) || !(\old(pumpRunning) == 1)) || !(\old(waterLevel) == 2)) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && (((((((2 == waterLevel && \old(waterLevel) == waterLevel) && pumpRunning == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 0)) || !(\old(waterLevel) <= 2))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2))) && (((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) || !(1 == systemActive)) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || (!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel))) && pumpRunning == switchedOnBeforeTS)) || (pumpRunning == \old(pumpRunning) && pumpRunning == 0)) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) == 2))) && (((!(\old(pumpRunning) == 0) || !(methaneLevelCritical == 1)) || !(\old(waterLevel) <= 2)) || !(0 == systemActive))) && ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(methaneLevelCritical == 0)) || ((pumpRunning == \old(pumpRunning) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) RESULT: Ultimate proved your program to be correct! [2022-11-19 06:39:35,900 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_c99971f6-9dd2-4e74-913f-be3d8a99c2f0/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE