./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 8393723b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 34b47c00ac265c7154b048b065075686f0b0d02157935b615817b802464c404c --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-8393723 [2022-11-19 07:45:22,432 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-19 07:45:22,436 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-19 07:45:22,476 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-19 07:45:22,479 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-19 07:45:22,484 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-19 07:45:22,488 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-19 07:45:22,495 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-19 07:45:22,501 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-19 07:45:22,504 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-19 07:45:22,507 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-19 07:45:22,510 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-19 07:45:22,511 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-19 07:45:22,517 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-19 07:45:22,522 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-19 07:45:22,524 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-19 07:45:22,526 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-19 07:45:22,528 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-19 07:45:22,530 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-19 07:45:22,534 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-19 07:45:22,538 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-19 07:45:22,540 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-19 07:45:22,544 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-19 07:45:22,545 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-19 07:45:22,553 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-19 07:45:22,558 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-19 07:45:22,559 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-19 07:45:22,560 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-19 07:45:22,562 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-19 07:45:22,564 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-19 07:45:22,564 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-19 07:45:22,565 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-19 07:45:22,568 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-19 07:45:22,570 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-19 07:45:22,572 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-19 07:45:22,572 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-19 07:45:22,573 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-19 07:45:22,574 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-19 07:45:22,574 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-19 07:45:22,575 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-19 07:45:22,576 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-19 07:45:22,577 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-19 07:45:22,632 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-19 07:45:22,633 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-19 07:45:22,634 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-19 07:45:22,634 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-19 07:45:22,635 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-19 07:45:22,635 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-19 07:45:22,636 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-19 07:45:22,636 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-19 07:45:22,636 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-19 07:45:22,637 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-19 07:45:22,638 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-19 07:45:22,639 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-19 07:45:22,639 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-19 07:45:22,639 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-19 07:45:22,640 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-19 07:45:22,640 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-19 07:45:22,640 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-19 07:45:22,641 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-19 07:45:22,642 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-19 07:45:22,642 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-19 07:45:22,643 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-19 07:45:22,643 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-19 07:45:22,643 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-19 07:45:22,644 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-19 07:45:22,644 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-19 07:45:22,644 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-19 07:45:22,645 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-19 07:45:22,645 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-19 07:45:22,646 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-19 07:45:22,646 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-19 07:45:22,646 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-19 07:45:22,647 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-19 07:45:22,647 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 07:45:22,648 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-19 07:45:22,648 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-19 07:45:22,649 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-19 07:45:22,649 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-19 07:45:22,649 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-19 07:45:22,650 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-19 07:45:22,650 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-19 07:45:22,650 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-19 07:45:22,651 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 34b47c00ac265c7154b048b065075686f0b0d02157935b615817b802464c404c [2022-11-19 07:45:23,023 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-19 07:45:23,057 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-19 07:45:23,060 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-19 07:45:23,062 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-19 07:45:23,063 INFO L275 PluginConnector]: CDTParser initialized [2022-11-19 07:45:23,064 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/../../sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c [2022-11-19 07:45:23,151 INFO L220 CDTParser]: Created temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/data/0a6e30da3/cc8ca4baee1b4d79b5633190020db831/FLAGe8e34a20e [2022-11-19 07:45:23,879 INFO L306 CDTParser]: Found 1 translation units. [2022-11-19 07:45:23,880 INFO L160 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c [2022-11-19 07:45:23,911 INFO L349 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/data/0a6e30da3/cc8ca4baee1b4d79b5633190020db831/FLAGe8e34a20e [2022-11-19 07:45:24,119 INFO L357 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/data/0a6e30da3/cc8ca4baee1b4d79b5633190020db831 [2022-11-19 07:45:24,123 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-19 07:45:24,127 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-19 07:45:24,132 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-19 07:45:24,132 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-19 07:45:24,137 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-19 07:45:24,138 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,140 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@2e4059a4 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24, skipping insertion in model container [2022-11-19 07:45:24,141 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,153 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-19 07:45:24,237 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-19 07:45:24,695 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c[19180,19193] [2022-11-19 07:45:24,702 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 07:45:24,713 INFO L203 MainTranslator]: Completed pre-run [2022-11-19 07:45:24,800 WARN L234 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/sv-benchmarks/c/product-lines/minepump_spec5_product62.cil.c[19180,19193] [2022-11-19 07:45:24,814 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-19 07:45:24,842 INFO L208 MainTranslator]: Completed translation [2022-11-19 07:45:24,843 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24 WrapperNode [2022-11-19 07:45:24,843 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-19 07:45:24,844 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-19 07:45:24,844 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-19 07:45:24,845 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-19 07:45:24,854 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,880 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,943 INFO L138 Inliner]: procedures = 60, calls = 108, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 241 [2022-11-19 07:45:24,944 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-19 07:45:24,945 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-19 07:45:24,945 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-19 07:45:24,945 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-19 07:45:24,958 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,958 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,961 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,962 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,967 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,973 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,975 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,977 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:24,980 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-19 07:45:24,981 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-19 07:45:24,981 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-19 07:45:24,981 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-19 07:45:24,983 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (1/1) ... [2022-11-19 07:45:25,023 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-19 07:45:25,040 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 07:45:25,072 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-19 07:45:25,075 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-19 07:45:25,135 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-19 07:45:25,136 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-19 07:45:25,137 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-19 07:45:25,138 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-19 07:45:25,138 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-19 07:45:25,138 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-19 07:45:25,138 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-19 07:45:25,139 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 07:45:25,139 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 07:45:25,139 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-19 07:45:25,139 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-19 07:45:25,140 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2022-11-19 07:45:25,140 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2022-11-19 07:45:25,140 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-19 07:45:25,140 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-19 07:45:25,141 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2022-11-19 07:45:25,141 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2022-11-19 07:45:25,141 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2022-11-19 07:45:25,141 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2022-11-19 07:45:25,142 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-19 07:45:25,142 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-19 07:45:25,142 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-19 07:45:25,142 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-19 07:45:25,143 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-19 07:45:25,300 INFO L235 CfgBuilder]: Building ICFG [2022-11-19 07:45:25,303 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-19 07:45:25,684 INFO L276 CfgBuilder]: Performing block encoding [2022-11-19 07:45:25,895 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-19 07:45:25,895 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-19 07:45:25,899 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 07:45:25 BoogieIcfgContainer [2022-11-19 07:45:25,899 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-19 07:45:25,902 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-19 07:45:25,902 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-19 07:45:25,906 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-19 07:45:25,907 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 19.11 07:45:24" (1/3) ... [2022-11-19 07:45:25,908 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7034d367 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 07:45:25, skipping insertion in model container [2022-11-19 07:45:25,908 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 19.11 07:45:24" (2/3) ... [2022-11-19 07:45:25,909 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7034d367 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 19.11 07:45:25, skipping insertion in model container [2022-11-19 07:45:25,909 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 07:45:25" (3/3) ... [2022-11-19 07:45:25,911 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product62.cil.c [2022-11-19 07:45:25,934 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-19 07:45:25,935 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-19 07:45:26,026 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-19 07:45:26,042 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@3376dcc9, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-19 07:45:26,043 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-19 07:45:26,048 INFO L276 IsEmpty]: Start isEmpty. Operand has 75 states, 45 states have (on average 1.4) internal successors, (63), 55 states have internal predecessors, (63), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) [2022-11-19 07:45:26,063 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-19 07:45:26,063 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:26,064 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:26,066 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:26,077 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:26,077 INFO L85 PathProgramCache]: Analyzing trace with hash 442962897, now seen corresponding path program 1 times [2022-11-19 07:45:26,090 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:26,092 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [857142121] [2022-11-19 07:45:26,092 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:26,093 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:26,258 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:26,341 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 07:45:26,342 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:26,342 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [857142121] [2022-11-19 07:45:26,343 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [857142121] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:26,343 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:26,345 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-19 07:45:26,347 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [841145324] [2022-11-19 07:45:26,349 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:26,354 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-19 07:45:26,356 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:26,391 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-19 07:45:26,393 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 07:45:26,397 INFO L87 Difference]: Start difference. First operand has 75 states, 45 states have (on average 1.4) internal successors, (63), 55 states have internal predecessors, (63), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:26,524 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:26,525 INFO L93 Difference]: Finished difference Result 148 states and 199 transitions. [2022-11-19 07:45:26,526 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-19 07:45:26,528 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-19 07:45:26,528 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:26,539 INFO L225 Difference]: With dead ends: 148 [2022-11-19 07:45:26,539 INFO L226 Difference]: Without dead ends: 70 [2022-11-19 07:45:26,544 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-19 07:45:26,548 INFO L413 NwaCegarLoop]: 78 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 78 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:26,549 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 78 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 07:45:26,571 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2022-11-19 07:45:26,624 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2022-11-19 07:45:26,626 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 42 states have (on average 1.3095238095238095) internal successors, (55), 51 states have internal predecessors, (55), 18 states have call successors, (18), 10 states have call predecessors, (18), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2022-11-19 07:45:26,630 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 90 transitions. [2022-11-19 07:45:26,632 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 90 transitions. Word has length 21 [2022-11-19 07:45:26,632 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:26,632 INFO L495 AbstractCegarLoop]: Abstraction has 70 states and 90 transitions. [2022-11-19 07:45:26,633 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:26,633 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 90 transitions. [2022-11-19 07:45:26,636 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-19 07:45:26,636 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:26,636 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:26,637 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-19 07:45:26,637 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:26,638 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:26,638 INFO L85 PathProgramCache]: Analyzing trace with hash 2021379213, now seen corresponding path program 1 times [2022-11-19 07:45:26,638 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:26,639 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [685098549] [2022-11-19 07:45:26,639 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:26,639 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:26,665 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:26,778 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 07:45:26,778 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:26,779 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [685098549] [2022-11-19 07:45:26,780 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [685098549] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:26,780 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:26,781 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-19 07:45:26,781 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [957279191] [2022-11-19 07:45:26,783 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:26,784 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-19 07:45:26,786 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:26,786 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-19 07:45:26,787 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 07:45:26,788 INFO L87 Difference]: Start difference. First operand 70 states and 90 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:26,888 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:26,891 INFO L93 Difference]: Finished difference Result 117 states and 151 transitions. [2022-11-19 07:45:26,892 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-19 07:45:26,893 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-19 07:45:26,893 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:26,895 INFO L225 Difference]: With dead ends: 117 [2022-11-19 07:45:26,895 INFO L226 Difference]: Without dead ends: 62 [2022-11-19 07:45:26,896 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-19 07:45:26,898 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 7 mSDsluCounter, 55 mSDsCounter, 0 mSdLazyCounter, 27 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 119 SdHoareTripleChecker+Invalid, 27 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 27 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:26,899 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 119 Invalid, 27 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 27 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-19 07:45:26,900 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 62 states. [2022-11-19 07:45:26,910 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 62 to 62. [2022-11-19 07:45:26,911 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 62 states, 37 states have (on average 1.3243243243243243) internal successors, (49), 46 states have internal predecessors, (49), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2022-11-19 07:45:26,913 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 62 states to 62 states and 79 transitions. [2022-11-19 07:45:26,914 INFO L78 Accepts]: Start accepts. Automaton has 62 states and 79 transitions. Word has length 22 [2022-11-19 07:45:26,914 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:26,914 INFO L495 AbstractCegarLoop]: Abstraction has 62 states and 79 transitions. [2022-11-19 07:45:26,914 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:26,915 INFO L276 IsEmpty]: Start isEmpty. Operand 62 states and 79 transitions. [2022-11-19 07:45:26,916 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-19 07:45:26,917 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:26,917 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:26,917 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-19 07:45:26,918 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:26,918 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:26,918 INFO L85 PathProgramCache]: Analyzing trace with hash 495074929, now seen corresponding path program 1 times [2022-11-19 07:45:26,919 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:26,919 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [419754261] [2022-11-19 07:45:26,919 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:26,920 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:26,948 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:27,159 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-19 07:45:27,160 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:27,160 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [419754261] [2022-11-19 07:45:27,161 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [419754261] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:27,161 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:27,161 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-19 07:45:27,161 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [986901837] [2022-11-19 07:45:27,162 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:27,162 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-19 07:45:27,163 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:27,163 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-19 07:45:27,164 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2022-11-19 07:45:27,164 INFO L87 Difference]: Start difference. First operand 62 states and 79 transitions. Second operand has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:27,403 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:27,403 INFO L93 Difference]: Finished difference Result 166 states and 218 transitions. [2022-11-19 07:45:27,404 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2022-11-19 07:45:27,404 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 24 [2022-11-19 07:45:27,405 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:27,407 INFO L225 Difference]: With dead ends: 166 [2022-11-19 07:45:27,407 INFO L226 Difference]: Without dead ends: 106 [2022-11-19 07:45:27,408 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2022-11-19 07:45:27,410 INFO L413 NwaCegarLoop]: 74 mSDtfsCounter, 43 mSDsluCounter, 238 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 44 SdHoareTripleChecker+Valid, 312 SdHoareTripleChecker+Invalid, 136 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:27,411 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [44 Valid, 312 Invalid, 136 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 07:45:27,412 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 106 states. [2022-11-19 07:45:27,436 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 106 to 102. [2022-11-19 07:45:27,438 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 102 states, 64 states have (on average 1.25) internal successors, (80), 72 states have internal predecessors, (80), 20 states have call successors, (20), 17 states have call predecessors, (20), 17 states have return successors, (26), 18 states have call predecessors, (26), 20 states have call successors, (26) [2022-11-19 07:45:27,440 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 102 states to 102 states and 126 transitions. [2022-11-19 07:45:27,440 INFO L78 Accepts]: Start accepts. Automaton has 102 states and 126 transitions. Word has length 24 [2022-11-19 07:45:27,441 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:27,441 INFO L495 AbstractCegarLoop]: Abstraction has 102 states and 126 transitions. [2022-11-19 07:45:27,441 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-19 07:45:27,442 INFO L276 IsEmpty]: Start isEmpty. Operand 102 states and 126 transitions. [2022-11-19 07:45:27,443 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2022-11-19 07:45:27,443 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:27,444 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:27,444 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-19 07:45:27,444 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:27,445 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:27,445 INFO L85 PathProgramCache]: Analyzing trace with hash 1823229499, now seen corresponding path program 1 times [2022-11-19 07:45:27,445 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:27,445 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1081369091] [2022-11-19 07:45:27,446 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:27,446 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:27,514 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:28,154 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 07:45:28,155 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:28,155 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1081369091] [2022-11-19 07:45:28,155 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1081369091] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:28,156 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:28,156 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-19 07:45:28,156 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1430225580] [2022-11-19 07:45:28,156 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:28,158 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-19 07:45:28,159 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:28,160 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-19 07:45:28,160 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-19 07:45:28,161 INFO L87 Difference]: Start difference. First operand 102 states and 126 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 6 states have internal predecessors, (29), 5 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-19 07:45:28,481 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:28,481 INFO L93 Difference]: Finished difference Result 289 states and 357 transitions. [2022-11-19 07:45:28,482 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-19 07:45:28,482 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 6 states have internal predecessors, (29), 5 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) Word has length 41 [2022-11-19 07:45:28,482 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:28,492 INFO L225 Difference]: With dead ends: 289 [2022-11-19 07:45:28,493 INFO L226 Difference]: Without dead ends: 189 [2022-11-19 07:45:28,498 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-19 07:45:28,502 INFO L413 NwaCegarLoop]: 100 mSDtfsCounter, 107 mSDsluCounter, 166 mSDsCounter, 0 mSdLazyCounter, 138 mSolverCounterSat, 25 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 108 SdHoareTripleChecker+Valid, 266 SdHoareTripleChecker+Invalid, 163 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 25 IncrementalHoareTripleChecker+Valid, 138 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:28,503 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [108 Valid, 266 Invalid, 163 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [25 Valid, 138 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-19 07:45:28,504 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 189 states. [2022-11-19 07:45:28,534 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 189 to 185. [2022-11-19 07:45:28,535 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 185 states, 116 states have (on average 1.2241379310344827) internal successors, (142), 129 states have internal predecessors, (142), 36 states have call successors, (36), 31 states have call predecessors, (36), 32 states have return successors, (48), 33 states have call predecessors, (48), 36 states have call successors, (48) [2022-11-19 07:45:28,537 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 185 states to 185 states and 226 transitions. [2022-11-19 07:45:28,538 INFO L78 Accepts]: Start accepts. Automaton has 185 states and 226 transitions. Word has length 41 [2022-11-19 07:45:28,538 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:28,539 INFO L495 AbstractCegarLoop]: Abstraction has 185 states and 226 transitions. [2022-11-19 07:45:28,539 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 6 states have internal predecessors, (29), 5 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2022-11-19 07:45:28,539 INFO L276 IsEmpty]: Start isEmpty. Operand 185 states and 226 transitions. [2022-11-19 07:45:28,542 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2022-11-19 07:45:28,542 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:28,542 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:28,542 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-19 07:45:28,543 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:28,543 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:28,543 INFO L85 PathProgramCache]: Analyzing trace with hash -203386622, now seen corresponding path program 1 times [2022-11-19 07:45:28,544 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:28,544 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [504667998] [2022-11-19 07:45:28,544 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:28,544 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:28,577 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:29,059 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-19 07:45:29,059 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:29,059 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [504667998] [2022-11-19 07:45:29,060 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [504667998] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:29,060 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:29,060 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-19 07:45:29,060 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [998254445] [2022-11-19 07:45:29,060 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:29,061 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 07:45:29,061 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:29,062 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 07:45:29,062 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-19 07:45:29,062 INFO L87 Difference]: Start difference. First operand 185 states and 226 transitions. Second operand has 8 states, 7 states have (on average 4.285714285714286) internal successors, (30), 7 states have internal predecessors, (30), 5 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) [2022-11-19 07:45:29,913 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:29,913 INFO L93 Difference]: Finished difference Result 435 states and 545 transitions. [2022-11-19 07:45:29,914 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-19 07:45:29,914 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 4.285714285714286) internal successors, (30), 7 states have internal predecessors, (30), 5 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) Word has length 44 [2022-11-19 07:45:29,915 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:29,922 INFO L225 Difference]: With dead ends: 435 [2022-11-19 07:45:29,923 INFO L226 Difference]: Without dead ends: 305 [2022-11-19 07:45:29,926 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-19 07:45:29,929 INFO L413 NwaCegarLoop]: 73 mSDtfsCounter, 245 mSDsluCounter, 181 mSDsCounter, 0 mSdLazyCounter, 386 mSolverCounterSat, 107 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 254 SdHoareTripleChecker+Valid, 254 SdHoareTripleChecker+Invalid, 493 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 107 IncrementalHoareTripleChecker+Valid, 386 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:29,931 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [254 Valid, 254 Invalid, 493 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [107 Valid, 386 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2022-11-19 07:45:29,934 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 305 states. [2022-11-19 07:45:30,020 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 305 to 275. [2022-11-19 07:45:30,021 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 275 states, 177 states have (on average 1.231638418079096) internal successors, (218), 195 states have internal predecessors, (218), 51 states have call successors, (51), 39 states have call predecessors, (51), 46 states have return successors, (70), 52 states have call predecessors, (70), 51 states have call successors, (70) [2022-11-19 07:45:30,026 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 275 states to 275 states and 339 transitions. [2022-11-19 07:45:30,026 INFO L78 Accepts]: Start accepts. Automaton has 275 states and 339 transitions. Word has length 44 [2022-11-19 07:45:30,027 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:30,027 INFO L495 AbstractCegarLoop]: Abstraction has 275 states and 339 transitions. [2022-11-19 07:45:30,028 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 4.285714285714286) internal successors, (30), 7 states have internal predecessors, (30), 5 states have call successors, (7), 3 states have call predecessors, (7), 2 states have return successors, (6), 4 states have call predecessors, (6), 5 states have call successors, (6) [2022-11-19 07:45:30,028 INFO L276 IsEmpty]: Start isEmpty. Operand 275 states and 339 transitions. [2022-11-19 07:45:30,036 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 62 [2022-11-19 07:45:30,036 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:30,036 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:30,037 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-19 07:45:30,037 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:30,037 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:30,038 INFO L85 PathProgramCache]: Analyzing trace with hash -1805179232, now seen corresponding path program 1 times [2022-11-19 07:45:30,038 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:30,038 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1315397708] [2022-11-19 07:45:30,038 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:30,038 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:30,061 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:30,221 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 6 proven. 0 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-11-19 07:45:30,221 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:30,221 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1315397708] [2022-11-19 07:45:30,221 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1315397708] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-19 07:45:30,222 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-19 07:45:30,222 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-19 07:45:30,222 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1550656631] [2022-11-19 07:45:30,222 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-19 07:45:30,223 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 07:45:30,223 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:30,223 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 07:45:30,224 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2022-11-19 07:45:30,224 INFO L87 Difference]: Start difference. First operand 275 states and 339 transitions. Second operand has 8 states, 7 states have (on average 5.285714285714286) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (7), 1 states have call predecessors, (7), 2 states have return successors, (8), 3 states have call predecessors, (8), 2 states have call successors, (8) [2022-11-19 07:45:30,926 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:30,926 INFO L93 Difference]: Finished difference Result 561 states and 726 transitions. [2022-11-19 07:45:30,926 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2022-11-19 07:45:30,927 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 5.285714285714286) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (7), 1 states have call predecessors, (7), 2 states have return successors, (8), 3 states have call predecessors, (8), 2 states have call successors, (8) Word has length 61 [2022-11-19 07:45:30,927 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:30,931 INFO L225 Difference]: With dead ends: 561 [2022-11-19 07:45:30,931 INFO L226 Difference]: Without dead ends: 412 [2022-11-19 07:45:30,932 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 46 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=71, Invalid=271, Unknown=0, NotChecked=0, Total=342 [2022-11-19 07:45:30,933 INFO L413 NwaCegarLoop]: 116 mSDtfsCounter, 124 mSDsluCounter, 317 mSDsCounter, 0 mSdLazyCounter, 521 mSolverCounterSat, 44 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 128 SdHoareTripleChecker+Valid, 433 SdHoareTripleChecker+Invalid, 565 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 44 IncrementalHoareTripleChecker+Valid, 521 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:30,934 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [128 Valid, 433 Invalid, 565 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [44 Valid, 521 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-19 07:45:30,935 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 412 states. [2022-11-19 07:45:30,987 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 412 to 379. [2022-11-19 07:45:30,988 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 379 states, 244 states have (on average 1.2049180327868851) internal successors, (294), 272 states have internal predecessors, (294), 70 states have call successors, (70), 54 states have call predecessors, (70), 64 states have return successors, (103), 70 states have call predecessors, (103), 70 states have call successors, (103) [2022-11-19 07:45:30,991 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 379 states to 379 states and 467 transitions. [2022-11-19 07:45:30,992 INFO L78 Accepts]: Start accepts. Automaton has 379 states and 467 transitions. Word has length 61 [2022-11-19 07:45:30,993 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:30,993 INFO L495 AbstractCegarLoop]: Abstraction has 379 states and 467 transitions. [2022-11-19 07:45:30,993 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 5.285714285714286) internal successors, (37), 6 states have internal predecessors, (37), 2 states have call successors, (7), 1 states have call predecessors, (7), 2 states have return successors, (8), 3 states have call predecessors, (8), 2 states have call successors, (8) [2022-11-19 07:45:30,994 INFO L276 IsEmpty]: Start isEmpty. Operand 379 states and 467 transitions. [2022-11-19 07:45:30,996 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 79 [2022-11-19 07:45:30,996 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:30,997 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:30,997 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-19 07:45:30,998 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:30,998 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:30,999 INFO L85 PathProgramCache]: Analyzing trace with hash 1711071724, now seen corresponding path program 1 times [2022-11-19 07:45:30,999 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:30,999 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1186834452] [2022-11-19 07:45:30,999 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:31,000 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:31,024 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:31,337 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 20 trivial. 0 not checked. [2022-11-19 07:45:31,338 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:31,338 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1186834452] [2022-11-19 07:45:31,338 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1186834452] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 07:45:31,338 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [409264831] [2022-11-19 07:45:31,339 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:31,339 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 07:45:31,339 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 07:45:31,344 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 07:45:31,357 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-19 07:45:31,511 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:31,528 INFO L263 TraceCheckSpWp]: Trace formula consists of 358 conjuncts, 22 conjunts are in the unsatisfiable core [2022-11-19 07:45:31,536 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 07:45:31,974 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 35 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-19 07:45:31,974 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 07:45:32,240 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 20 trivial. 0 not checked. [2022-11-19 07:45:32,241 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [409264831] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 07:45:32,241 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1556377259] [2022-11-19 07:45:32,275 INFO L159 IcfgInterpreter]: Started Sifa with 45 locations of interest [2022-11-19 07:45:32,276 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 07:45:32,281 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 07:45:32,288 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 07:45:32,288 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 07:45:39,492 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 53 for LOIs [2022-11-19 07:45:39,504 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 31 for LOIs [2022-11-19 07:45:40,008 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 44 for LOIs [2022-11-19 07:45:40,016 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 26 for LOIs [2022-11-19 07:45:40,082 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 07:45:40,208 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 28 for LOIs [2022-11-19 07:45:40,211 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 07:45:49,260 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '4943#(and (= |timeShift_getWaterLevel_~retValue_acc~8#1| ~waterLevel~0) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (= |old(~waterLevel~0)| ~waterLevel~0) (<= 2 |timeShift_getWaterLevel_#res#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (= ~switchedOnBeforeTS~0 0) (<= |timeShift_getWaterLevel_~retValue_acc~8#1| 2147483647) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~8#1| |timeShift_getWaterLevel_#res#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= |old(~switchedOnBeforeTS~0)| 0))' at error location [2022-11-19 07:45:49,261 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 07:45:49,261 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 07:45:49,261 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [6, 6, 6] total 8 [2022-11-19 07:45:49,261 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1049183901] [2022-11-19 07:45:49,261 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 07:45:49,262 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-19 07:45:49,262 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:45:49,263 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-19 07:45:49,264 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=180, Invalid=1380, Unknown=0, NotChecked=0, Total=1560 [2022-11-19 07:45:49,264 INFO L87 Difference]: Start difference. First operand 379 states and 467 transitions. Second operand has 8 states, 8 states have (on average 7.5) internal successors, (60), 8 states have internal predecessors, (60), 3 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-19 07:45:50,160 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:45:50,160 INFO L93 Difference]: Finished difference Result 1310 states and 1701 transitions. [2022-11-19 07:45:50,168 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-11-19 07:45:50,169 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 7.5) internal successors, (60), 8 states have internal predecessors, (60), 3 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 78 [2022-11-19 07:45:50,169 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:45:50,176 INFO L225 Difference]: With dead ends: 1310 [2022-11-19 07:45:50,176 INFO L226 Difference]: Without dead ends: 921 [2022-11-19 07:45:50,179 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 246 GetRequests, 188 SyntacticMatches, 15 SemanticMatches, 43 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 780 ImplicationChecksByTransitivity, 9.3s TimeCoverageRelationStatistics Valid=221, Invalid=1759, Unknown=0, NotChecked=0, Total=1980 [2022-11-19 07:45:50,181 INFO L413 NwaCegarLoop]: 129 mSDtfsCounter, 203 mSDsluCounter, 366 mSDsCounter, 0 mSdLazyCounter, 358 mSolverCounterSat, 78 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 204 SdHoareTripleChecker+Valid, 495 SdHoareTripleChecker+Invalid, 436 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 78 IncrementalHoareTripleChecker+Valid, 358 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-19 07:45:50,181 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [204 Valid, 495 Invalid, 436 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [78 Valid, 358 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-19 07:45:50,183 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 921 states. [2022-11-19 07:45:50,275 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 921 to 778. [2022-11-19 07:45:50,277 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 778 states, 504 states have (on average 1.1984126984126984) internal successors, (604), 562 states have internal predecessors, (604), 140 states have call successors, (140), 118 states have call predecessors, (140), 133 states have return successors, (248), 138 states have call predecessors, (248), 140 states have call successors, (248) [2022-11-19 07:45:50,283 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 778 states to 778 states and 992 transitions. [2022-11-19 07:45:50,284 INFO L78 Accepts]: Start accepts. Automaton has 778 states and 992 transitions. Word has length 78 [2022-11-19 07:45:50,285 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:45:50,285 INFO L495 AbstractCegarLoop]: Abstraction has 778 states and 992 transitions. [2022-11-19 07:45:50,285 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 7.5) internal successors, (60), 8 states have internal predecessors, (60), 3 states have call successors, (15), 3 states have call predecessors, (15), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2022-11-19 07:45:50,286 INFO L276 IsEmpty]: Start isEmpty. Operand 778 states and 992 transitions. [2022-11-19 07:45:50,290 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 111 [2022-11-19 07:45:50,290 INFO L187 NwaCegarLoop]: Found error trace [2022-11-19 07:45:50,290 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:45:50,299 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-19 07:45:50,498 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 07:45:50,498 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-19 07:45:50,499 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-19 07:45:50,499 INFO L85 PathProgramCache]: Analyzing trace with hash 681535356, now seen corresponding path program 1 times [2022-11-19 07:45:50,499 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-19 07:45:50,500 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1493184845] [2022-11-19 07:45:50,500 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:50,500 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-19 07:45:50,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:51,587 INFO L134 CoverageAnalysis]: Checked inductivity of 89 backedges. 44 proven. 14 refuted. 0 times theorem prover too weak. 31 trivial. 0 not checked. [2022-11-19 07:45:51,587 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-19 07:45:51,587 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1493184845] [2022-11-19 07:45:51,588 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1493184845] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-19 07:45:51,588 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [915739195] [2022-11-19 07:45:51,588 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-19 07:45:51,588 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-19 07:45:51,588 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 [2022-11-19 07:45:51,589 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-19 07:45:51,621 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-19 07:45:51,727 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-19 07:45:51,744 INFO L263 TraceCheckSpWp]: Trace formula consists of 462 conjuncts, 38 conjunts are in the unsatisfiable core [2022-11-19 07:45:51,749 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-19 07:45:52,247 INFO L134 CoverageAnalysis]: Checked inductivity of 89 backedges. 66 proven. 15 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-19 07:45:52,247 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-19 07:45:53,335 INFO L134 CoverageAnalysis]: Checked inductivity of 89 backedges. 53 proven. 5 refuted. 0 times theorem prover too weak. 31 trivial. 0 not checked. [2022-11-19 07:45:53,336 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [915739195] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-19 07:45:53,336 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1535472071] [2022-11-19 07:45:53,339 INFO L159 IcfgInterpreter]: Started Sifa with 51 locations of interest [2022-11-19 07:45:53,339 INFO L166 IcfgInterpreter]: Building call graph [2022-11-19 07:45:53,339 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-19 07:45:53,340 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-19 07:45:53,340 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-19 07:45:59,120 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 55 for LOIs [2022-11-19 07:45:59,128 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 30 for LOIs [2022-11-19 07:45:59,647 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 41 for LOIs [2022-11-19 07:45:59,654 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 26 for LOIs [2022-11-19 07:45:59,713 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-19 07:45:59,855 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 58 for LOIs [2022-11-19 07:45:59,874 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-19 07:46:09,624 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '8880#(and (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 0)) (= |timeShift_getWaterLevel_~retValue_acc~8#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (= ~head~0.offset 0) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| 2)) (= 1 ~systemActive~0) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1| 1) (<= |old(~pumpRunning~0)| 0) (<= 2 |old(~waterLevel~0)|) (<= ~methaneLevelCritical~0 0) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (<= 0 ~head~0.base) (<= 0 ~methaneLevelCritical~0) (<= 2 |timeShift_getWaterLevel_#res#1|) (<= ~head~0.base 0) (= |#NULL.offset| 0) (<= 0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~2#1|) (= ~switchedOnBeforeTS~0 0) (<= |timeShift_getWaterLevel_~retValue_acc~8#1| 2147483647) (<= 0 |#StackHeapBarrier|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~8#1| |timeShift_getWaterLevel_#res#1|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-19 07:46:09,625 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-19 07:46:09,625 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-19 07:46:09,626 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [14, 12, 11] total 26 [2022-11-19 07:46:09,626 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1111354006] [2022-11-19 07:46:09,626 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-19 07:46:09,627 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 26 states [2022-11-19 07:46:09,627 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-19 07:46:09,628 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 26 interpolants. [2022-11-19 07:46:09,630 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=387, Invalid=3273, Unknown=0, NotChecked=0, Total=3660 [2022-11-19 07:46:09,630 INFO L87 Difference]: Start difference. First operand 778 states and 992 transitions. Second operand has 26 states, 25 states have (on average 5.32) internal successors, (133), 26 states have internal predecessors, (133), 14 states have call successors, (32), 6 states have call predecessors, (32), 10 states have return successors, (32), 14 states have call predecessors, (32), 13 states have call successors, (32) [2022-11-19 07:46:13,964 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-19 07:46:13,964 INFO L93 Difference]: Finished difference Result 1684 states and 2168 transitions. [2022-11-19 07:46:13,964 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 59 states. [2022-11-19 07:46:13,965 INFO L78 Accepts]: Start accepts. Automaton has has 26 states, 25 states have (on average 5.32) internal successors, (133), 26 states have internal predecessors, (133), 14 states have call successors, (32), 6 states have call predecessors, (32), 10 states have return successors, (32), 14 states have call predecessors, (32), 13 states have call successors, (32) Word has length 110 [2022-11-19 07:46:13,965 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-19 07:46:13,966 INFO L225 Difference]: With dead ends: 1684 [2022-11-19 07:46:13,966 INFO L226 Difference]: Without dead ends: 0 [2022-11-19 07:46:13,975 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 430 GetRequests, 307 SyntacticMatches, 9 SemanticMatches, 114 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5280 ImplicationChecksByTransitivity, 12.1s TimeCoverageRelationStatistics Valid=1410, Invalid=11930, Unknown=0, NotChecked=0, Total=13340 [2022-11-19 07:46:13,976 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 1104 mSDsluCounter, 535 mSDsCounter, 0 mSdLazyCounter, 1910 mSolverCounterSat, 963 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1104 SdHoareTripleChecker+Valid, 610 SdHoareTripleChecker+Invalid, 2873 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 963 IncrementalHoareTripleChecker+Valid, 1910 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.2s IncrementalHoareTripleChecker+Time [2022-11-19 07:46:13,977 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1104 Valid, 610 Invalid, 2873 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [963 Valid, 1910 Invalid, 0 Unknown, 0 Unchecked, 2.2s Time] [2022-11-19 07:46:13,977 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-19 07:46:13,978 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-19 07:46:13,978 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-19 07:46:13,978 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-19 07:46:13,979 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 110 [2022-11-19 07:46:13,979 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-19 07:46:13,979 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-19 07:46:13,980 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 26 states, 25 states have (on average 5.32) internal successors, (133), 26 states have internal predecessors, (133), 14 states have call successors, (32), 6 states have call predecessors, (32), 10 states have return successors, (32), 14 states have call predecessors, (32), 13 states have call successors, (32) [2022-11-19 07:46:13,980 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-19 07:46:13,980 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-19 07:46:13,983 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-19 07:46:13,991 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2022-11-19 07:46:14,184 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable7 [2022-11-19 07:46:14,186 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-19 07:46:23,284 INFO L895 garLoopResultBuilder]: At program point deactivatePumpENTRY(lines 203 210) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (= ~switchedOnBeforeTS~0 0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,284 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 203 210) no Hoare annotation was computed. [2022-11-19 07:46:23,284 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 93 99) no Hoare annotation was computed. [2022-11-19 07:46:23,284 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 93 99) the Hoare annotation is: true [2022-11-19 07:46:23,285 INFO L895 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-19 07:46:23,285 INFO L895 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (and (not (= ~switchedOnBeforeTS~0 0)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,285 INFO L899 garLoopResultBuilder]: For program point L135(lines 135 143) no Hoare annotation was computed. [2022-11-19 07:46:23,285 INFO L895 garLoopResultBuilder]: At program point L131(lines 131 148) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,286 INFO L895 garLoopResultBuilder]: At program point L146(line 146) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (= ~switchedOnBeforeTS~0 0) .cse1) (or .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-19 07:46:23,286 INFO L899 garLoopResultBuilder]: For program point L146-1(lines 127 151) no Hoare annotation was computed. [2022-11-19 07:46:23,286 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__methaneQueryENTRY(lines 127 151) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,286 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 127 151) no Hoare annotation was computed. [2022-11-19 07:46:23,286 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 222 230) no Hoare annotation was computed. [2022-11-19 07:46:23,287 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 222 230) the Hoare annotation is: true [2022-11-19 07:46:23,287 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 827 838) the Hoare annotation is: true [2022-11-19 07:46:23,287 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 827 838) no Hoare annotation was computed. [2022-11-19 07:46:23,287 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 905 934) no Hoare annotation was computed. [2022-11-19 07:46:23,287 INFO L899 garLoopResultBuilder]: For program point L926(line 926) no Hoare annotation was computed. [2022-11-19 07:46:23,288 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 905 934) the Hoare annotation is: true [2022-11-19 07:46:23,288 INFO L899 garLoopResultBuilder]: For program point L919(lines 919 923) no Hoare annotation was computed. [2022-11-19 07:46:23,288 INFO L902 garLoopResultBuilder]: At program point L919-1(lines 919 923) the Hoare annotation is: true [2022-11-19 07:46:23,288 INFO L902 garLoopResultBuilder]: At program point L915-2(lines 915 929) the Hoare annotation is: true [2022-11-19 07:46:23,288 INFO L902 garLoopResultBuilder]: At program point L911(line 911) the Hoare annotation is: true [2022-11-19 07:46:23,288 INFO L899 garLoopResultBuilder]: For program point L911-1(line 911) no Hoare annotation was computed. [2022-11-19 07:46:23,289 INFO L902 garLoopResultBuilder]: At program point L930(lines 905 934) the Hoare annotation is: true [2022-11-19 07:46:23,289 INFO L895 garLoopResultBuilder]: At program point L159(line 159) the Hoare annotation is: (let ((.cse1 (and (not (= ~pumpRunning~0 0)) (let ((.cse2 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse2) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse0 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0) (or .cse1 .cse0 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse1 .cse0))) [2022-11-19 07:46:23,289 INFO L899 garLoopResultBuilder]: For program point L159-1(line 159) no Hoare annotation was computed. [2022-11-19 07:46:23,291 INFO L895 garLoopResultBuilder]: At program point L345(line 345) the Hoare annotation is: (let ((.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse8 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (= ~pumpRunning~0 0)) (.cse11 (let ((.cse12 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse12) .cse6) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse12)))) (.cse7 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0)) (.cse3 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse4 (not .cse3)) (.cse1 (and (not (= ~switchedOnBeforeTS~0 0)) .cse5 .cse11 .cse7)) (.cse2 (and (not .cse5) .cse11 .cse7 .cse8)) (.cse9 (not (<= |old(~waterLevel~0)| 2))) (.cse10 (not (<= 2 |old(~waterLevel~0)|)))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 .cse1 .cse2 .cse3) (or .cse0 .cse4 (and .cse5 .cse6 .cse7 .cse8)) (or .cse4 .cse9 .cse10) (or .cse1 .cse2 .cse9 .cse10))))) [2022-11-19 07:46:23,291 INFO L899 garLoopResultBuilder]: For program point L345-1(line 345) no Hoare annotation was computed. [2022-11-19 07:46:23,291 INFO L895 garLoopResultBuilder]: At program point L172(line 172) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (= |old(~switchedOnBeforeTS~0)| 0)) (or .cse1 .cse0 (not (<= 2 |old(~waterLevel~0)|))) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2022-11-19 07:46:23,292 INFO L895 garLoopResultBuilder]: At program point L172-1(lines 153 177) the Hoare annotation is: (let ((.cse9 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse10 (<= ~waterLevel~0 2)) (.cse5 (let ((.cse11 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse11) .cse9) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse11)))) (.cse8 (= ~pumpRunning~0 0))) (let ((.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse4 (not .cse8)) (.cse7 (and (not (= ~switchedOnBeforeTS~0 0)) .cse8 .cse10 .cse5)) (.cse2 (and (<= 2 ~waterLevel~0) .cse10 .cse9)) (.cse3 (not (<= 2 |old(~waterLevel~0)|))) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse4 .cse5 .cse6) .cse1 .cse7 (= |old(~switchedOnBeforeTS~0)| 0)) (or .cse1 (and .cse4 (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0) .cse6) .cse7 .cse2 .cse3) (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and .cse8 .cse9 .cse6)))))) [2022-11-19 07:46:23,292 INFO L899 garLoopResultBuilder]: For program point L73-2(lines 69 91) no Hoare annotation was computed. [2022-11-19 07:46:23,292 INFO L895 garLoopResultBuilder]: At program point L330(line 330) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~switchedOnBeforeTS~0 0))) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))) (or .cse2 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or .cse3 (= ~pumpRunning~0 0) .cse1) (or .cse4 .cse3 .cse1 .cse5) (or .cse6 .cse3 .cse0) (or .cse4 .cse2 .cse1 .cse5) (or .cse2 .cse6 .cse0))) [2022-11-19 07:46:23,293 INFO L895 garLoopResultBuilder]: At program point L330-1(line 330) the Hoare annotation is: (let ((.cse3 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse0 (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__2_#t~ret19#1|)) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (<= |old(~waterLevel~0)| 2)))) (and (or (and .cse0 .cse1) .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or .cse3 .cse1 .cse2) (or .cse3 (and (not (= ~switchedOnBeforeTS~0 0)) .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse2 (= |old(~switchedOnBeforeTS~0)| 0)) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse0 .cse1) .cse2))) [2022-11-19 07:46:23,293 INFO L899 garLoopResultBuilder]: For program point L161(lines 161 169) no Hoare annotation was computed. [2022-11-19 07:46:23,293 INFO L899 garLoopResultBuilder]: For program point L157(lines 157 174) no Hoare annotation was computed. [2022-11-19 07:46:23,293 INFO L899 garLoopResultBuilder]: For program point L347(lines 347 357) no Hoare annotation was computed. [2022-11-19 07:46:23,293 INFO L899 garLoopResultBuilder]: For program point L343(lines 343 360) no Hoare annotation was computed. [2022-11-19 07:46:23,294 INFO L895 garLoopResultBuilder]: At program point L343-1(lines 335 363) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 0)) (.cse5 (not (= ~switchedOnBeforeTS~0 0))) (.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~6#1| ~waterLevel~0)) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (<= 2 ~waterLevel~0) .cse0) .cse1 (and .cse2 .cse0 .cse3 .cse4)) (let ((.cse6 (or .cse0 (= ~waterLevel~0 1)))) (or (and .cse0 .cse3) (and .cse5 .cse2 .cse6 .cse3) .cse1 (and (not .cse2) .cse6 .cse3 .cse4) (not (<= 2 |old(~waterLevel~0)|)))) (let ((.cse7 (let ((.cse8 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse8) .cse0) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse8))))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse5 .cse2 .cse7 .cse3) (and .cse5 .cse7 .cse3 .cse4) .cse1 (= |old(~switchedOnBeforeTS~0)| 0))))) [2022-11-19 07:46:23,294 INFO L895 garLoopResultBuilder]: At program point L1008(line 1008) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 1)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0) (or (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-19 07:46:23,294 INFO L899 garLoopResultBuilder]: For program point L348(lines 348 354) no Hoare annotation was computed. [2022-11-19 07:46:23,295 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 66 92) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (not (= ~switchedOnBeforeTS~0 0))) (.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse5 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))) (or .cse2 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (or .cse3 (= ~pumpRunning~0 0) .cse1) (or .cse4 .cse3 .cse1 .cse5) (or .cse6 .cse3 .cse0) (or .cse4 .cse2 .cse1 .cse5) (or .cse2 .cse6 .cse0))) [2022-11-19 07:46:23,295 INFO L895 garLoopResultBuilder]: At program point L80-1(lines 80 86) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (not .cse1)) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse5 (not (= ~switchedOnBeforeTS~0 0))) (.cse4 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (<= |old(~waterLevel~0)| 1)) .cse0 (and .cse1 .cse2)) (or .cse0 .cse3 .cse4) (or (and .cse5 .cse1 (= ~waterLevel~0 1)) .cse3 .cse4 (and .cse6 (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0) .cse2) (not (<= 2 |old(~waterLevel~0)|))) (let ((.cse7 (let ((.cse8 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse8) .cse3) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse8))))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and .cse6 .cse7 .cse2) (and .cse5 .cse1 .cse7) .cse4 (= |old(~switchedOnBeforeTS~0)| 0)))))) [2022-11-19 07:46:23,295 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 92) no Hoare annotation was computed. [2022-11-19 07:46:23,295 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 1008) no Hoare annotation was computed. [2022-11-19 07:46:23,296 INFO L895 garLoopResultBuilder]: At program point L167(line 167) the Hoare annotation is: (let ((.cse1 (and (not (= ~pumpRunning~0 0)) (let ((.cse2 (< 0 |old(~waterLevel~0)|))) (or (and (not .cse2) (= |old(~waterLevel~0)| ~waterLevel~0)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse0 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0) (or .cse1 .cse0 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse1 .cse0))) [2022-11-19 07:46:23,296 INFO L895 garLoopResultBuilder]: At program point L163(line 163) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse3 (< 0 |old(~waterLevel~0)|)) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0) (or .cse0 (and .cse1 .cse2 .cse3 .cse4) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (not (<= |old(~waterLevel~0)| 1)) (and .cse1 (<= ~waterLevel~0 0) (or (and .cse2 .cse3) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4)))) [2022-11-19 07:46:23,296 INFO L895 garLoopResultBuilder]: At program point L990(lines 990 997) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_main_~tmp~11#1| 1) (= ~waterLevel~0 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2022-11-19 07:46:23,297 INFO L895 garLoopResultBuilder]: At program point L416-2(lines 408 421) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~11#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (<= ~waterLevel~0 2))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2) (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))) [2022-11-19 07:46:23,297 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-19 07:46:23,297 INFO L902 garLoopResultBuilder]: At program point L990-2(lines 990 997) the Hoare annotation is: true [2022-11-19 07:46:23,297 INFO L899 garLoopResultBuilder]: For program point L379(lines 378 425) no Hoare annotation was computed. [2022-11-19 07:46:23,297 INFO L895 garLoopResultBuilder]: At program point L400(line 400) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~11#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (<= ~waterLevel~0 2))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2) (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))) [2022-11-19 07:46:23,298 INFO L902 garLoopResultBuilder]: At program point L429(lines 368 433) the Hoare annotation is: true [2022-11-19 07:46:23,298 INFO L899 garLoopResultBuilder]: For program point L388(lines 388 394) no Hoare annotation was computed. [2022-11-19 07:46:23,298 INFO L899 garLoopResultBuilder]: For program point L388-1(lines 388 394) no Hoare annotation was computed. [2022-11-19 07:46:23,298 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-19 07:46:23,298 INFO L895 garLoopResultBuilder]: At program point L426(lines 377 427) the Hoare annotation is: false [2022-11-19 07:46:23,298 INFO L899 garLoopResultBuilder]: For program point L398(lines 398 404) no Hoare annotation was computed. [2022-11-19 07:46:23,299 INFO L895 garLoopResultBuilder]: At program point L398-1(lines 398 404) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~11#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (<= ~waterLevel~0 2))) (or (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2) (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2) (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))) [2022-11-19 07:46:23,299 INFO L895 garLoopResultBuilder]: At program point L423(lines 378 425) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~11#1| 1)) (.cse1 (<= ~waterLevel~0 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and .cse0 (<= 2 ~waterLevel~0) .cse2 (<= ~waterLevel~0 2)) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2))) [2022-11-19 07:46:23,299 INFO L895 garLoopResultBuilder]: At program point L390(line 390) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_main_~tmp~11#1| 1)) (.cse2 (<= ~waterLevel~0 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 (or (and (<= 2 ~waterLevel~0) .cse1 (<= ~waterLevel~0 2)) (and .cse2 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))) (and (= ~pumpRunning~0 0) .cse0 .cse2 .cse1))) [2022-11-19 07:46:23,299 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 101 125) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,300 INFO L895 garLoopResultBuilder]: At program point L120(line 120) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-19 07:46:23,300 INFO L899 garLoopResultBuilder]: For program point L120-1(lines 101 125) no Hoare annotation was computed. [2022-11-19 07:46:23,300 INFO L895 garLoopResultBuilder]: At program point L191(line 191) the Hoare annotation is: (or (and (= ~pumpRunning~0 0) (<= 2 ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (not (<= ~waterLevel~0 2)) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,300 INFO L895 garLoopResultBuilder]: At program point L191-1(line 191) the Hoare annotation is: (or (and (= ~pumpRunning~0 0) (<= 2 ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (not (<= ~waterLevel~0 2)) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,301 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 101 125) no Hoare annotation was computed. [2022-11-19 07:46:23,301 INFO L895 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse0 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (and (or (<= 2 ~waterLevel~0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse0 .cse1) (or .cse0 (= ~switchedOnBeforeTS~0 0) .cse1))) [2022-11-19 07:46:23,301 INFO L899 garLoopResultBuilder]: For program point L109(lines 109 117) no Hoare annotation was computed. [2022-11-19 07:46:23,301 INFO L895 garLoopResultBuilder]: At program point L105(lines 105 122) the Hoare annotation is: (or (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-19 07:46:23,301 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 815 826) no Hoare annotation was computed. [2022-11-19 07:46:23,302 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 815 826) the Hoare annotation is: (let ((.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (not (= ~pumpRunning~0 0)) .cse1) (or .cse1 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1))) [2022-11-19 07:46:23,302 INFO L902 garLoopResultBuilder]: At program point isMethaneAlarmENTRY(lines 211 221) the Hoare annotation is: true [2022-11-19 07:46:23,302 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 211 221) no Hoare annotation was computed. [2022-11-19 07:46:23,305 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1] [2022-11-19 07:46:23,307 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-19 07:46:23,342 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 19.11 07:46:23 BoogieIcfgContainer [2022-11-19 07:46:23,342 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-19 07:46:23,343 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-19 07:46:23,343 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-19 07:46:23,343 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-19 07:46:23,344 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 19.11 07:45:25" (3/4) ... [2022-11-19 07:46:23,348 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-19 07:46:23,354 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2022-11-19 07:46:23,354 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-19 07:46:23,355 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-19 07:46:23,355 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-19 07:46:23,355 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-19 07:46:23,356 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-19 07:46:23,356 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-19 07:46:23,356 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2022-11-19 07:46:23,356 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-19 07:46:23,356 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2022-11-19 07:46:23,365 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 56 nodes and edges [2022-11-19 07:46:23,366 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 14 nodes and edges [2022-11-19 07:46:23,367 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 6 nodes and edges [2022-11-19 07:46:23,368 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 07:46:23,368 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-19 07:46:23,399 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == aux-isPumpRunning()-aux) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && ((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) [2022-11-19 07:46:23,400 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && pumpRunning == switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) [2022-11-19 07:46:23,401 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(\old(pumpRunning) == 0) || (2 <= waterLevel && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) && (((((\old(waterLevel) == waterLevel && tmp == waterLevel) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && tmp == waterLevel)) || !(\old(waterLevel) <= 2)) || (((!(pumpRunning == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || (((!(switchedOnBeforeTS == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) [2022-11-19 07:46:23,401 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && (!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1))) && (!(\old(waterLevel) <= 2) || !(2 <= \old(waterLevel))) [2022-11-19 07:46:23,401 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) || ((2 <= waterLevel && waterLevel <= 2) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel <= 2) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(switchedOnBeforeTS) == 0)) && ((((!(\old(waterLevel) <= 2) || (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) && pumpRunning == switchedOnBeforeTS)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel <= 2) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || ((2 <= waterLevel && waterLevel <= 2) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel)))) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) [2022-11-19 07:46:23,402 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel <= 2) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) [2022-11-19 07:46:23,402 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (!(waterLevel <= 2) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) [2022-11-19 07:46:23,403 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((pumpRunning == 0 && 2 <= waterLevel) && pumpRunning == switchedOnBeforeTS) || !(waterLevel <= 2)) || !(switchedOnBeforeTS == \old(pumpRunning)) [2022-11-19 07:46:23,439 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/witness.graphml [2022-11-19 07:46:23,439 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-19 07:46:23,440 INFO L158 Benchmark]: Toolchain (without parser) took 59312.91ms. Allocated memory was 130.0MB in the beginning and 511.7MB in the end (delta: 381.7MB). Free memory was 97.5MB in the beginning and 411.5MB in the end (delta: -314.1MB). Peak memory consumption was 68.0MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,440 INFO L158 Benchmark]: CDTParser took 0.33ms. Allocated memory is still 81.8MB. Free memory was 40.0MB in the beginning and 40.0MB in the end (delta: 40.5kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-19 07:46:23,441 INFO L158 Benchmark]: CACSL2BoogieTranslator took 711.70ms. Allocated memory is still 130.0MB. Free memory was 97.5MB in the beginning and 96.5MB in the end (delta: 906.0kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,441 INFO L158 Benchmark]: Boogie Procedure Inliner took 99.99ms. Allocated memory is still 130.0MB. Free memory was 96.5MB in the beginning and 93.9MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,441 INFO L158 Benchmark]: Boogie Preprocessor took 35.58ms. Allocated memory is still 130.0MB. Free memory was 93.9MB in the beginning and 92.4MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,442 INFO L158 Benchmark]: RCFGBuilder took 918.34ms. Allocated memory is still 130.0MB. Free memory was 92.4MB in the beginning and 63.5MB in the end (delta: 28.8MB). Peak memory consumption was 29.4MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,442 INFO L158 Benchmark]: TraceAbstraction took 57440.39ms. Allocated memory was 130.0MB in the beginning and 511.7MB in the end (delta: 381.7MB). Free memory was 63.0MB in the beginning and 417.8MB in the end (delta: -354.8MB). Peak memory consumption was 274.5MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,443 INFO L158 Benchmark]: Witness Printer took 96.39ms. Allocated memory is still 511.7MB. Free memory was 417.8MB in the beginning and 411.5MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-19 07:46:23,445 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.33ms. Allocated memory is still 81.8MB. Free memory was 40.0MB in the beginning and 40.0MB in the end (delta: 40.5kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 711.70ms. Allocated memory is still 130.0MB. Free memory was 97.5MB in the beginning and 96.5MB in the end (delta: 906.0kB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 99.99ms. Allocated memory is still 130.0MB. Free memory was 96.5MB in the beginning and 93.9MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 35.58ms. Allocated memory is still 130.0MB. Free memory was 93.9MB in the beginning and 92.4MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 918.34ms. Allocated memory is still 130.0MB. Free memory was 92.4MB in the beginning and 63.5MB in the end (delta: 28.8MB). Peak memory consumption was 29.4MB. Max. memory is 16.1GB. * TraceAbstraction took 57440.39ms. Allocated memory was 130.0MB in the beginning and 511.7MB in the end (delta: 381.7MB). Free memory was 63.0MB in the beginning and 417.8MB in the end (delta: -354.8MB). Peak memory consumption was 274.5MB. Max. memory is 16.1GB. * Witness Printer took 96.39ms. Allocated memory is still 511.7MB. Free memory was 417.8MB in the beginning and 411.5MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 1008]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 11 procedures, 75 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 57.3s, OverallIterations: 8, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 7.8s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 9.1s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1852 SdHoareTripleChecker+Valid, 4.3s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1833 mSDsluCounter, 2567 SdHoareTripleChecker+Invalid, 3.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1858 mSDsCounter, 1226 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3486 IncrementalHoareTripleChecker+Invalid, 4712 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1226 mSolverCounterUnsat, 709 mSDtfsCounter, 3486 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 740 GetRequests, 516 SyntacticMatches, 24 SemanticMatches, 200 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6141 ImplicationChecksByTransitivity, 21.9s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=778occurred in iteration=7, InterpolantAutomatonStates: 121, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 8 MinimizatonAttempts, 214 StatesRemovedByMinimization, 5 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 44 LocationsWithAnnotation, 1686 PreInvPairs, 2105 NumberOfFragments, 1681 HoareAnnotationTreeSize, 1686 FomulaSimplifications, 4325 FormulaSimplificationTreeSizeReduction, 0.9s HoareSimplificationTime, 44 FomulaSimplificationsInter, 34986 FormulaSimplificationTreeSizeReductionInter, 8.1s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 5.4s InterpolantComputationTime, 589 NumberOfCodeBlocks, 589 NumberOfCodeBlocksAsserted, 10 NumberOfCheckSat, 765 ConstructedInterpolants, 0 QuantifiedInterpolants, 2470 SizeOfPredicates, 29 NumberOfNonLiveVariables, 820 ConjunctsInSsa, 60 ConjunctsInUnsatCore, 12 InterpolantComputations, 6 PerfectInterpolantSequences, 367/404 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 330]: Loop Invariant Derived loop invariant: (((((pumpRunning == aux-isPumpRunning()-aux && \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && ((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == aux-isPumpRunning()-aux) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && ((!(\old(pumpRunning) == 0) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 378]: Loop Invariant Derived loop invariant: ((((tmp == 1 && waterLevel <= 1) && splverifierCounter == 0) && pumpRunning == switchedOnBeforeTS) || (((tmp == 1 && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2)) || (((pumpRunning == 0 && tmp == 1) && waterLevel <= 1) && splverifierCounter == 0) - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 105]: Loop Invariant Derived loop invariant: (!(waterLevel <= 2) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) - InvariantResult [Line: 990]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 1008]: Loop Invariant Derived loop invariant: ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) && (!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1))) && (!(\old(waterLevel) <= 2) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 915]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 905]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 80]: Loop Invariant Derived loop invariant: ((((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && pumpRunning == switchedOnBeforeTS)) && ((!(\old(pumpRunning) == 0) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2))) && ((((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 211]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 990]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && tmp == 1) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS - InvariantResult [Line: 191]: Loop Invariant Derived loop invariant: (((pumpRunning == 0 && 2 <= waterLevel) && pumpRunning == switchedOnBeforeTS) || !(waterLevel <= 2)) || !(switchedOnBeforeTS == \old(pumpRunning)) - InvariantResult [Line: 131]: Loop Invariant Derived loop invariant: (!(waterLevel <= 2) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) - InvariantResult [Line: 377]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 368]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 335]: Loop Invariant Derived loop invariant: ((((!(\old(pumpRunning) == 0) || (2 <= waterLevel && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || (((pumpRunning == 0 && \old(waterLevel) == waterLevel) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) && (((((\old(waterLevel) == waterLevel && tmp == waterLevel) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && tmp == waterLevel)) || !(\old(waterLevel) <= 2)) || (((!(pumpRunning == 0) && (\old(waterLevel) == waterLevel || waterLevel == 1)) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel)))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel)) || (((!(switchedOnBeforeTS == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0) - InvariantResult [Line: 398]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0 && tmp == 1) && splverifierCounter == 0) && waterLevel <= 2) || (((tmp == 1 && 2 <= waterLevel) && splverifierCounter == 0) && waterLevel <= 2)) || (((tmp == 1 && splverifierCounter == 0) && waterLevel <= 2) && pumpRunning == switchedOnBeforeTS) - InvariantResult [Line: 153]: Loop Invariant Derived loop invariant: (((((!(\old(pumpRunning) == 0) || !(\old(waterLevel) <= 2)) || ((2 <= waterLevel && waterLevel <= 2) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || ((!(pumpRunning == 0) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel <= 2) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || \old(switchedOnBeforeTS) == 0)) && ((((!(\old(waterLevel) <= 2) || (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) && pumpRunning == switchedOnBeforeTS)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel <= 2) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel))))) || ((2 <= waterLevel && waterLevel <= 2) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel)))) && ((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) RESULT: Ultimate proved your program to be correct! [2022-11-19 07:46:23,479 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_cb8eace4-e505-4847-89cd-5a07b19a302d/bin/utaipan-I9t0OCRTmS/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE