./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 6b4ec56b Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9 --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-6b4ec56 [2022-11-20 20:00:09,736 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-20 20:00:09,739 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-20 20:00:09,782 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-20 20:00:09,784 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-20 20:00:09,789 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-20 20:00:09,790 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-20 20:00:09,793 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-20 20:00:09,795 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-20 20:00:09,798 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-20 20:00:09,800 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-20 20:00:09,803 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-20 20:00:09,804 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-20 20:00:09,810 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-20 20:00:09,813 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-20 20:00:09,814 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-20 20:00:09,817 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-20 20:00:09,818 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-20 20:00:09,820 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-20 20:00:09,822 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-20 20:00:09,827 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-20 20:00:09,828 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-20 20:00:09,831 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-20 20:00:09,832 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-20 20:00:09,838 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-20 20:00:09,839 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-20 20:00:09,839 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-20 20:00:09,841 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-20 20:00:09,842 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-20 20:00:09,843 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-20 20:00:09,843 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-20 20:00:09,844 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-20 20:00:09,846 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-20 20:00:09,848 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-20 20:00:09,850 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-20 20:00:09,850 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-20 20:00:09,851 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-20 20:00:09,851 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-20 20:00:09,852 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-20 20:00:09,854 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-20 20:00:09,854 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-20 20:00:09,855 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-20 20:00:09,901 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-20 20:00:09,901 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-20 20:00:09,902 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-20 20:00:09,902 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-20 20:00:09,903 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-20 20:00:09,903 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-20 20:00:09,904 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-20 20:00:09,904 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-20 20:00:09,904 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-20 20:00:09,904 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-20 20:00:09,905 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-20 20:00:09,906 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-20 20:00:09,906 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-20 20:00:09,906 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-20 20:00:09,906 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-20 20:00:09,907 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-20 20:00:09,907 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-20 20:00:09,907 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-20 20:00:09,908 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-20 20:00:09,908 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-20 20:00:09,908 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-20 20:00:09,909 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-20 20:00:09,909 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-20 20:00:09,909 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-20 20:00:09,909 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-20 20:00:09,910 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-20 20:00:09,910 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-20 20:00:09,910 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-20 20:00:09,910 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-20 20:00:09,911 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-20 20:00:09,911 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-20 20:00:09,911 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-20 20:00:09,912 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-20 20:00:09,912 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-20 20:00:09,912 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-20 20:00:09,912 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-20 20:00:09,913 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-20 20:00:09,913 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-20 20:00:09,913 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-20 20:00:09,913 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-20 20:00:09,913 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-20 20:00:09,914 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9 Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> debcf50bf3bb3961401c62ca4b7217ea7cc93038f750143121614e56b550164d [2022-11-20 20:00:10,242 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-20 20:00:10,276 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-20 20:00:10,279 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-20 20:00:10,280 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-20 20:00:10,281 INFO L275 PluginConnector]: CDTParser initialized [2022-11-20 20:00:10,282 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/../../sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2022-11-20 20:00:13,321 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-11-20 20:00:13,602 INFO L351 CDTParser]: Found 1 translation units. [2022-11-20 20:00:13,603 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c [2022-11-20 20:00:13,613 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/data/e216438e2/8d590ec9dfee47faa8056f648a426d0f/FLAGb72e08234 [2022-11-20 20:00:13,627 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/data/e216438e2/8d590ec9dfee47faa8056f648a426d0f [2022-11-20 20:00:13,629 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-20 20:00:13,631 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-20 20:00:13,632 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-20 20:00:13,633 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-20 20:00:13,636 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-20 20:00:13,637 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.11 08:00:13" (1/1) ... [2022-11-20 20:00:13,638 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@5fd86aa and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:13, skipping insertion in model container [2022-11-20 20:00:13,638 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 20.11 08:00:13" (1/1) ... [2022-11-20 20:00:13,646 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-20 20:00:13,678 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-20 20:00:13,879 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2022-11-20 20:00:13,939 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-20 20:00:13,953 INFO L203 MainTranslator]: Completed pre-run [2022-11-20 20:00:14,025 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/sv-benchmarks/c/product-lines/minepump_spec4_product58.cil.c[11718,11731] [2022-11-20 20:00:14,070 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-20 20:00:14,093 INFO L208 MainTranslator]: Completed translation [2022-11-20 20:00:14,094 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14 WrapperNode [2022-11-20 20:00:14,094 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-20 20:00:14,095 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-20 20:00:14,095 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-20 20:00:14,095 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-20 20:00:14,100 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,114 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,144 INFO L138 Inliner]: procedures = 57, calls = 101, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 227 [2022-11-20 20:00:14,144 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-20 20:00:14,145 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-20 20:00:14,145 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-20 20:00:14,145 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-20 20:00:14,155 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,155 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,158 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,158 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,163 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,167 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,169 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,170 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,173 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-20 20:00:14,173 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-20 20:00:14,174 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-20 20:00:14,174 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-20 20:00:14,175 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (1/1) ... [2022-11-20 20:00:14,181 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-20 20:00:14,193 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 [2022-11-20 20:00:14,205 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-20 20:00:14,228 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-20 20:00:14,264 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-20 20:00:14,264 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-20 20:00:14,264 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-20 20:00:14,264 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-20 20:00:14,265 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-20 20:00:14,265 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-20 20:00:14,265 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-20 20:00:14,265 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-20 20:00:14,265 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-20 20:00:14,265 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-20 20:00:14,266 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-20 20:00:14,266 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-20 20:00:14,266 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-20 20:00:14,266 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-20 20:00:14,266 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-20 20:00:14,267 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-20 20:00:14,386 INFO L235 CfgBuilder]: Building ICFG [2022-11-20 20:00:14,388 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-20 20:00:14,674 INFO L276 CfgBuilder]: Performing block encoding [2022-11-20 20:00:14,884 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-20 20:00:14,885 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-20 20:00:14,887 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.11 08:00:14 BoogieIcfgContainer [2022-11-20 20:00:14,887 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-20 20:00:14,890 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-20 20:00:14,890 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-20 20:00:14,894 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-20 20:00:14,894 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 20.11 08:00:13" (1/3) ... [2022-11-20 20:00:14,895 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@2e0a5723 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.11 08:00:14, skipping insertion in model container [2022-11-20 20:00:14,895 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 20.11 08:00:14" (2/3) ... [2022-11-20 20:00:14,895 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@2e0a5723 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 20.11 08:00:14, skipping insertion in model container [2022-11-20 20:00:14,895 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.11 08:00:14" (3/3) ... [2022-11-20 20:00:14,897 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product58.cil.c [2022-11-20 20:00:14,917 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-20 20:00:14,917 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-20 20:00:14,981 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-20 20:00:14,988 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@7e2c1539, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-20 20:00:14,988 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-20 20:00:14,996 INFO L276 IsEmpty]: Start isEmpty. Operand has 51 states, 33 states have (on average 1.4545454545454546) internal successors, (48), 41 states have internal predecessors, (48), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) [2022-11-20 20:00:15,008 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 13 [2022-11-20 20:00:15,008 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:15,009 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:15,010 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:15,017 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:15,017 INFO L85 PathProgramCache]: Analyzing trace with hash -1497506587, now seen corresponding path program 1 times [2022-11-20 20:00:15,029 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:15,030 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [617736778] [2022-11-20 20:00:15,031 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:15,031 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:15,141 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:15,200 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:15,201 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:15,201 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [617736778] [2022-11-20 20:00:15,202 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [617736778] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:15,202 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:15,203 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-20 20:00:15,204 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [892242916] [2022-11-20 20:00:15,205 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:15,210 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-20 20:00:15,210 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:15,240 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-20 20:00:15,241 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-20 20:00:15,244 INFO L87 Difference]: Start difference. First operand has 51 states, 33 states have (on average 1.4545454545454546) internal successors, (48), 41 states have internal predecessors, (48), 10 states have call successors, (10), 6 states have call predecessors, (10), 6 states have return successors, (10), 8 states have call predecessors, (10), 10 states have call successors, (10) Second operand has 2 states, 2 states have (on average 5.0) internal successors, (10), 2 states have internal predecessors, (10), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,329 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:15,329 INFO L93 Difference]: Finished difference Result 100 states and 137 transitions. [2022-11-20 20:00:15,335 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-20 20:00:15,336 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 5.0) internal successors, (10), 2 states have internal predecessors, (10), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 12 [2022-11-20 20:00:15,344 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:15,353 INFO L225 Difference]: With dead ends: 100 [2022-11-20 20:00:15,358 INFO L226 Difference]: Without dead ends: 46 [2022-11-20 20:00:15,362 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-20 20:00:15,368 INFO L413 NwaCegarLoop]: 48 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 48 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:15,372 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 48 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-20 20:00:15,391 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 46 states. [2022-11-20 20:00:15,419 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 46 to 46. [2022-11-20 20:00:15,421 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 46 states, 30 states have (on average 1.3333333333333333) internal successors, (40), 37 states have internal predecessors, (40), 10 states have call successors, (10), 6 states have call predecessors, (10), 5 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-20 20:00:15,425 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 46 states to 46 states and 59 transitions. [2022-11-20 20:00:15,427 INFO L78 Accepts]: Start accepts. Automaton has 46 states and 59 transitions. Word has length 12 [2022-11-20 20:00:15,428 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:15,429 INFO L495 AbstractCegarLoop]: Abstraction has 46 states and 59 transitions. [2022-11-20 20:00:15,430 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 5.0) internal successors, (10), 2 states have internal predecessors, (10), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,430 INFO L276 IsEmpty]: Start isEmpty. Operand 46 states and 59 transitions. [2022-11-20 20:00:15,432 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 14 [2022-11-20 20:00:15,433 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:15,433 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:15,433 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-20 20:00:15,434 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:15,435 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:15,435 INFO L85 PathProgramCache]: Analyzing trace with hash -903472037, now seen corresponding path program 1 times [2022-11-20 20:00:15,435 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:15,437 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [898912821] [2022-11-20 20:00:15,438 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:15,438 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:15,479 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:15,562 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:15,562 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:15,563 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [898912821] [2022-11-20 20:00:15,563 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [898912821] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:15,563 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:15,563 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-20 20:00:15,564 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1098908389] [2022-11-20 20:00:15,564 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:15,565 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-20 20:00:15,565 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:15,566 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-20 20:00:15,566 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-20 20:00:15,567 INFO L87 Difference]: Start difference. First operand 46 states and 59 transitions. Second operand has 3 states, 3 states have (on average 3.6666666666666665) internal successors, (11), 3 states have internal predecessors, (11), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,609 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:15,610 INFO L93 Difference]: Finished difference Result 69 states and 89 transitions. [2022-11-20 20:00:15,610 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-20 20:00:15,611 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 3.6666666666666665) internal successors, (11), 3 states have internal predecessors, (11), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 13 [2022-11-20 20:00:15,611 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:15,612 INFO L225 Difference]: With dead ends: 69 [2022-11-20 20:00:15,612 INFO L226 Difference]: Without dead ends: 38 [2022-11-20 20:00:15,613 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-20 20:00:15,619 INFO L413 NwaCegarLoop]: 34 mSDtfsCounter, 7 mSDsluCounter, 25 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 59 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:15,621 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 59 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-20 20:00:15,624 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 38 states. [2022-11-20 20:00:15,636 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 38 to 38. [2022-11-20 20:00:15,639 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 38 states, 25 states have (on average 1.36) internal successors, (34), 32 states have internal predecessors, (34), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-20 20:00:15,641 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 38 states to 38 states and 48 transitions. [2022-11-20 20:00:15,643 INFO L78 Accepts]: Start accepts. Automaton has 38 states and 48 transitions. Word has length 13 [2022-11-20 20:00:15,644 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:15,644 INFO L495 AbstractCegarLoop]: Abstraction has 38 states and 48 transitions. [2022-11-20 20:00:15,644 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 3.6666666666666665) internal successors, (11), 3 states have internal predecessors, (11), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,645 INFO L276 IsEmpty]: Start isEmpty. Operand 38 states and 48 transitions. [2022-11-20 20:00:15,646 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 16 [2022-11-20 20:00:15,646 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:15,647 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:15,647 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-20 20:00:15,647 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:15,650 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:15,650 INFO L85 PathProgramCache]: Analyzing trace with hash -1673097531, now seen corresponding path program 1 times [2022-11-20 20:00:15,650 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:15,651 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [530949378] [2022-11-20 20:00:15,651 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:15,652 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:15,698 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:15,864 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:15,864 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:15,864 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [530949378] [2022-11-20 20:00:15,865 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [530949378] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:15,865 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:15,865 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-20 20:00:15,865 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1505284383] [2022-11-20 20:00:15,866 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:15,866 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-20 20:00:15,866 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:15,867 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-20 20:00:15,867 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-20 20:00:15,867 INFO L87 Difference]: Start difference. First operand 38 states and 48 transitions. Second operand has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,900 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:15,901 INFO L93 Difference]: Finished difference Result 74 states and 95 transitions. [2022-11-20 20:00:15,901 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-20 20:00:15,902 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 15 [2022-11-20 20:00:15,902 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:15,903 INFO L225 Difference]: With dead ends: 74 [2022-11-20 20:00:15,903 INFO L226 Difference]: Without dead ends: 38 [2022-11-20 20:00:15,904 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-20 20:00:15,905 INFO L413 NwaCegarLoop]: 32 mSDtfsCounter, 37 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 15 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 37 SdHoareTripleChecker+Valid, 32 SdHoareTripleChecker+Invalid, 15 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 15 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:15,905 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [37 Valid, 32 Invalid, 15 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 15 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-20 20:00:15,906 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 38 states. [2022-11-20 20:00:15,912 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 38 to 38. [2022-11-20 20:00:15,913 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 38 states, 25 states have (on average 1.32) internal successors, (33), 32 states have internal predecessors, (33), 7 states have call successors, (7), 5 states have call predecessors, (7), 5 states have return successors, (7), 5 states have call predecessors, (7), 7 states have call successors, (7) [2022-11-20 20:00:15,913 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 38 states to 38 states and 47 transitions. [2022-11-20 20:00:15,914 INFO L78 Accepts]: Start accepts. Automaton has 38 states and 47 transitions. Word has length 15 [2022-11-20 20:00:15,914 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:15,914 INFO L495 AbstractCegarLoop]: Abstraction has 38 states and 47 transitions. [2022-11-20 20:00:15,914 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:15,915 INFO L276 IsEmpty]: Start isEmpty. Operand 38 states and 47 transitions. [2022-11-20 20:00:15,915 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 19 [2022-11-20 20:00:15,916 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:15,916 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:15,916 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-20 20:00:15,916 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:15,917 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:15,917 INFO L85 PathProgramCache]: Analyzing trace with hash -1105785491, now seen corresponding path program 1 times [2022-11-20 20:00:15,918 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:15,918 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [530129573] [2022-11-20 20:00:15,918 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:15,918 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:15,943 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:16,329 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:16,329 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:16,330 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [530129573] [2022-11-20 20:00:16,330 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [530129573] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:16,330 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:16,330 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2022-11-20 20:00:16,331 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2018263622] [2022-11-20 20:00:16,331 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:16,332 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-20 20:00:16,333 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:16,352 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-20 20:00:16,352 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=8, Invalid=12, Unknown=0, NotChecked=0, Total=20 [2022-11-20 20:00:16,352 INFO L87 Difference]: Start difference. First operand 38 states and 47 transitions. Second operand has 5 states, 5 states have (on average 3.4) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:16,686 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:16,686 INFO L93 Difference]: Finished difference Result 170 states and 218 transitions. [2022-11-20 20:00:16,686 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-20 20:00:16,686 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 18 [2022-11-20 20:00:16,687 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:16,688 INFO L225 Difference]: With dead ends: 170 [2022-11-20 20:00:16,689 INFO L226 Difference]: Without dead ends: 134 [2022-11-20 20:00:16,689 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=12, Invalid=18, Unknown=0, NotChecked=0, Total=30 [2022-11-20 20:00:16,690 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 102 mSDsluCounter, 79 mSDsCounter, 0 mSdLazyCounter, 124 mSolverCounterSat, 27 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 104 SdHoareTripleChecker+Valid, 136 SdHoareTripleChecker+Invalid, 151 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 27 IncrementalHoareTripleChecker+Valid, 124 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:16,691 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [104 Valid, 136 Invalid, 151 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [27 Valid, 124 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-20 20:00:16,692 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 134 states. [2022-11-20 20:00:16,718 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 134 to 111. [2022-11-20 20:00:16,719 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 111 states, 77 states have (on average 1.2987012987012987) internal successors, (100), 88 states have internal predecessors, (100), 16 states have call successors, (16), 14 states have call predecessors, (16), 17 states have return successors, (24), 16 states have call predecessors, (24), 16 states have call successors, (24) [2022-11-20 20:00:16,720 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 111 states to 111 states and 140 transitions. [2022-11-20 20:00:16,721 INFO L78 Accepts]: Start accepts. Automaton has 111 states and 140 transitions. Word has length 18 [2022-11-20 20:00:16,721 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:16,721 INFO L495 AbstractCegarLoop]: Abstraction has 111 states and 140 transitions. [2022-11-20 20:00:16,721 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 4 states have internal predecessors, (17), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:16,722 INFO L276 IsEmpty]: Start isEmpty. Operand 111 states and 140 transitions. [2022-11-20 20:00:16,722 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2022-11-20 20:00:16,723 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:16,723 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:16,723 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-20 20:00:16,723 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:16,724 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:16,724 INFO L85 PathProgramCache]: Analyzing trace with hash 1419149477, now seen corresponding path program 1 times [2022-11-20 20:00:16,724 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:16,724 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1681244022] [2022-11-20 20:00:16,724 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:16,725 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:16,737 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:16,828 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:16,828 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:16,829 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1681244022] [2022-11-20 20:00:16,829 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1681244022] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:16,829 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:16,829 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2022-11-20 20:00:16,829 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1510279128] [2022-11-20 20:00:16,830 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:16,830 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-20 20:00:16,830 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:16,830 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-20 20:00:16,831 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=8, Invalid=12, Unknown=0, NotChecked=0, Total=20 [2022-11-20 20:00:16,831 INFO L87 Difference]: Start difference. First operand 111 states and 140 transitions. Second operand has 5 states, 5 states have (on average 4.0) internal successors, (20), 5 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-20 20:00:16,975 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:16,975 INFO L93 Difference]: Finished difference Result 319 states and 429 transitions. [2022-11-20 20:00:16,976 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-20 20:00:16,976 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 4.0) internal successors, (20), 5 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2022-11-20 20:00:16,976 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:16,978 INFO L225 Difference]: With dead ends: 319 [2022-11-20 20:00:16,978 INFO L226 Difference]: Without dead ends: 210 [2022-11-20 20:00:16,979 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=13, Invalid=17, Unknown=0, NotChecked=0, Total=30 [2022-11-20 20:00:16,980 INFO L413 NwaCegarLoop]: 47 mSDtfsCounter, 66 mSDsluCounter, 121 mSDsCounter, 0 mSdLazyCounter, 86 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 66 SdHoareTripleChecker+Valid, 168 SdHoareTripleChecker+Invalid, 96 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 86 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:16,981 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [66 Valid, 168 Invalid, 96 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 86 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-20 20:00:16,982 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 210 states. [2022-11-20 20:00:17,017 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 210 to 180. [2022-11-20 20:00:17,018 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 180 states, 127 states have (on average 1.2519685039370079) internal successors, (159), 139 states have internal predecessors, (159), 23 states have call successors, (23), 22 states have call predecessors, (23), 29 states have return successors, (45), 27 states have call predecessors, (45), 23 states have call successors, (45) [2022-11-20 20:00:17,020 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 180 states to 180 states and 227 transitions. [2022-11-20 20:00:17,020 INFO L78 Accepts]: Start accepts. Automaton has 180 states and 227 transitions. Word has length 23 [2022-11-20 20:00:17,020 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:17,020 INFO L495 AbstractCegarLoop]: Abstraction has 180 states and 227 transitions. [2022-11-20 20:00:17,021 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 4.0) internal successors, (20), 5 states have internal predecessors, (20), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2022-11-20 20:00:17,021 INFO L276 IsEmpty]: Start isEmpty. Operand 180 states and 227 transitions. [2022-11-20 20:00:17,022 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2022-11-20 20:00:17,022 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:17,022 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:17,022 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-20 20:00:17,023 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:17,023 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:17,023 INFO L85 PathProgramCache]: Analyzing trace with hash 355769214, now seen corresponding path program 1 times [2022-11-20 20:00:17,023 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:17,024 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [792503118] [2022-11-20 20:00:17,024 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:17,024 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:17,036 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:17,209 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:17,209 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:17,209 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [792503118] [2022-11-20 20:00:17,209 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [792503118] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:17,209 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:17,210 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-20 20:00:17,210 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1159931742] [2022-11-20 20:00:17,210 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:17,210 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-20 20:00:17,211 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:17,211 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-20 20:00:17,211 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=40, Unknown=0, NotChecked=0, Total=56 [2022-11-20 20:00:17,212 INFO L87 Difference]: Start difference. First operand 180 states and 227 transitions. Second operand has 8 states, 7 states have (on average 3.0) internal successors, (21), 7 states have internal predecessors, (21), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-20 20:00:17,655 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:17,655 INFO L93 Difference]: Finished difference Result 521 states and 693 transitions. [2022-11-20 20:00:17,655 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2022-11-20 20:00:17,656 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.0) internal successors, (21), 7 states have internal predecessors, (21), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) Word has length 26 [2022-11-20 20:00:17,656 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:17,659 INFO L225 Difference]: With dead ends: 521 [2022-11-20 20:00:17,659 INFO L226 Difference]: Without dead ends: 380 [2022-11-20 20:00:17,660 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=40, Invalid=92, Unknown=0, NotChecked=0, Total=132 [2022-11-20 20:00:17,661 INFO L413 NwaCegarLoop]: 43 mSDtfsCounter, 155 mSDsluCounter, 118 mSDsCounter, 0 mSdLazyCounter, 256 mSolverCounterSat, 81 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 158 SdHoareTripleChecker+Valid, 161 SdHoareTripleChecker+Invalid, 337 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 81 IncrementalHoareTripleChecker+Valid, 256 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:17,661 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [158 Valid, 161 Invalid, 337 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [81 Valid, 256 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-20 20:00:17,662 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 380 states. [2022-11-20 20:00:17,735 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 380 to 366. [2022-11-20 20:00:17,737 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 366 states, 258 states have (on average 1.248062015503876) internal successors, (322), 282 states have internal predecessors, (322), 48 states have call successors, (48), 45 states have call predecessors, (48), 59 states have return successors, (112), 55 states have call predecessors, (112), 48 states have call successors, (112) [2022-11-20 20:00:17,740 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 366 states to 366 states and 482 transitions. [2022-11-20 20:00:17,740 INFO L78 Accepts]: Start accepts. Automaton has 366 states and 482 transitions. Word has length 26 [2022-11-20 20:00:17,741 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:17,741 INFO L495 AbstractCegarLoop]: Abstraction has 366 states and 482 transitions. [2022-11-20 20:00:17,741 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.0) internal successors, (21), 7 states have internal predecessors, (21), 2 states have call successors, (3), 3 states have call predecessors, (3), 2 states have return successors, (2), 1 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-20 20:00:17,742 INFO L276 IsEmpty]: Start isEmpty. Operand 366 states and 482 transitions. [2022-11-20 20:00:17,743 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2022-11-20 20:00:17,743 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:17,743 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:17,743 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-20 20:00:17,744 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:17,744 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:17,744 INFO L85 PathProgramCache]: Analyzing trace with hash -874326473, now seen corresponding path program 1 times [2022-11-20 20:00:17,745 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:17,745 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1975650444] [2022-11-20 20:00:17,745 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:17,745 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:17,757 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:17,935 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:17,935 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:17,936 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1975650444] [2022-11-20 20:00:17,936 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1975650444] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:17,936 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:17,936 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-11-20 20:00:17,936 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1087659983] [2022-11-20 20:00:17,936 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:17,937 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-20 20:00:17,937 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:17,938 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-20 20:00:17,938 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=22, Invalid=50, Unknown=0, NotChecked=0, Total=72 [2022-11-20 20:00:17,938 INFO L87 Difference]: Start difference. First operand 366 states and 482 transitions. Second operand has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 4 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-20 20:00:18,509 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:18,509 INFO L93 Difference]: Finished difference Result 945 states and 1316 transitions. [2022-11-20 20:00:18,510 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-20 20:00:18,510 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 4 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 3 states have call successors, (3) Word has length 29 [2022-11-20 20:00:18,510 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:18,517 INFO L225 Difference]: With dead ends: 945 [2022-11-20 20:00:18,517 INFO L226 Difference]: Without dead ends: 681 [2022-11-20 20:00:18,520 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 14 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 34 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=71, Invalid=169, Unknown=0, NotChecked=0, Total=240 [2022-11-20 20:00:18,523 INFO L413 NwaCegarLoop]: 45 mSDtfsCounter, 132 mSDsluCounter, 151 mSDsCounter, 0 mSdLazyCounter, 331 mSolverCounterSat, 71 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 136 SdHoareTripleChecker+Valid, 196 SdHoareTripleChecker+Invalid, 402 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 71 IncrementalHoareTripleChecker+Valid, 331 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:18,523 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [136 Valid, 196 Invalid, 402 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [71 Valid, 331 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2022-11-20 20:00:18,524 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 681 states. [2022-11-20 20:00:18,633 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 681 to 558. [2022-11-20 20:00:18,635 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 558 states, 395 states have (on average 1.220253164556962) internal successors, (482), 425 states have internal predecessors, (482), 69 states have call successors, (69), 65 states have call predecessors, (69), 93 states have return successors, (169), 88 states have call predecessors, (169), 69 states have call successors, (169) [2022-11-20 20:00:18,638 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 558 states to 558 states and 720 transitions. [2022-11-20 20:00:18,638 INFO L78 Accepts]: Start accepts. Automaton has 558 states and 720 transitions. Word has length 29 [2022-11-20 20:00:18,638 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:18,639 INFO L495 AbstractCegarLoop]: Abstraction has 558 states and 720 transitions. [2022-11-20 20:00:18,639 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 2.75) internal successors, (22), 8 states have internal predecessors, (22), 4 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 3 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-20 20:00:18,639 INFO L276 IsEmpty]: Start isEmpty. Operand 558 states and 720 transitions. [2022-11-20 20:00:18,641 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2022-11-20 20:00:18,642 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:18,642 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:18,642 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-20 20:00:18,642 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:18,642 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:18,643 INFO L85 PathProgramCache]: Analyzing trace with hash -904725257, now seen corresponding path program 1 times [2022-11-20 20:00:18,643 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:18,643 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1470404460] [2022-11-20 20:00:18,643 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:18,643 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:18,656 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:18,894 INFO L134 CoverageAnalysis]: Checked inductivity of 13 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:18,895 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:18,895 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1470404460] [2022-11-20 20:00:18,895 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1470404460] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:18,895 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-20 20:00:18,896 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2022-11-20 20:00:18,896 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [805482407] [2022-11-20 20:00:18,896 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:18,896 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2022-11-20 20:00:18,896 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:18,897 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2022-11-20 20:00:18,897 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=46, Unknown=0, NotChecked=0, Total=72 [2022-11-20 20:00:18,897 INFO L87 Difference]: Start difference. First operand 558 states and 720 transitions. Second operand has 9 states, 8 states have (on average 4.375) internal successors, (35), 8 states have internal predecessors, (35), 3 states have call successors, (4), 3 states have call predecessors, (4), 3 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-20 20:00:19,206 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:19,207 INFO L93 Difference]: Finished difference Result 1073 states and 1407 transitions. [2022-11-20 20:00:19,208 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2022-11-20 20:00:19,208 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 4.375) internal successors, (35), 8 states have internal predecessors, (35), 3 states have call successors, (4), 3 states have call predecessors, (4), 3 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 42 [2022-11-20 20:00:19,209 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:19,212 INFO L225 Difference]: With dead ends: 1073 [2022-11-20 20:00:19,212 INFO L226 Difference]: Without dead ends: 577 [2022-11-20 20:00:19,214 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 14 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=39, Invalid=71, Unknown=0, NotChecked=0, Total=110 [2022-11-20 20:00:19,215 INFO L413 NwaCegarLoop]: 36 mSDtfsCounter, 159 mSDsluCounter, 53 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 70 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 165 SdHoareTripleChecker+Valid, 89 SdHoareTripleChecker+Invalid, 198 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 70 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:19,215 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [165 Valid, 89 Invalid, 198 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [70 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-20 20:00:19,217 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 577 states. [2022-11-20 20:00:19,319 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 577 to 517. [2022-11-20 20:00:19,321 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 517 states, 368 states have (on average 1.2173913043478262) internal successors, (448), 394 states have internal predecessors, (448), 62 states have call successors, (62), 58 states have call predecessors, (62), 86 states have return successors, (154), 81 states have call predecessors, (154), 62 states have call successors, (154) [2022-11-20 20:00:19,325 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 517 states to 517 states and 664 transitions. [2022-11-20 20:00:19,326 INFO L78 Accepts]: Start accepts. Automaton has 517 states and 664 transitions. Word has length 42 [2022-11-20 20:00:19,326 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:19,326 INFO L495 AbstractCegarLoop]: Abstraction has 517 states and 664 transitions. [2022-11-20 20:00:19,327 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 4.375) internal successors, (35), 8 states have internal predecessors, (35), 3 states have call successors, (4), 3 states have call predecessors, (4), 3 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-20 20:00:19,327 INFO L276 IsEmpty]: Start isEmpty. Operand 517 states and 664 transitions. [2022-11-20 20:00:19,330 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2022-11-20 20:00:19,331 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:19,331 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:19,331 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2022-11-20 20:00:19,332 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:19,332 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:19,332 INFO L85 PathProgramCache]: Analyzing trace with hash 317890339, now seen corresponding path program 2 times [2022-11-20 20:00:19,333 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:19,333 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2012516113] [2022-11-20 20:00:19,333 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:19,333 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:19,365 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:19,735 INFO L134 CoverageAnalysis]: Checked inductivity of 13 backedges. 0 proven. 9 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-20 20:00:19,736 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:19,736 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2012516113] [2022-11-20 20:00:19,736 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2012516113] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-20 20:00:19,736 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1762897407] [2022-11-20 20:00:19,736 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST2 [2022-11-20 20:00:19,736 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:19,737 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 [2022-11-20 20:00:19,743 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-20 20:00:19,747 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-20 20:00:19,836 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST2 issued 1 check-sat command(s) [2022-11-20 20:00:19,836 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2022-11-20 20:00:19,839 INFO L263 TraceCheckSpWp]: Trace formula consists of 170 conjuncts, 9 conjunts are in the unsatisfiable core [2022-11-20 20:00:19,844 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-20 20:00:19,907 INFO L134 CoverageAnalysis]: Checked inductivity of 13 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-20 20:00:19,907 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-20 20:00:19,907 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1762897407] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:19,908 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-20 20:00:19,908 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [11] total 13 [2022-11-20 20:00:19,908 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1700600411] [2022-11-20 20:00:19,908 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:19,909 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2022-11-20 20:00:19,909 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:19,909 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2022-11-20 20:00:19,909 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=33, Invalid=123, Unknown=0, NotChecked=0, Total=156 [2022-11-20 20:00:19,910 INFO L87 Difference]: Start difference. First operand 517 states and 664 transitions. Second operand has 4 states, 4 states have (on average 7.0) internal successors, (28), 4 states have internal predecessors, (28), 1 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-20 20:00:20,047 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:20,047 INFO L93 Difference]: Finished difference Result 954 states and 1273 transitions. [2022-11-20 20:00:20,047 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2022-11-20 20:00:20,048 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 7.0) internal successors, (28), 4 states have internal predecessors, (28), 1 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) Word has length 42 [2022-11-20 20:00:20,048 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:20,051 INFO L225 Difference]: With dead ends: 954 [2022-11-20 20:00:20,051 INFO L226 Difference]: Without dead ends: 485 [2022-11-20 20:00:20,053 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 57 GetRequests, 45 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 36 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=38, Invalid=144, Unknown=0, NotChecked=0, Total=182 [2022-11-20 20:00:20,053 INFO L413 NwaCegarLoop]: 38 mSDtfsCounter, 38 mSDsluCounter, 67 mSDsCounter, 0 mSdLazyCounter, 45 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 38 SdHoareTripleChecker+Valid, 105 SdHoareTripleChecker+Invalid, 51 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 45 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:20,054 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [38 Valid, 105 Invalid, 51 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 45 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-20 20:00:20,055 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 485 states. [2022-11-20 20:00:20,115 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 485 to 437. [2022-11-20 20:00:20,116 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 437 states, 308 states have (on average 1.1915584415584415) internal successors, (367), 332 states have internal predecessors, (367), 57 states have call successors, (57), 55 states have call predecessors, (57), 71 states have return successors, (115), 67 states have call predecessors, (115), 57 states have call successors, (115) [2022-11-20 20:00:20,118 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 437 states to 437 states and 539 transitions. [2022-11-20 20:00:20,119 INFO L78 Accepts]: Start accepts. Automaton has 437 states and 539 transitions. Word has length 42 [2022-11-20 20:00:20,119 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:20,119 INFO L495 AbstractCegarLoop]: Abstraction has 437 states and 539 transitions. [2022-11-20 20:00:20,120 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 7.0) internal successors, (28), 4 states have internal predecessors, (28), 1 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (3), 1 states have call predecessors, (3), 1 states have call successors, (3) [2022-11-20 20:00:20,120 INFO L276 IsEmpty]: Start isEmpty. Operand 437 states and 539 transitions. [2022-11-20 20:00:20,121 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2022-11-20 20:00:20,121 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:20,121 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:20,128 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2022-11-20 20:00:20,327 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2022-11-20 20:00:20,327 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:20,328 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:20,328 INFO L85 PathProgramCache]: Analyzing trace with hash -940303233, now seen corresponding path program 1 times [2022-11-20 20:00:20,328 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:20,328 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1076335922] [2022-11-20 20:00:20,328 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:20,328 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:20,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:20,656 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 3 proven. 16 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-20 20:00:20,656 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:20,656 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1076335922] [2022-11-20 20:00:20,656 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1076335922] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-20 20:00:20,656 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1175299302] [2022-11-20 20:00:20,656 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:20,656 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:20,657 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 [2022-11-20 20:00:20,658 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-20 20:00:20,683 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-20 20:00:20,757 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:20,759 INFO L263 TraceCheckSpWp]: Trace formula consists of 272 conjuncts, 29 conjunts are in the unsatisfiable core [2022-11-20 20:00:20,763 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-20 20:00:21,064 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 5 proven. 11 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2022-11-20 20:00:21,064 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-20 20:00:21,423 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 0 proven. 11 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2022-11-20 20:00:21,424 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1175299302] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-20 20:00:21,424 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1152666983] [2022-11-20 20:00:21,444 INFO L159 IcfgInterpreter]: Started Sifa with 32 locations of interest [2022-11-20 20:00:21,444 INFO L166 IcfgInterpreter]: Building call graph [2022-11-20 20:00:21,450 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-20 20:00:21,456 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-20 20:00:21,457 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-20 20:00:27,334 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 139 for LOIs [2022-11-20 20:00:27,357 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 52 for LOIs [2022-11-20 20:00:27,546 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 24 for LOIs [2022-11-20 20:00:27,689 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 25 for LOIs [2022-11-20 20:00:27,691 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-20 20:00:32,695 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '11161#(and (= |timeShift_getWaterLevel_~retValue_acc~4#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~4#1| ~waterLevel~0) (<= ~pumpRunning~0 1) (= ~methaneLevelCritical~0 0) (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1| 0)) (= ~head~0.offset 0) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~11#1|) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~11#1|) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| |timeShift_getWaterLevel_#res#1|) (= |old(~waterLevel~0)| ~waterLevel~0) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1|) (<= 0 ~pumpRunning~0) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-20 20:00:32,695 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-20 20:00:32,695 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-20 20:00:32,695 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 9, 9] total 25 [2022-11-20 20:00:32,696 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [141173859] [2022-11-20 20:00:32,696 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-20 20:00:32,696 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 25 states [2022-11-20 20:00:32,696 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:32,697 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 25 interpolants. [2022-11-20 20:00:32,698 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=271, Invalid=1985, Unknown=0, NotChecked=0, Total=2256 [2022-11-20 20:00:32,698 INFO L87 Difference]: Start difference. First operand 437 states and 539 transitions. Second operand has 25 states, 22 states have (on average 4.0) internal successors, (88), 24 states have internal predecessors, (88), 12 states have call successors, (16), 8 states have call predecessors, (16), 9 states have return successors, (14), 12 states have call predecessors, (14), 11 states have call successors, (14) [2022-11-20 20:00:38,396 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:38,396 INFO L93 Difference]: Finished difference Result 1867 states and 2669 transitions. [2022-11-20 20:00:38,397 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 91 states. [2022-11-20 20:00:38,397 INFO L78 Accepts]: Start accepts. Automaton has has 25 states, 22 states have (on average 4.0) internal successors, (88), 24 states have internal predecessors, (88), 12 states have call successors, (16), 8 states have call predecessors, (16), 9 states have return successors, (14), 12 states have call predecessors, (14), 11 states have call successors, (14) Word has length 50 [2022-11-20 20:00:38,397 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:38,405 INFO L225 Difference]: With dead ends: 1867 [2022-11-20 20:00:38,406 INFO L226 Difference]: Without dead ends: 1462 [2022-11-20 20:00:38,413 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 260 GetRequests, 130 SyntacticMatches, 4 SemanticMatches, 126 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5980 ImplicationChecksByTransitivity, 7.9s TimeCoverageRelationStatistics Valid=2152, Invalid=14104, Unknown=0, NotChecked=0, Total=16256 [2022-11-20 20:00:38,414 INFO L413 NwaCegarLoop]: 105 mSDtfsCounter, 1093 mSDsluCounter, 972 mSDsCounter, 0 mSdLazyCounter, 2920 mSolverCounterSat, 1049 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 2.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1100 SdHoareTripleChecker+Valid, 1077 SdHoareTripleChecker+Invalid, 3969 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1049 IncrementalHoareTripleChecker+Valid, 2920 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.7s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:38,414 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1100 Valid, 1077 Invalid, 3969 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1049 Valid, 2920 Invalid, 0 Unknown, 0 Unchecked, 2.7s Time] [2022-11-20 20:00:38,416 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1462 states. [2022-11-20 20:00:38,579 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1462 to 894. [2022-11-20 20:00:38,581 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 894 states, 631 states have (on average 1.196513470681458) internal successors, (755), 696 states have internal predecessors, (755), 126 states have call successors, (126), 106 states have call predecessors, (126), 136 states have return successors, (257), 139 states have call predecessors, (257), 126 states have call successors, (257) [2022-11-20 20:00:38,586 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 894 states to 894 states and 1138 transitions. [2022-11-20 20:00:38,587 INFO L78 Accepts]: Start accepts. Automaton has 894 states and 1138 transitions. Word has length 50 [2022-11-20 20:00:38,587 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:38,587 INFO L495 AbstractCegarLoop]: Abstraction has 894 states and 1138 transitions. [2022-11-20 20:00:38,588 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 25 states, 22 states have (on average 4.0) internal successors, (88), 24 states have internal predecessors, (88), 12 states have call successors, (16), 8 states have call predecessors, (16), 9 states have return successors, (14), 12 states have call predecessors, (14), 11 states have call successors, (14) [2022-11-20 20:00:38,588 INFO L276 IsEmpty]: Start isEmpty. Operand 894 states and 1138 transitions. [2022-11-20 20:00:38,589 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 75 [2022-11-20 20:00:38,589 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:38,590 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:38,596 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-20 20:00:38,795 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:38,796 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:38,796 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:38,797 INFO L85 PathProgramCache]: Analyzing trace with hash 1352416078, now seen corresponding path program 1 times [2022-11-20 20:00:38,797 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:38,797 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [561813677] [2022-11-20 20:00:38,797 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:38,797 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:38,821 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:39,402 INFO L134 CoverageAnalysis]: Checked inductivity of 58 backedges. 28 proven. 10 refuted. 0 times theorem prover too weak. 20 trivial. 0 not checked. [2022-11-20 20:00:39,402 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:39,403 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [561813677] [2022-11-20 20:00:39,403 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [561813677] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-20 20:00:39,403 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1172998148] [2022-11-20 20:00:39,403 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:39,403 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:39,403 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 [2022-11-20 20:00:39,404 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-20 20:00:39,432 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-20 20:00:39,509 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:39,512 INFO L263 TraceCheckSpWp]: Trace formula consists of 349 conjuncts, 18 conjunts are in the unsatisfiable core [2022-11-20 20:00:39,515 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-20 20:00:39,616 INFO L134 CoverageAnalysis]: Checked inductivity of 58 backedges. 48 proven. 0 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-20 20:00:39,616 INFO L324 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2022-11-20 20:00:39,616 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1172998148] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-20 20:00:39,617 INFO L184 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2022-11-20 20:00:39,617 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [12] total 15 [2022-11-20 20:00:39,617 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2114140783] [2022-11-20 20:00:39,617 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-20 20:00:39,618 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2022-11-20 20:00:39,618 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:39,619 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2022-11-20 20:00:39,619 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=38, Invalid=172, Unknown=0, NotChecked=0, Total=210 [2022-11-20 20:00:39,620 INFO L87 Difference]: Start difference. First operand 894 states and 1138 transitions. Second operand has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-11-20 20:00:39,925 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:39,925 INFO L93 Difference]: Finished difference Result 1589 states and 2024 transitions. [2022-11-20 20:00:39,926 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2022-11-20 20:00:39,926 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) Word has length 74 [2022-11-20 20:00:39,927 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:39,931 INFO L225 Difference]: With dead ends: 1589 [2022-11-20 20:00:39,931 INFO L226 Difference]: Without dead ends: 666 [2022-11-20 20:00:39,936 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 98 GetRequests, 81 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 60 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=58, Invalid=284, Unknown=0, NotChecked=0, Total=342 [2022-11-20 20:00:39,937 INFO L413 NwaCegarLoop]: 60 mSDtfsCounter, 54 mSDsluCounter, 127 mSDsCounter, 0 mSdLazyCounter, 121 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 54 SdHoareTripleChecker+Valid, 187 SdHoareTripleChecker+Invalid, 128 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 121 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:39,937 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [54 Valid, 187 Invalid, 128 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 121 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-20 20:00:39,938 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 666 states. [2022-11-20 20:00:40,026 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 666 to 575. [2022-11-20 20:00:40,027 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 575 states, 410 states have (on average 1.1853658536585365) internal successors, (486), 448 states have internal predecessors, (486), 74 states have call successors, (74), 73 states have call predecessors, (74), 90 states have return successors, (119), 82 states have call predecessors, (119), 74 states have call successors, (119) [2022-11-20 20:00:40,030 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 575 states to 575 states and 679 transitions. [2022-11-20 20:00:40,030 INFO L78 Accepts]: Start accepts. Automaton has 575 states and 679 transitions. Word has length 74 [2022-11-20 20:00:40,031 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:40,031 INFO L495 AbstractCegarLoop]: Abstraction has 575 states and 679 transitions. [2022-11-20 20:00:40,031 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 3 states have call successors, (8), 3 states have call predecessors, (8), 3 states have return successors, (8), 3 states have call predecessors, (8), 3 states have call successors, (8) [2022-11-20 20:00:40,031 INFO L276 IsEmpty]: Start isEmpty. Operand 575 states and 679 transitions. [2022-11-20 20:00:40,033 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 88 [2022-11-20 20:00:40,033 INFO L187 NwaCegarLoop]: Found error trace [2022-11-20 20:00:40,033 INFO L195 NwaCegarLoop]: trace histogram [4, 4, 4, 4, 4, 4, 4, 4, 4, 4, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:40,049 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-20 20:00:40,249 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:40,249 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-20 20:00:40,250 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-20 20:00:40,250 INFO L85 PathProgramCache]: Analyzing trace with hash 1539431954, now seen corresponding path program 1 times [2022-11-20 20:00:40,250 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-20 20:00:40,250 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [887903482] [2022-11-20 20:00:40,250 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:40,251 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-20 20:00:40,280 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:41,053 INFO L134 CoverageAnalysis]: Checked inductivity of 99 backedges. 45 proven. 41 refuted. 0 times theorem prover too weak. 13 trivial. 0 not checked. [2022-11-20 20:00:41,054 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-20 20:00:41,054 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [887903482] [2022-11-20 20:00:41,054 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [887903482] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-20 20:00:41,054 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [30207513] [2022-11-20 20:00:41,054 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-20 20:00:41,054 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-20 20:00:41,054 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 [2022-11-20 20:00:41,056 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-20 20:00:41,059 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2022-11-20 20:00:41,169 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-20 20:00:41,172 INFO L263 TraceCheckSpWp]: Trace formula consists of 420 conjuncts, 43 conjunts are in the unsatisfiable core [2022-11-20 20:00:41,175 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-20 20:00:41,676 INFO L134 CoverageAnalysis]: Checked inductivity of 99 backedges. 51 proven. 36 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2022-11-20 20:00:41,677 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-20 20:00:42,493 INFO L134 CoverageAnalysis]: Checked inductivity of 99 backedges. 62 proven. 21 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2022-11-20 20:00:42,493 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [30207513] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-20 20:00:42,493 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [887729028] [2022-11-20 20:00:42,496 INFO L159 IcfgInterpreter]: Started Sifa with 34 locations of interest [2022-11-20 20:00:42,496 INFO L166 IcfgInterpreter]: Building call graph [2022-11-20 20:00:42,497 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-20 20:00:42,497 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-20 20:00:42,497 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-20 20:00:44,217 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 23 for LOIs [2022-11-20 20:00:44,220 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 26 for LOIs [2022-11-20 20:00:44,382 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 59 for LOIs [2022-11-20 20:00:44,606 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 33 for LOIs [2022-11-20 20:00:44,608 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-20 20:00:48,605 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '20102#(and (<= |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1| 2147483647) (= |timeShift_getWaterLevel_~retValue_acc~4#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~4#1| ~waterLevel~0) (<= 0 (+ |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1| 2147483648)) (= ~methaneLevelCritical~0 0) (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1| 0)) (= ~head~0.offset 0) (= |timeShift_isPumpRunning_#res#1| |timeShift_isPumpRunning_~retValue_acc~11#1|) (= 1 ~systemActive~0) (= ~pumpRunning~0 |timeShift_isPumpRunning_~retValue_acc~11#1|) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_isPumpRunning_#res#1| |timeShift___utac_acc__Specification4_spec__1_~tmp___0~0#1|) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-20 20:00:48,605 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-20 20:00:48,606 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-20 20:00:48,606 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [17, 14, 14] total 35 [2022-11-20 20:00:48,606 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2093121191] [2022-11-20 20:00:48,606 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-20 20:00:48,607 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 35 states [2022-11-20 20:00:48,607 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-20 20:00:48,608 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 35 interpolants. [2022-11-20 20:00:48,609 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=444, Invalid=2978, Unknown=0, NotChecked=0, Total=3422 [2022-11-20 20:00:48,609 INFO L87 Difference]: Start difference. First operand 575 states and 679 transitions. Second operand has 35 states, 33 states have (on average 3.9696969696969697) internal successors, (131), 33 states have internal predecessors, (131), 12 states have call successors, (18), 8 states have call predecessors, (18), 13 states have return successors, (20), 12 states have call predecessors, (20), 12 states have call successors, (20) [2022-11-20 20:00:49,622 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-20 20:00:49,623 INFO L93 Difference]: Finished difference Result 649 states and 768 transitions. [2022-11-20 20:00:49,623 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 18 states. [2022-11-20 20:00:49,624 INFO L78 Accepts]: Start accepts. Automaton has has 35 states, 33 states have (on average 3.9696969696969697) internal successors, (131), 33 states have internal predecessors, (131), 12 states have call successors, (18), 8 states have call predecessors, (18), 13 states have return successors, (20), 12 states have call predecessors, (20), 12 states have call successors, (20) Word has length 87 [2022-11-20 20:00:49,624 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-20 20:00:49,624 INFO L225 Difference]: With dead ends: 649 [2022-11-20 20:00:49,624 INFO L226 Difference]: Without dead ends: 0 [2022-11-20 20:00:49,627 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 296 GetRequests, 214 SyntacticMatches, 10 SemanticMatches, 72 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2481 ImplicationChecksByTransitivity, 5.1s TimeCoverageRelationStatistics Valid=782, Invalid=4620, Unknown=0, NotChecked=0, Total=5402 [2022-11-20 20:00:49,628 INFO L413 NwaCegarLoop]: 28 mSDtfsCounter, 486 mSDsluCounter, 196 mSDsCounter, 0 mSdLazyCounter, 500 mSolverCounterSat, 310 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 487 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 810 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 310 IncrementalHoareTripleChecker+Valid, 500 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-20 20:00:49,628 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [487 Valid, 224 Invalid, 810 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [310 Valid, 500 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-20 20:00:49,629 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-20 20:00:49,629 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-20 20:00:49,630 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-20 20:00:49,630 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-20 20:00:49,630 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 87 [2022-11-20 20:00:49,630 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-20 20:00:49,630 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-20 20:00:49,631 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 35 states, 33 states have (on average 3.9696969696969697) internal successors, (131), 33 states have internal predecessors, (131), 12 states have call successors, (18), 8 states have call predecessors, (18), 13 states have return successors, (20), 12 states have call predecessors, (20), 12 states have call successors, (20) [2022-11-20 20:00:49,631 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-20 20:00:49,631 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-20 20:00:49,634 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-20 20:00:49,644 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2022-11-20 20:00:49,844 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2022-11-20 20:00:49,846 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-20 20:00:54,442 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2022-11-20 20:00:54,443 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2022-11-20 20:00:54,443 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 487 498) the Hoare annotation is: true [2022-11-20 20:00:54,443 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 487 498) no Hoare annotation was computed. [2022-11-20 20:00:54,444 INFO L895 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0) (or .cse0 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,444 INFO L895 garLoopResultBuilder]: At program point L449(line 449) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0) (or .cse0 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,446 INFO L895 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse1 (= ~waterLevel~0 1))))) [2022-11-20 20:00:54,446 INFO L895 garLoopResultBuilder]: At program point L784-1(lines 765 789) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= ~waterLevel~0 1))) (and (or (and .cse0 .cse1 (<= 1 |timeShift_processEnvironment_~tmp~6#1|) .cse2) .cse3 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 (and .cse1 .cse2)))) [2022-11-20 20:00:54,446 INFO L895 garLoopResultBuilder]: At program point L718-1(lines 718 724) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= ~waterLevel~0 1))) (and (or (and .cse0 .cse1 (<= 1 |timeShift_processEnvironment_~tmp~6#1|) .cse2) .cse3 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse3 (and .cse1 .cse2)))) [2022-11-20 20:00:54,446 INFO L899 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2022-11-20 20:00:54,447 INFO L895 garLoopResultBuilder]: At program point L773(lines 773 781) the Hoare annotation is: (let ((.cse4 (not (= |old(~waterLevel~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0)))) (let ((.cse1 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (and (or .cse4 .cse2) (or (and .cse3 (or (not (< 0 (+ |old(~waterLevel~0)| 1))) (not (<= |old(~waterLevel~0)| 0)))) .cse2)))) (and (or (< |old(~waterLevel~0)| 2) .cse0 .cse1) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (= ~waterLevel~0 1)) .cse2 .cse1 (not (<= 2 |old(~waterLevel~0)|))) (or .cse3 .cse4 .cse0)))) [2022-11-20 20:00:54,447 INFO L895 garLoopResultBuilder]: At program point L769(lines 769 786) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0 (and .cse1 (= ~waterLevel~0 1))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (or (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (and (not .cse1) (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))))) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,447 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 707 730) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) .cse0 (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1))) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,447 INFO L899 garLoopResultBuilder]: For program point L431(lines 431 437) no Hoare annotation was computed. [2022-11-20 20:00:54,448 INFO L895 garLoopResultBuilder]: At program point L427(lines 427 440) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse3 (= ~waterLevel~0 1)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 1) .cse2 .cse3)) (or (and .cse0 .cse2 (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 0)) .cse3) .cse1 (and (= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|) (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,448 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2022-11-20 20:00:54,448 INFO L895 garLoopResultBuilder]: At program point L427-1(lines 419 443) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse3 (= ~waterLevel~0 1)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 1) .cse2 .cse3)) (or (and .cse0 .cse2 (<= 1 |timeShift_processEnvironment_~tmp~6#1|) (not (= |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1| 0)) .cse3) .cse1 (and (= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~3#1|) (= |old(~waterLevel~0)| ~waterLevel~0)) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-20 20:00:54,448 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 449) no Hoare annotation was computed. [2022-11-20 20:00:54,449 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 566 595) no Hoare annotation was computed. [2022-11-20 20:00:54,449 INFO L902 garLoopResultBuilder]: At program point L576-2(lines 576 590) the Hoare annotation is: true [2022-11-20 20:00:54,449 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 566 595) the Hoare annotation is: true [2022-11-20 20:00:54,449 INFO L902 garLoopResultBuilder]: At program point L572(line 572) the Hoare annotation is: true [2022-11-20 20:00:54,449 INFO L899 garLoopResultBuilder]: For program point L572-1(line 572) no Hoare annotation was computed. [2022-11-20 20:00:54,449 INFO L902 garLoopResultBuilder]: At program point L591(lines 566 595) the Hoare annotation is: true [2022-11-20 20:00:54,450 INFO L899 garLoopResultBuilder]: For program point L587(line 587) no Hoare annotation was computed. [2022-11-20 20:00:54,450 INFO L899 garLoopResultBuilder]: For program point L580(lines 580 584) no Hoare annotation was computed. [2022-11-20 20:00:54,450 INFO L902 garLoopResultBuilder]: At program point L580-1(lines 580 584) the Hoare annotation is: true [2022-11-20 20:00:54,450 INFO L895 garLoopResultBuilder]: At program point L985(lines 936 986) the Hoare annotation is: false [2022-11-20 20:00:54,450 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-20 20:00:54,450 INFO L899 garLoopResultBuilder]: For program point L957(lines 957 963) no Hoare annotation was computed. [2022-11-20 20:00:54,451 INFO L895 garLoopResultBuilder]: At program point L957-1(lines 957 963) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,451 INFO L895 garLoopResultBuilder]: At program point L982(lines 937 984) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,451 INFO L895 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1 (<= ~waterLevel~0 2)) (and (= ~pumpRunning~0 0) .cse0 .cse1 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,451 INFO L895 garLoopResultBuilder]: At program point L652(lines 652 659) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= |ULTIMATE.start_main_~tmp~4#1| 1) (= ~waterLevel~0 1)) [2022-11-20 20:00:54,451 INFO L902 garLoopResultBuilder]: At program point L652-2(lines 652 659) the Hoare annotation is: true [2022-11-20 20:00:54,452 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-20 20:00:54,452 INFO L895 garLoopResultBuilder]: At program point L975-2(lines 967 980) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,452 INFO L899 garLoopResultBuilder]: For program point L938(lines 937 984) no Hoare annotation was computed. [2022-11-20 20:00:54,452 INFO L895 garLoopResultBuilder]: At program point L959(line 959) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,452 INFO L902 garLoopResultBuilder]: At program point L988(lines 927 992) the Hoare annotation is: true [2022-11-20 20:00:54,452 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2022-11-20 20:00:54,453 INFO L899 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2022-11-20 20:00:54,453 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 739 763) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (and (not (= |old(~pumpRunning~0)| 0)) (or (not (<= ~waterLevel~0 0)) (not (< 0 (+ ~waterLevel~0 1))))))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 (not (= 2 ~waterLevel~0)) .cse2))) [2022-11-20 20:00:54,453 INFO L895 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (not (= 2 ~waterLevel~0))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2022-11-20 20:00:54,453 INFO L899 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2022-11-20 20:00:54,453 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2022-11-20 20:00:54,454 INFO L895 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (not (= 2 ~waterLevel~0))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))))) [2022-11-20 20:00:54,454 INFO L895 garLoopResultBuilder]: At program point L747(lines 747 755) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 (not (= 2 ~waterLevel~0)) (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 1))) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 (and .cse2 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))))) [2022-11-20 20:00:54,454 INFO L895 garLoopResultBuilder]: At program point L743(lines 743 760) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (and (not (= |old(~pumpRunning~0)| 0)) (or (not (<= ~waterLevel~0 0)) (not (< 0 (+ ~waterLevel~0 1))))))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse0 .cse1 (not (= 2 ~waterLevel~0)) .cse2))) [2022-11-20 20:00:54,454 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 475 486) no Hoare annotation was computed. [2022-11-20 20:00:54,454 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 475 486) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or (not (= ~pumpRunning~0 0)) (not (= |old(~waterLevel~0)| 1)) .cse0 (= ~waterLevel~0 1)))) [2022-11-20 20:00:54,458 INFO L444 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-20 20:00:54,460 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-20 20:00:54,488 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 20.11 08:00:54 BoogieIcfgContainer [2022-11-20 20:00:54,503 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-20 20:00:54,504 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-20 20:00:54,504 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-20 20:00:54,504 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-20 20:00:54,505 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 20.11 08:00:14" (3/4) ... [2022-11-20 20:00:54,508 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-20 20:00:54,518 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-20 20:00:54,518 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-20 20:00:54,518 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-20 20:00:54,518 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-20 20:00:54,519 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-20 20:00:54,519 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-20 20:00:54,525 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 52 nodes and edges [2022-11-20 20:00:54,529 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 14 nodes and edges [2022-11-20 20:00:54,529 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2022-11-20 20:00:54,530 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-20 20:00:54,530 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-20 20:00:54,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-20 20:00:54,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) [2022-11-20 20:00:54,565 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-20 20:00:54,565 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) [2022-11-20 20:00:54,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(waterLevel == 1) || pumpRunning == 0) || !(1 == systemActive)) || (!(\old(pumpRunning) == 0) && (!(waterLevel <= 0) || !(0 < waterLevel + 1)))) && (((pumpRunning == 0 || !(1 == systemActive)) || !(2 == waterLevel)) || (!(\old(pumpRunning) == 0) && (!(waterLevel <= 0) || !(0 < waterLevel + 1)))) [2022-11-20 20:00:54,568 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp == 1 && pumpRunning == 0) && waterLevel == 1)) && ((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && !(tmp == 0)) && waterLevel == 1) || !(1 == systemActive)) || (2 == tmp && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-20 20:00:54,568 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp == 1 && pumpRunning == 0) && waterLevel == 1)) && ((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && !(tmp == 0)) && waterLevel == 1) || !(1 == systemActive)) || (2 == tmp && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-20 20:00:54,569 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) && ((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-20 20:00:54,569 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2 || ((!(\old(waterLevel) == 1) || !(1 == systemActive)) && ((!(\old(pumpRunning) == 0) && (!(0 < \old(waterLevel) + 1) || !(\old(waterLevel) <= 0))) || !(1 == systemActive)))) || !(\old(waterLevel) <= 2)) && (((((pumpRunning == \old(pumpRunning) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((!(\old(waterLevel) == 1) || !(1 == systemActive)) && ((!(\old(pumpRunning) == 0) && (!(0 < \old(waterLevel) + 1) || !(\old(waterLevel) <= 0))) || !(1 == systemActive)))) [2022-11-20 20:00:54,569 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || (pumpRunning == 0 && tmp == 1)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && tmp == 0)) [2022-11-20 20:00:54,619 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/witness.graphml [2022-11-20 20:00:54,619 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-20 20:00:54,620 INFO L158 Benchmark]: Toolchain (without parser) took 40989.34ms. Allocated memory was 155.2MB in the beginning and 524.3MB in the end (delta: 369.1MB). Free memory was 122.2MB in the beginning and 200.6MB in the end (delta: -78.4MB). Peak memory consumption was 291.2MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,620 INFO L158 Benchmark]: CDTParser took 0.27ms. Allocated memory is still 155.2MB. Free memory was 99.5MB in the beginning and 99.3MB in the end (delta: 159.5kB). There was no memory consumed. Max. memory is 16.1GB. [2022-11-20 20:00:54,621 INFO L158 Benchmark]: CACSL2BoogieTranslator took 461.99ms. Allocated memory is still 155.2MB. Free memory was 122.2MB in the beginning and 103.3MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,621 INFO L158 Benchmark]: Boogie Procedure Inliner took 49.51ms. Allocated memory is still 155.2MB. Free memory was 103.3MB in the beginning and 100.7MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,622 INFO L158 Benchmark]: Boogie Preprocessor took 27.90ms. Allocated memory is still 155.2MB. Free memory was 100.7MB in the beginning and 99.1MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,622 INFO L158 Benchmark]: RCFGBuilder took 714.17ms. Allocated memory is still 155.2MB. Free memory was 99.1MB in the beginning and 72.5MB in the end (delta: 26.6MB). Peak memory consumption was 25.2MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,623 INFO L158 Benchmark]: TraceAbstraction took 39613.41ms. Allocated memory was 155.2MB in the beginning and 524.3MB in the end (delta: 369.1MB). Free memory was 71.8MB in the beginning and 205.8MB in the end (delta: -134.0MB). Peak memory consumption was 268.4MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,624 INFO L158 Benchmark]: Witness Printer took 115.55ms. Allocated memory is still 524.3MB. Free memory was 205.8MB in the beginning and 200.6MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2022-11-20 20:00:54,626 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.27ms. Allocated memory is still 155.2MB. Free memory was 99.5MB in the beginning and 99.3MB in the end (delta: 159.5kB). There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 461.99ms. Allocated memory is still 155.2MB. Free memory was 122.2MB in the beginning and 103.3MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 49.51ms. Allocated memory is still 155.2MB. Free memory was 103.3MB in the beginning and 100.7MB in the end (delta: 2.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 27.90ms. Allocated memory is still 155.2MB. Free memory was 100.7MB in the beginning and 99.1MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 714.17ms. Allocated memory is still 155.2MB. Free memory was 99.1MB in the beginning and 72.5MB in the end (delta: 26.6MB). Peak memory consumption was 25.2MB. Max. memory is 16.1GB. * TraceAbstraction took 39613.41ms. Allocated memory was 155.2MB in the beginning and 524.3MB in the end (delta: 369.1MB). Free memory was 71.8MB in the beginning and 205.8MB in the end (delta: -134.0MB). Peak memory consumption was 268.4MB. Max. memory is 16.1GB. * Witness Printer took 115.55ms. Allocated memory is still 524.3MB. Free memory was 205.8MB in the beginning and 200.6MB in the end (delta: 5.2MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 449]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 51 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 39.5s, OverallIterations: 12, TraceHistogramMax: 4, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.0s, AutomataDifference: 9.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 4.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2355 SdHoareTripleChecker+Valid, 4.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2329 mSDsluCounter, 2482 SdHoareTripleChecker+Invalid, 3.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1909 mSDsCounter, 1632 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4568 IncrementalHoareTripleChecker+Invalid, 6200 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1632 mSolverCounterUnsat, 573 mSDtfsCounter, 4568 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 781 GetRequests, 497 SyntacticMatches, 14 SemanticMatches, 270 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8620 ImplicationChecksByTransitivity, 13.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=894occurred in iteration=10, InterpolantAutomatonStates: 178, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.8s AutomataMinimizationTime, 12 MinimizatonAttempts, 957 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 33 LocationsWithAnnotation, 1956 PreInvPairs, 2019 NumberOfFragments, 920 HoareAnnotationTreeSize, 1956 FomulaSimplifications, 18426 FormulaSimplificationTreeSizeReduction, 1.2s HoareSimplificationTime, 33 FomulaSimplificationsInter, 31241 FormulaSimplificationTreeSizeReductionInter, 3.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 5.6s InterpolantComputationTime, 684 NumberOfCodeBlocks, 660 NumberOfCodeBlocksAsserted, 16 NumberOfCheckSat, 803 ConstructedInterpolants, 0 QuantifiedInterpolants, 3015 SizeOfPredicates, 37 NumberOfNonLiveVariables, 1211 ConjunctsInSsa, 99 ConjunctsInUnsatCore, 18 InterpolantComputations, 10 PerfectInterpolantSequences, 354/509 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp == 1 && pumpRunning == 0) && waterLevel == 1)) && ((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && !(tmp == 0)) && waterLevel == 1) || !(1 == systemActive)) || (2 == tmp && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 773]: Loop Invariant Derived loop invariant: (((\old(waterLevel) < 2 || ((!(\old(waterLevel) == 1) || !(1 == systemActive)) && ((!(\old(pumpRunning) == 0) && (!(0 < \old(waterLevel) + 1) || !(\old(waterLevel) <= 0))) || !(1 == systemActive)))) || !(\old(waterLevel) <= 2)) && (((((pumpRunning == \old(pumpRunning) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || ((!(\old(waterLevel) == 1) || !(1 == systemActive)) && ((!(\old(pumpRunning) == 0) && (!(0 < \old(waterLevel) + 1) || !(\old(waterLevel) <= 0))) || !(1 == systemActive)))) - InvariantResult [Line: 718]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) - InvariantResult [Line: 937]: Loop Invariant Derived loop invariant: ((2 == waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 927]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 707]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 743]: Loop Invariant Derived loop invariant: (((!(waterLevel == 1) || pumpRunning == 0) || !(1 == systemActive)) || (!(\old(pumpRunning) == 0) && (!(waterLevel <= 0) || !(0 < waterLevel + 1)))) && (((pumpRunning == 0 || !(1 == systemActive)) || !(2 == waterLevel)) || (!(\old(pumpRunning) == 0) && (!(waterLevel <= 0) || !(0 < waterLevel + 1)))) - InvariantResult [Line: 957]: Loop Invariant Derived loop invariant: ((2 == waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((pumpRunning == 0 && 1 == systemActive) && splverifierCounter == 0) && waterLevel == 1) - InvariantResult [Line: 576]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 652]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 765]: Loop Invariant Derived loop invariant: (((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && waterLevel == 1) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) && (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) - InvariantResult [Line: 769]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || (pumpRunning == 0 && waterLevel == 1)) && (((!(1 == systemActive) || (pumpRunning == \old(pumpRunning) && ((pumpRunning == 0 && \old(waterLevel) == waterLevel) || (!(pumpRunning == 0) && \old(waterLevel) == waterLevel + 1)))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 449]: Loop Invariant Derived loop invariant: ((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) && ((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 652]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && tmp == 1) && waterLevel == 1 - InvariantResult [Line: 747]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(2 == waterLevel)) || (pumpRunning == 0 && tmp == 1)) && (((!(waterLevel == 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || (pumpRunning == 0 && tmp == 0)) - InvariantResult [Line: 936]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 566]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 427]: Loop Invariant Derived loop invariant: (((!(\old(pumpRunning) == 0) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || ((tmp == 1 && pumpRunning == 0) && waterLevel == 1)) && ((((((((!(\old(pumpRunning) == 0) && pumpRunning == 0) && 1 <= tmp) && !(tmp == 0)) && waterLevel == 1) || !(1 == systemActive)) || (2 == tmp && \old(waterLevel) == waterLevel)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) RESULT: Ultimate proved your program to be correct! [2022-11-20 20:00:54,685 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_b08047d1-aa20-4dd7-8279-3f13c42d531a/bin/utaipan-6cKwYrpEi9/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE