./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 4e7fbc69 Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash aba011a2dee79947f4cca7910fc4583b21e1f3cb9acd1affa050aa7677352666 --- Real Ultimate output --- [0.001s][warning][os,container] Duplicate cpuset controllers detected. Picking /sys/fs/cgroup/cpuset, skipping /sys/fs/cgroup/cpuset. This is Ultimate 0.2.2-dev-4e7fbc6 [2022-11-23 14:21:07,338 INFO L177 SettingsManager]: Resetting all preferences to default values... [2022-11-23 14:21:07,340 INFO L181 SettingsManager]: Resetting UltimateCore preferences to default values [2022-11-23 14:21:07,360 INFO L184 SettingsManager]: Ultimate Commandline Interface provides no preferences, ignoring... [2022-11-23 14:21:07,360 INFO L181 SettingsManager]: Resetting Boogie Preprocessor preferences to default values [2022-11-23 14:21:07,361 INFO L181 SettingsManager]: Resetting Boogie Procedure Inliner preferences to default values [2022-11-23 14:21:07,363 INFO L181 SettingsManager]: Resetting Abstract Interpretation preferences to default values [2022-11-23 14:21:07,365 INFO L181 SettingsManager]: Resetting LassoRanker preferences to default values [2022-11-23 14:21:07,366 INFO L181 SettingsManager]: Resetting Reaching Definitions preferences to default values [2022-11-23 14:21:07,367 INFO L181 SettingsManager]: Resetting SyntaxChecker preferences to default values [2022-11-23 14:21:07,369 INFO L181 SettingsManager]: Resetting Sifa preferences to default values [2022-11-23 14:21:07,370 INFO L184 SettingsManager]: Büchi Program Product provides no preferences, ignoring... [2022-11-23 14:21:07,371 INFO L181 SettingsManager]: Resetting LTL2Aut preferences to default values [2022-11-23 14:21:07,372 INFO L181 SettingsManager]: Resetting PEA to Boogie preferences to default values [2022-11-23 14:21:07,373 INFO L181 SettingsManager]: Resetting BlockEncodingV2 preferences to default values [2022-11-23 14:21:07,374 INFO L181 SettingsManager]: Resetting ChcToBoogie preferences to default values [2022-11-23 14:21:07,375 INFO L181 SettingsManager]: Resetting AutomataScriptInterpreter preferences to default values [2022-11-23 14:21:07,376 INFO L181 SettingsManager]: Resetting BuchiAutomizer preferences to default values [2022-11-23 14:21:07,378 INFO L181 SettingsManager]: Resetting CACSL2BoogieTranslator preferences to default values [2022-11-23 14:21:07,380 INFO L181 SettingsManager]: Resetting CodeCheck preferences to default values [2022-11-23 14:21:07,381 INFO L181 SettingsManager]: Resetting InvariantSynthesis preferences to default values [2022-11-23 14:21:07,383 INFO L181 SettingsManager]: Resetting RCFGBuilder preferences to default values [2022-11-23 14:21:07,384 INFO L181 SettingsManager]: Resetting Referee preferences to default values [2022-11-23 14:21:07,385 INFO L181 SettingsManager]: Resetting TraceAbstraction preferences to default values [2022-11-23 14:21:07,389 INFO L184 SettingsManager]: TraceAbstractionConcurrent provides no preferences, ignoring... [2022-11-23 14:21:07,389 INFO L184 SettingsManager]: TraceAbstractionWithAFAs provides no preferences, ignoring... [2022-11-23 14:21:07,390 INFO L181 SettingsManager]: Resetting TreeAutomizer preferences to default values [2022-11-23 14:21:07,391 INFO L181 SettingsManager]: Resetting IcfgToChc preferences to default values [2022-11-23 14:21:07,391 INFO L181 SettingsManager]: Resetting IcfgTransformer preferences to default values [2022-11-23 14:21:07,393 INFO L184 SettingsManager]: ReqToTest provides no preferences, ignoring... [2022-11-23 14:21:07,393 INFO L181 SettingsManager]: Resetting Boogie Printer preferences to default values [2022-11-23 14:21:07,394 INFO L181 SettingsManager]: Resetting ChcSmtPrinter preferences to default values [2022-11-23 14:21:07,395 INFO L181 SettingsManager]: Resetting ReqPrinter preferences to default values [2022-11-23 14:21:07,396 INFO L181 SettingsManager]: Resetting Witness Printer preferences to default values [2022-11-23 14:21:07,397 INFO L184 SettingsManager]: Boogie PL CUP Parser provides no preferences, ignoring... [2022-11-23 14:21:07,397 INFO L181 SettingsManager]: Resetting CDTParser preferences to default values [2022-11-23 14:21:07,398 INFO L184 SettingsManager]: AutomataScriptParser provides no preferences, ignoring... [2022-11-23 14:21:07,398 INFO L184 SettingsManager]: ReqParser provides no preferences, ignoring... [2022-11-23 14:21:07,399 INFO L181 SettingsManager]: Resetting SmtParser preferences to default values [2022-11-23 14:21:07,400 INFO L181 SettingsManager]: Resetting Witness Parser preferences to default values [2022-11-23 14:21:07,401 INFO L188 SettingsManager]: Finished resetting all preferences to default values... [2022-11-23 14:21:07,402 INFO L101 SettingsManager]: Beginning loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/config/svcomp-Reach-32bit-Taipan_Default.epf [2022-11-23 14:21:07,440 INFO L113 SettingsManager]: Loading preferences was successful [2022-11-23 14:21:07,440 INFO L115 SettingsManager]: Preferences different from defaults after loading the file: [2022-11-23 14:21:07,441 INFO L136 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2022-11-23 14:21:07,441 INFO L138 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2022-11-23 14:21:07,442 INFO L136 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2022-11-23 14:21:07,442 INFO L138 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2022-11-23 14:21:07,442 INFO L138 SettingsManager]: * User list type=DISABLED [2022-11-23 14:21:07,442 INFO L136 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2022-11-23 14:21:07,442 INFO L138 SettingsManager]: * Explicit value domain=true [2022-11-23 14:21:07,443 INFO L138 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2022-11-23 14:21:07,447 INFO L138 SettingsManager]: * Octagon Domain=false [2022-11-23 14:21:07,447 INFO L138 SettingsManager]: * Abstract domain=CompoundDomain [2022-11-23 14:21:07,447 INFO L138 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2022-11-23 14:21:07,447 INFO L138 SettingsManager]: * Use the RCFG-of-the-future interface=true [2022-11-23 14:21:07,448 INFO L138 SettingsManager]: * Interval Domain=false [2022-11-23 14:21:07,448 INFO L136 SettingsManager]: Preferences of Sifa differ from their defaults: [2022-11-23 14:21:07,448 INFO L138 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2022-11-23 14:21:07,448 INFO L138 SettingsManager]: * Simplification Technique=POLY_PAC [2022-11-23 14:21:07,449 INFO L136 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2022-11-23 14:21:07,449 INFO L138 SettingsManager]: * sizeof long=4 [2022-11-23 14:21:07,449 INFO L138 SettingsManager]: * Overapproximate operations on floating types=true [2022-11-23 14:21:07,449 INFO L138 SettingsManager]: * sizeof POINTER=4 [2022-11-23 14:21:07,450 INFO L138 SettingsManager]: * Check division by zero=IGNORE [2022-11-23 14:21:07,450 INFO L138 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2022-11-23 14:21:07,450 INFO L138 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2022-11-23 14:21:07,450 INFO L138 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2022-11-23 14:21:07,451 INFO L138 SettingsManager]: * sizeof long double=12 [2022-11-23 14:21:07,451 INFO L138 SettingsManager]: * Check if freed pointer was valid=false [2022-11-23 14:21:07,451 INFO L138 SettingsManager]: * Use constant arrays=true [2022-11-23 14:21:07,452 INFO L138 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2022-11-23 14:21:07,452 INFO L136 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2022-11-23 14:21:07,452 INFO L138 SettingsManager]: * SMT solver=External_DefaultMode [2022-11-23 14:21:07,452 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-23 14:21:07,453 INFO L136 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2022-11-23 14:21:07,453 INFO L138 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES [2022-11-23 14:21:07,453 INFO L138 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2022-11-23 14:21:07,453 INFO L138 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2022-11-23 14:21:07,453 INFO L138 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2022-11-23 14:21:07,453 INFO L138 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2022-11-23 14:21:07,454 INFO L138 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2022-11-23 14:21:07,454 INFO L138 SettingsManager]: * Trace refinement exception blacklist=NONE [2022-11-23 14:21:07,455 INFO L138 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> aba011a2dee79947f4cca7910fc4583b21e1f3cb9acd1affa050aa7677352666 [2022-11-23 14:21:07,790 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2022-11-23 14:21:07,824 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2022-11-23 14:21:07,827 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2022-11-23 14:21:07,828 INFO L271 PluginConnector]: Initializing CDTParser... [2022-11-23 14:21:07,829 INFO L275 PluginConnector]: CDTParser initialized [2022-11-23 14:21:07,830 INFO L432 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/../../sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c [2022-11-23 14:21:11,020 INFO L500 CDTParser]: Created temporary CDT project at NULL [2022-11-23 14:21:11,269 INFO L351 CDTParser]: Found 1 translation units. [2022-11-23 14:21:11,269 INFO L172 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c [2022-11-23 14:21:11,300 INFO L394 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/data/b148d065d/e46d87767a5846f298ba0af864b91708/FLAG847822f18 [2022-11-23 14:21:11,320 INFO L402 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/data/b148d065d/e46d87767a5846f298ba0af864b91708 [2022-11-23 14:21:11,323 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2022-11-23 14:21:11,328 INFO L131 ToolchainWalker]: Walking toolchain with 6 elements. [2022-11-23 14:21:11,332 INFO L113 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2022-11-23 14:21:11,333 INFO L271 PluginConnector]: Initializing CACSL2BoogieTranslator... [2022-11-23 14:21:11,337 INFO L275 PluginConnector]: CACSL2BoogieTranslator initialized [2022-11-23 14:21:11,338 INFO L185 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,340 INFO L205 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1566a34e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11, skipping insertion in model container [2022-11-23 14:21:11,340 INFO L185 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,348 INFO L145 MainTranslator]: Starting translation in SV-COMP mode [2022-11-23 14:21:11,418 INFO L178 MainTranslator]: Built tables and reachable declarations [2022-11-23 14:21:11,572 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c[1605,1618] [2022-11-23 14:21:11,689 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-23 14:21:11,708 INFO L203 MainTranslator]: Completed pre-run [2022-11-23 14:21:11,738 WARN L237 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/sv-benchmarks/c/product-lines/minepump_spec5_product57.cil.c[1605,1618] [2022-11-23 14:21:11,796 INFO L210 PostProcessor]: Analyzing one entry point: main [2022-11-23 14:21:11,815 INFO L208 MainTranslator]: Completed translation [2022-11-23 14:21:11,816 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11 WrapperNode [2022-11-23 14:21:11,816 INFO L132 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2022-11-23 14:21:11,817 INFO L113 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2022-11-23 14:21:11,817 INFO L271 PluginConnector]: Initializing Boogie Procedure Inliner... [2022-11-23 14:21:11,817 INFO L275 PluginConnector]: Boogie Procedure Inliner initialized [2022-11-23 14:21:11,825 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,839 INFO L185 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,866 INFO L138 Inliner]: procedures = 58, calls = 103, calls flagged for inlining = 27, calls inlined = 24, statements flattened = 229 [2022-11-23 14:21:11,866 INFO L132 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2022-11-23 14:21:11,867 INFO L113 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2022-11-23 14:21:11,867 INFO L271 PluginConnector]: Initializing Boogie Preprocessor... [2022-11-23 14:21:11,867 INFO L275 PluginConnector]: Boogie Preprocessor initialized [2022-11-23 14:21:11,877 INFO L185 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,878 INFO L185 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,880 INFO L185 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,880 INFO L185 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,887 INFO L185 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,892 INFO L185 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,894 INFO L185 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,896 INFO L185 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,898 INFO L132 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2022-11-23 14:21:11,899 INFO L113 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2022-11-23 14:21:11,899 INFO L271 PluginConnector]: Initializing RCFGBuilder... [2022-11-23 14:21:11,900 INFO L275 PluginConnector]: RCFGBuilder initialized [2022-11-23 14:21:11,900 INFO L185 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (1/1) ... [2022-11-23 14:21:11,911 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2022-11-23 14:21:11,932 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 [2022-11-23 14:21:11,946 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2022-11-23 14:21:11,948 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2022-11-23 14:21:11,991 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2022-11-23 14:21:11,991 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2022-11-23 14:21:11,991 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2022-11-23 14:21:11,991 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2022-11-23 14:21:11,991 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2022-11-23 14:21:11,992 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2022-11-23 14:21:11,992 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2022-11-23 14:21:11,992 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2022-11-23 14:21:11,992 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2022-11-23 14:21:11,992 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2022-11-23 14:21:11,993 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2022-11-23 14:21:11,993 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2022-11-23 14:21:11,993 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2022-11-23 14:21:11,993 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2022-11-23 14:21:11,993 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2022-11-23 14:21:11,993 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2022-11-23 14:21:11,994 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2022-11-23 14:21:11,994 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2022-11-23 14:21:12,079 INFO L235 CfgBuilder]: Building ICFG [2022-11-23 14:21:12,081 INFO L261 CfgBuilder]: Building CFG for each procedure with an implementation [2022-11-23 14:21:12,405 INFO L276 CfgBuilder]: Performing block encoding [2022-11-23 14:21:12,703 INFO L295 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2022-11-23 14:21:12,703 INFO L300 CfgBuilder]: Removed 2 assume(true) statements. [2022-11-23 14:21:12,706 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 02:21:12 BoogieIcfgContainer [2022-11-23 14:21:12,706 INFO L132 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2022-11-23 14:21:12,708 INFO L113 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2022-11-23 14:21:12,708 INFO L271 PluginConnector]: Initializing TraceAbstraction... [2022-11-23 14:21:12,711 INFO L275 PluginConnector]: TraceAbstraction initialized [2022-11-23 14:21:12,712 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 23.11 02:21:11" (1/3) ... [2022-11-23 14:21:12,712 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@477748e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 02:21:12, skipping insertion in model container [2022-11-23 14:21:12,712 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 23.11 02:21:11" (2/3) ... [2022-11-23 14:21:12,713 INFO L205 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@477748e and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 23.11 02:21:12, skipping insertion in model container [2022-11-23 14:21:12,713 INFO L185 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 02:21:12" (3/3) ... [2022-11-23 14:21:12,714 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product57.cil.c [2022-11-23 14:21:12,764 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2022-11-23 14:21:12,765 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2022-11-23 14:21:12,855 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2022-11-23 14:21:12,863 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@5ce4a6c5, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2022-11-23 14:21:12,864 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2022-11-23 14:21:12,872 INFO L276 IsEmpty]: Start isEmpty. Operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2022-11-23 14:21:12,884 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2022-11-23 14:21:12,884 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:12,885 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:12,886 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:12,894 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:12,894 INFO L85 PathProgramCache]: Analyzing trace with hash -930217378, now seen corresponding path program 1 times [2022-11-23 14:21:12,905 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:12,906 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1770215501] [2022-11-23 14:21:12,906 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:12,906 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:13,037 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:13,101 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:13,101 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:13,102 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1770215501] [2022-11-23 14:21:13,103 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1770215501] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:13,103 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:13,103 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2022-11-23 14:21:13,105 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1667814627] [2022-11-23 14:21:13,106 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:13,110 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2022-11-23 14:21:13,111 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:13,163 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2022-11-23 14:21:13,164 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-23 14:21:13,168 INFO L87 Difference]: Start difference. First operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-23 14:21:13,292 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:13,292 INFO L93 Difference]: Finished difference Result 114 states and 155 transitions. [2022-11-23 14:21:13,296 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2022-11-23 14:21:13,297 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2022-11-23 14:21:13,297 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:13,307 INFO L225 Difference]: With dead ends: 114 [2022-11-23 14:21:13,308 INFO L226 Difference]: Without dead ends: 53 [2022-11-23 14:21:13,312 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2022-11-23 14:21:13,316 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 57 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:13,317 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 57 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2022-11-23 14:21:13,336 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2022-11-23 14:21:13,374 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2022-11-23 14:21:13,375 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3235294117647058) internal successors, (45), 41 states have internal predecessors, (45), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2022-11-23 14:21:13,381 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 68 transitions. [2022-11-23 14:21:13,383 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 68 transitions. Word has length 21 [2022-11-23 14:21:13,384 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:13,385 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 68 transitions. [2022-11-23 14:21:13,385 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-23 14:21:13,386 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 68 transitions. [2022-11-23 14:21:13,391 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2022-11-23 14:21:13,391 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:13,391 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:13,391 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2022-11-23 14:21:13,392 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:13,393 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:13,393 INFO L85 PathProgramCache]: Analyzing trace with hash -861027973, now seen corresponding path program 1 times [2022-11-23 14:21:13,393 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:13,394 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1080274101] [2022-11-23 14:21:13,394 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:13,394 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:13,438 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:13,532 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:13,533 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:13,533 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1080274101] [2022-11-23 14:21:13,533 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1080274101] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:13,534 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:13,534 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-23 14:21:13,534 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1161146339] [2022-11-23 14:21:13,534 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:13,536 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-23 14:21:13,536 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:13,537 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-23 14:21:13,537 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:13,537 INFO L87 Difference]: Start difference. First operand 53 states and 68 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-23 14:21:13,593 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:13,593 INFO L93 Difference]: Finished difference Result 83 states and 107 transitions. [2022-11-23 14:21:13,595 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-23 14:21:13,596 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2022-11-23 14:21:13,596 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:13,597 INFO L225 Difference]: With dead ends: 83 [2022-11-23 14:21:13,597 INFO L226 Difference]: Without dead ends: 45 [2022-11-23 14:21:13,598 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:13,599 INFO L413 NwaCegarLoop]: 43 mSDtfsCounter, 7 mSDsluCounter, 34 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 77 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:13,600 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 77 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-23 14:21:13,601 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 45 states. [2022-11-23 14:21:13,606 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 45 to 45. [2022-11-23 14:21:13,606 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 45 states, 29 states have (on average 1.3448275862068966) internal successors, (39), 36 states have internal predecessors, (39), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-23 14:21:13,617 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 45 states to 45 states and 57 transitions. [2022-11-23 14:21:13,617 INFO L78 Accepts]: Start accepts. Automaton has 45 states and 57 transitions. Word has length 22 [2022-11-23 14:21:13,617 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:13,618 INFO L495 AbstractCegarLoop]: Abstraction has 45 states and 57 transitions. [2022-11-23 14:21:13,618 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2022-11-23 14:21:13,618 INFO L276 IsEmpty]: Start isEmpty. Operand 45 states and 57 transitions. [2022-11-23 14:21:13,620 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2022-11-23 14:21:13,621 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:13,621 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:13,621 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2022-11-23 14:21:13,621 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:13,627 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:13,627 INFO L85 PathProgramCache]: Analyzing trace with hash 1265715326, now seen corresponding path program 1 times [2022-11-23 14:21:13,627 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:13,627 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1393800524] [2022-11-23 14:21:13,627 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:13,628 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:13,665 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:13,798 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:13,799 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:13,799 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1393800524] [2022-11-23 14:21:13,799 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1393800524] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:13,799 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:13,800 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-23 14:21:13,800 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [425779945] [2022-11-23 14:21:13,800 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:13,801 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-23 14:21:13,801 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:13,801 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-23 14:21:13,802 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:13,802 INFO L87 Difference]: Start difference. First operand 45 states and 57 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-23 14:21:13,840 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:13,840 INFO L93 Difference]: Finished difference Result 88 states and 113 transitions. [2022-11-23 14:21:13,841 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-23 14:21:13,841 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 24 [2022-11-23 14:21:13,841 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:13,842 INFO L225 Difference]: With dead ends: 88 [2022-11-23 14:21:13,842 INFO L226 Difference]: Without dead ends: 45 [2022-11-23 14:21:13,843 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:13,845 INFO L413 NwaCegarLoop]: 41 mSDtfsCounter, 44 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 15 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 44 SdHoareTripleChecker+Valid, 41 SdHoareTripleChecker+Invalid, 15 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 15 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:13,845 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [44 Valid, 41 Invalid, 15 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 15 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-23 14:21:13,846 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 45 states. [2022-11-23 14:21:13,853 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 45 to 45. [2022-11-23 14:21:13,853 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 45 states, 29 states have (on average 1.3103448275862069) internal successors, (38), 36 states have internal predecessors, (38), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2022-11-23 14:21:13,854 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 45 states to 45 states and 56 transitions. [2022-11-23 14:21:13,854 INFO L78 Accepts]: Start accepts. Automaton has 45 states and 56 transitions. Word has length 24 [2022-11-23 14:21:13,855 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:13,856 INFO L495 AbstractCegarLoop]: Abstraction has 45 states and 56 transitions. [2022-11-23 14:21:13,856 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-23 14:21:13,856 INFO L276 IsEmpty]: Start isEmpty. Operand 45 states and 56 transitions. [2022-11-23 14:21:13,857 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 28 [2022-11-23 14:21:13,857 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:13,858 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:13,858 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2022-11-23 14:21:13,858 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:13,859 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:13,859 INFO L85 PathProgramCache]: Analyzing trace with hash -715277681, now seen corresponding path program 1 times [2022-11-23 14:21:13,859 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:13,859 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [78310377] [2022-11-23 14:21:13,860 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:13,860 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:13,878 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:13,941 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:13,942 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:13,942 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [78310377] [2022-11-23 14:21:13,942 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [78310377] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:13,943 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:13,943 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2022-11-23 14:21:13,943 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1675899273] [2022-11-23 14:21:13,943 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:13,944 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2022-11-23 14:21:13,944 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:13,945 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2022-11-23 14:21:13,945 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:13,945 INFO L87 Difference]: Start difference. First operand 45 states and 56 transitions. Second operand has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-23 14:21:14,006 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:14,006 INFO L93 Difference]: Finished difference Result 125 states and 159 transitions. [2022-11-23 14:21:14,007 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2022-11-23 14:21:14,007 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 27 [2022-11-23 14:21:14,007 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:14,008 INFO L225 Difference]: With dead ends: 125 [2022-11-23 14:21:14,009 INFO L226 Difference]: Without dead ends: 82 [2022-11-23 14:21:14,009 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2022-11-23 14:21:14,011 INFO L413 NwaCegarLoop]: 60 mSDtfsCounter, 36 mSDsluCounter, 37 mSDsCounter, 0 mSdLazyCounter, 28 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 36 SdHoareTripleChecker+Valid, 97 SdHoareTripleChecker+Invalid, 32 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 28 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:14,011 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [36 Valid, 97 Invalid, 32 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 28 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2022-11-23 14:21:14,012 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 82 states. [2022-11-23 14:21:14,025 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 82 to 80. [2022-11-23 14:21:14,039 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 53 states have (on average 1.2641509433962264) internal successors, (67), 60 states have internal predecessors, (67), 14 states have call successors, (14), 12 states have call predecessors, (14), 12 states have return successors, (18), 14 states have call predecessors, (18), 14 states have call successors, (18) [2022-11-23 14:21:14,040 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 99 transitions. [2022-11-23 14:21:14,040 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 99 transitions. Word has length 27 [2022-11-23 14:21:14,041 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:14,042 INFO L495 AbstractCegarLoop]: Abstraction has 80 states and 99 transitions. [2022-11-23 14:21:14,042 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.0) internal successors, (21), 3 states have internal predecessors, (21), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2022-11-23 14:21:14,042 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 99 transitions. [2022-11-23 14:21:14,043 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2022-11-23 14:21:14,043 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:14,044 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:14,044 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2022-11-23 14:21:14,044 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:14,044 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:14,045 INFO L85 PathProgramCache]: Analyzing trace with hash -2083189764, now seen corresponding path program 1 times [2022-11-23 14:21:14,045 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:14,045 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [739963816] [2022-11-23 14:21:14,045 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:14,045 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:14,091 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:14,504 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:14,504 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:14,504 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [739963816] [2022-11-23 14:21:14,505 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [739963816] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:14,505 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:14,505 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2022-11-23 14:21:14,506 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2079045535] [2022-11-23 14:21:14,506 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:14,506 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2022-11-23 14:21:14,507 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:14,507 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2022-11-23 14:21:14,507 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2022-11-23 14:21:14,508 INFO L87 Difference]: Start difference. First operand 80 states and 99 transitions. Second operand has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-23 14:21:14,766 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:14,766 INFO L93 Difference]: Finished difference Result 241 states and 298 transitions. [2022-11-23 14:21:14,768 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2022-11-23 14:21:14,768 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) Word has length 32 [2022-11-23 14:21:14,768 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:14,780 INFO L225 Difference]: With dead ends: 241 [2022-11-23 14:21:14,780 INFO L226 Difference]: Without dead ends: 163 [2022-11-23 14:21:14,783 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2022-11-23 14:21:14,786 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 81 mSDsluCounter, 139 mSDsCounter, 0 mSdLazyCounter, 148 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 82 SdHoareTripleChecker+Valid, 214 SdHoareTripleChecker+Invalid, 158 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 148 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:14,786 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [82 Valid, 214 Invalid, 158 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 148 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-23 14:21:14,787 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 163 states. [2022-11-23 14:21:14,829 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 163 to 157. [2022-11-23 14:21:14,830 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 157 states, 102 states have (on average 1.2450980392156863) internal successors, (127), 114 states have internal predecessors, (127), 29 states have call successors, (29), 25 states have call predecessors, (29), 25 states have return successors, (38), 27 states have call predecessors, (38), 29 states have call successors, (38) [2022-11-23 14:21:14,831 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 157 states to 157 states and 194 transitions. [2022-11-23 14:21:14,832 INFO L78 Accepts]: Start accepts. Automaton has 157 states and 194 transitions. Word has length 32 [2022-11-23 14:21:14,832 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:14,833 INFO L495 AbstractCegarLoop]: Abstraction has 157 states and 194 transitions. [2022-11-23 14:21:14,833 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.0) internal successors, (24), 6 states have internal predecessors, (24), 3 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 3 states have call successors, (3) [2022-11-23 14:21:14,833 INFO L276 IsEmpty]: Start isEmpty. Operand 157 states and 194 transitions. [2022-11-23 14:21:14,834 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-23 14:21:14,835 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:14,835 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:14,835 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2022-11-23 14:21:14,835 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:14,836 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:14,836 INFO L85 PathProgramCache]: Analyzing trace with hash -600228651, now seen corresponding path program 1 times [2022-11-23 14:21:14,836 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:14,836 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [91147688] [2022-11-23 14:21:14,837 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:14,837 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:14,854 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:15,175 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:15,175 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:15,175 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [91147688] [2022-11-23 14:21:15,176 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [91147688] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:15,176 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:15,176 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2022-11-23 14:21:15,176 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2069375316] [2022-11-23 14:21:15,177 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:15,177 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2022-11-23 14:21:15,177 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:15,178 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2022-11-23 14:21:15,178 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2022-11-23 14:21:15,178 INFO L87 Difference]: Start difference. First operand 157 states and 194 transitions. Second operand has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-23 14:21:15,751 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:15,752 INFO L93 Difference]: Finished difference Result 372 states and 470 transitions. [2022-11-23 14:21:15,752 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 15 states. [2022-11-23 14:21:15,754 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 35 [2022-11-23 14:21:15,754 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:15,763 INFO L225 Difference]: With dead ends: 372 [2022-11-23 14:21:15,763 INFO L226 Difference]: Without dead ends: 266 [2022-11-23 14:21:15,765 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 29 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=67, Invalid=143, Unknown=0, NotChecked=0, Total=210 [2022-11-23 14:21:15,767 INFO L413 NwaCegarLoop]: 69 mSDtfsCounter, 164 mSDsluCounter, 167 mSDsCounter, 0 mSdLazyCounter, 312 mSolverCounterSat, 66 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 169 SdHoareTripleChecker+Valid, 236 SdHoareTripleChecker+Invalid, 378 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 66 IncrementalHoareTripleChecker+Valid, 312 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:15,770 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [169 Valid, 236 Invalid, 378 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [66 Valid, 312 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2022-11-23 14:21:15,773 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 266 states. [2022-11-23 14:21:15,832 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 266 to 234. [2022-11-23 14:21:15,834 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 234 states, 157 states have (on average 1.2547770700636942) internal successors, (197), 174 states have internal predecessors, (197), 40 states have call successors, (40), 31 states have call predecessors, (40), 36 states have return successors, (55), 42 states have call predecessors, (55), 40 states have call successors, (55) [2022-11-23 14:21:15,836 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 234 states to 234 states and 292 transitions. [2022-11-23 14:21:15,836 INFO L78 Accepts]: Start accepts. Automaton has 234 states and 292 transitions. Word has length 35 [2022-11-23 14:21:15,837 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:15,837 INFO L495 AbstractCegarLoop]: Abstraction has 234 states and 292 transitions. [2022-11-23 14:21:15,837 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 3.5714285714285716) internal successors, (25), 7 states have internal predecessors, (25), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2022-11-23 14:21:15,837 INFO L276 IsEmpty]: Start isEmpty. Operand 234 states and 292 transitions. [2022-11-23 14:21:15,844 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2022-11-23 14:21:15,845 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:15,845 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:15,846 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2022-11-23 14:21:15,846 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:15,847 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:15,847 INFO L85 PathProgramCache]: Analyzing trace with hash -175161021, now seen corresponding path program 1 times [2022-11-23 14:21:15,847 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:15,850 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [970640315] [2022-11-23 14:21:15,850 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:15,850 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:15,874 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:15,990 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2022-11-23 14:21:15,991 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:15,991 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [970640315] [2022-11-23 14:21:15,991 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [970640315] provided 1 perfect and 0 imperfect interpolant sequences [2022-11-23 14:21:15,991 INFO L184 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2022-11-23 14:21:15,992 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2022-11-23 14:21:15,992 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [473223918] [2022-11-23 14:21:15,992 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2022-11-23 14:21:15,992 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2022-11-23 14:21:15,993 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:15,993 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2022-11-23 14:21:15,993 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2022-11-23 14:21:15,993 INFO L87 Difference]: Start difference. First operand 234 states and 292 transitions. Second operand has 7 states, 6 states have (on average 4.333333333333333) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-23 14:21:16,339 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:16,339 INFO L93 Difference]: Finished difference Result 499 states and 629 transitions. [2022-11-23 14:21:16,340 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2022-11-23 14:21:16,340 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 6 states have (on average 4.333333333333333) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 2 states have call successors, (4) Word has length 35 [2022-11-23 14:21:16,341 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:16,342 INFO L225 Difference]: With dead ends: 499 [2022-11-23 14:21:16,343 INFO L226 Difference]: Without dead ends: 267 [2022-11-23 14:21:16,344 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 22 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=53, Invalid=157, Unknown=0, NotChecked=0, Total=210 [2022-11-23 14:21:16,344 INFO L413 NwaCegarLoop]: 49 mSDtfsCounter, 58 mSDsluCounter, 175 mSDsCounter, 0 mSdLazyCounter, 237 mSolverCounterSat, 30 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 64 SdHoareTripleChecker+Valid, 224 SdHoareTripleChecker+Invalid, 267 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 30 IncrementalHoareTripleChecker+Valid, 237 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:16,345 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [64 Valid, 224 Invalid, 267 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [30 Valid, 237 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2022-11-23 14:21:16,346 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 267 states. [2022-11-23 14:21:16,394 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 267 to 239. [2022-11-23 14:21:16,395 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 239 states, 160 states have (on average 1.21875) internal successors, (195), 177 states have internal predecessors, (195), 41 states have call successors, (41), 31 states have call predecessors, (41), 37 states have return successors, (58), 43 states have call predecessors, (58), 41 states have call successors, (58) [2022-11-23 14:21:16,396 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 239 states to 239 states and 294 transitions. [2022-11-23 14:21:16,397 INFO L78 Accepts]: Start accepts. Automaton has 239 states and 294 transitions. Word has length 35 [2022-11-23 14:21:16,397 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:16,397 INFO L495 AbstractCegarLoop]: Abstraction has 239 states and 294 transitions. [2022-11-23 14:21:16,398 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 6 states have (on average 4.333333333333333) internal successors, (26), 6 states have internal predecessors, (26), 2 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 2 states have call successors, (4) [2022-11-23 14:21:16,398 INFO L276 IsEmpty]: Start isEmpty. Operand 239 states and 294 transitions. [2022-11-23 14:21:16,401 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2022-11-23 14:21:16,401 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:16,402 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:16,402 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2022-11-23 14:21:16,402 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:16,403 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:16,403 INFO L85 PathProgramCache]: Analyzing trace with hash -1855284806, now seen corresponding path program 1 times [2022-11-23 14:21:16,403 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:16,403 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1772008842] [2022-11-23 14:21:16,403 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:16,404 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:16,423 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:16,848 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 0 proven. 16 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-23 14:21:16,848 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:16,848 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1772008842] [2022-11-23 14:21:16,848 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1772008842] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-23 14:21:16,849 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [233108347] [2022-11-23 14:21:16,851 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:16,851 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-23 14:21:16,852 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 [2022-11-23 14:21:16,855 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-23 14:21:16,875 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2022-11-23 14:21:16,972 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:16,975 INFO L263 TraceCheckSpWp]: Trace formula consists of 328 conjuncts, 22 conjunts are in the unsatisfiable core [2022-11-23 14:21:16,981 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-23 14:21:17,286 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 26 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2022-11-23 14:21:17,286 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-23 14:21:17,486 INFO L134 CoverageAnalysis]: Checked inductivity of 27 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2022-11-23 14:21:17,486 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [233108347] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-23 14:21:17,486 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [35636019] [2022-11-23 14:21:17,506 INFO L159 IcfgInterpreter]: Started Sifa with 36 locations of interest [2022-11-23 14:21:17,506 INFO L166 IcfgInterpreter]: Building call graph [2022-11-23 14:21:17,510 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-23 14:21:17,516 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-23 14:21:17,516 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-23 14:21:21,250 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 52 for LOIs [2022-11-23 14:21:21,272 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 51 for LOIs [2022-11-23 14:21:21,654 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 44 for LOIs [2022-11-23 14:21:21,660 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 26 for LOIs [2022-11-23 14:21:21,695 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-23 14:21:25,931 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '4184#(and (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| 2)) (= |timeShift_getWaterLevel_~retValue_acc~4#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~4#1| ~waterLevel~0) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (= ~head~0.offset 0) (= 1 ~systemActive~0) (= |old(~pumpRunning~0)| 0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| |timeShift_getWaterLevel_#res#1|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= 2 |timeShift_getWaterLevel_~retValue_acc~4#1|) (= ~pumpRunning~0 1) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0) (= |old(~switchedOnBeforeTS~0)| 0))' at error location [2022-11-23 14:21:25,932 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-23 14:21:25,932 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-23 14:21:25,932 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 14 [2022-11-23 14:21:25,932 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1390109387] [2022-11-23 14:21:25,933 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-23 14:21:25,933 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-11-23 14:21:25,933 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:25,934 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-11-23 14:21:25,934 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=191, Invalid=1291, Unknown=0, NotChecked=0, Total=1482 [2022-11-23 14:21:25,934 INFO L87 Difference]: Start difference. First operand 239 states and 294 transitions. Second operand has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) [2022-11-23 14:21:27,657 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:27,657 INFO L93 Difference]: Finished difference Result 680 states and 863 transitions. [2022-11-23 14:21:27,658 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 34 states. [2022-11-23 14:21:27,658 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) Word has length 60 [2022-11-23 14:21:27,659 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:27,662 INFO L225 Difference]: With dead ends: 680 [2022-11-23 14:21:27,662 INFO L226 Difference]: Without dead ends: 443 [2022-11-23 14:21:27,665 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 227 GetRequests, 162 SyntacticMatches, 4 SemanticMatches, 61 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1322 ImplicationChecksByTransitivity, 5.2s TimeCoverageRelationStatistics Valid=551, Invalid=3355, Unknown=0, NotChecked=0, Total=3906 [2022-11-23 14:21:27,665 INFO L413 NwaCegarLoop]: 52 mSDtfsCounter, 377 mSDsluCounter, 286 mSDsCounter, 0 mSdLazyCounter, 827 mSolverCounterSat, 226 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 383 SdHoareTripleChecker+Valid, 338 SdHoareTripleChecker+Invalid, 1053 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 226 IncrementalHoareTripleChecker+Valid, 827 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:27,666 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [383 Valid, 338 Invalid, 1053 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [226 Valid, 827 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2022-11-23 14:21:27,667 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 443 states. [2022-11-23 14:21:27,738 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 443 to 393. [2022-11-23 14:21:27,739 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 393 states, 262 states have (on average 1.183206106870229) internal successors, (310), 294 states have internal predecessors, (310), 63 states have call successors, (63), 50 states have call predecessors, (63), 67 states have return successors, (108), 67 states have call predecessors, (108), 63 states have call successors, (108) [2022-11-23 14:21:27,742 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 393 states to 393 states and 481 transitions. [2022-11-23 14:21:27,742 INFO L78 Accepts]: Start accepts. Automaton has 393 states and 481 transitions. Word has length 60 [2022-11-23 14:21:27,743 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:27,743 INFO L495 AbstractCegarLoop]: Abstraction has 393 states and 481 transitions. [2022-11-23 14:21:27,744 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 13 states have (on average 5.153846153846154) internal successors, (67), 13 states have internal predecessors, (67), 7 states have call successors, (15), 5 states have call predecessors, (15), 5 states have return successors, (14), 6 states have call predecessors, (14), 7 states have call successors, (14) [2022-11-23 14:21:27,744 INFO L276 IsEmpty]: Start isEmpty. Operand 393 states and 481 transitions. [2022-11-23 14:21:27,745 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 64 [2022-11-23 14:21:27,745 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:27,746 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:27,757 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2022-11-23 14:21:27,951 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-23 14:21:27,952 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:27,952 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:27,952 INFO L85 PathProgramCache]: Analyzing trace with hash -1919116790, now seen corresponding path program 1 times [2022-11-23 14:21:27,953 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:27,953 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2099747749] [2022-11-23 14:21:27,953 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:27,953 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:27,972 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:28,247 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 1 proven. 20 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2022-11-23 14:21:28,247 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:28,248 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2099747749] [2022-11-23 14:21:28,248 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2099747749] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-23 14:21:28,248 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [952958327] [2022-11-23 14:21:28,248 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:28,248 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-23 14:21:28,249 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 [2022-11-23 14:21:28,250 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-23 14:21:28,260 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2022-11-23 14:21:28,354 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:28,356 INFO L263 TraceCheckSpWp]: Trace formula consists of 320 conjuncts, 13 conjunts are in the unsatisfiable core [2022-11-23 14:21:28,359 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-23 14:21:28,421 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 14 proven. 1 refuted. 0 times theorem prover too weak. 10 trivial. 0 not checked. [2022-11-23 14:21:28,421 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-23 14:21:28,502 INFO L134 CoverageAnalysis]: Checked inductivity of 25 backedges. 7 proven. 1 refuted. 0 times theorem prover too weak. 17 trivial. 0 not checked. [2022-11-23 14:21:28,502 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [952958327] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-23 14:21:28,502 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1691397304] [2022-11-23 14:21:28,505 INFO L159 IcfgInterpreter]: Started Sifa with 41 locations of interest [2022-11-23 14:21:28,505 INFO L166 IcfgInterpreter]: Building call graph [2022-11-23 14:21:28,506 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-23 14:21:28,506 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-23 14:21:28,507 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-23 14:21:30,703 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 32 for LOIs [2022-11-23 14:21:30,707 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 29 for LOIs [2022-11-23 14:21:30,954 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2022-11-23 14:21:30,966 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 73 for LOIs [2022-11-23 14:21:31,307 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 50 for LOIs [2022-11-23 14:21:31,313 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-23 14:21:35,510 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '6318#(and (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| 2)) (= |timeShift_getWaterLevel_~retValue_acc~4#1| |timeShift_getWaterLevel_#res#1|) (= |timeShift_getWaterLevel_~retValue_acc~4#1| ~waterLevel~0) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~methaneLevelCritical~0 0) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (= ~head~0.offset 0) (<= |old(~pumpRunning~0)| 2147483647) (= 1 ~systemActive~0) (<= 0 (+ |timeShift_getWaterLevel_~retValue_acc~4#1| 2147483648)) (<= 0 (+ |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483648)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 2147483647) (= ~head~0.base 0) (= |#NULL.offset| 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| |timeShift_getWaterLevel_#res#1|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (= ~cleanupTimeShifts~0 4) (= |#NULL.base| 0))' at error location [2022-11-23 14:21:35,511 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-23 14:21:35,511 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-23 14:21:35,511 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 6, 6] total 14 [2022-11-23 14:21:35,511 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [909802074] [2022-11-23 14:21:35,511 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-23 14:21:35,512 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2022-11-23 14:21:35,512 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:35,513 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2022-11-23 14:21:35,514 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=257, Invalid=1723, Unknown=0, NotChecked=0, Total=1980 [2022-11-23 14:21:35,514 INFO L87 Difference]: Start difference. First operand 393 states and 481 transitions. Second operand has 14 states, 12 states have (on average 5.5) internal successors, (66), 12 states have internal predecessors, (66), 5 states have call successors, (14), 3 states have call predecessors, (14), 6 states have return successors, (17), 7 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-23 14:21:36,628 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:36,628 INFO L93 Difference]: Finished difference Result 762 states and 954 transitions. [2022-11-23 14:21:36,630 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2022-11-23 14:21:36,630 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 12 states have (on average 5.5) internal successors, (66), 12 states have internal predecessors, (66), 5 states have call successors, (14), 3 states have call predecessors, (14), 6 states have return successors, (17), 7 states have call predecessors, (17), 5 states have call successors, (17) Word has length 63 [2022-11-23 14:21:36,631 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:36,633 INFO L225 Difference]: With dead ends: 762 [2022-11-23 14:21:36,634 INFO L226 Difference]: Without dead ends: 464 [2022-11-23 14:21:36,639 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 239 GetRequests, 171 SyntacticMatches, 0 SemanticMatches, 68 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1530 ImplicationChecksByTransitivity, 4.8s TimeCoverageRelationStatistics Valid=594, Invalid=4236, Unknown=0, NotChecked=0, Total=4830 [2022-11-23 14:21:36,640 INFO L413 NwaCegarLoop]: 82 mSDtfsCounter, 346 mSDsluCounter, 271 mSDsCounter, 0 mSdLazyCounter, 537 mSolverCounterSat, 216 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 351 SdHoareTripleChecker+Valid, 353 SdHoareTripleChecker+Invalid, 753 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 216 IncrementalHoareTripleChecker+Valid, 537 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:36,640 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [351 Valid, 353 Invalid, 753 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [216 Valid, 537 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2022-11-23 14:21:36,641 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 464 states. [2022-11-23 14:21:36,693 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 464 to 433. [2022-11-23 14:21:36,694 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 433 states, 285 states have (on average 1.1578947368421053) internal successors, (330), 320 states have internal predecessors, (330), 71 states have call successors, (71), 62 states have call predecessors, (71), 76 states have return successors, (116), 74 states have call predecessors, (116), 71 states have call successors, (116) [2022-11-23 14:21:36,697 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 433 states to 433 states and 517 transitions. [2022-11-23 14:21:36,697 INFO L78 Accepts]: Start accepts. Automaton has 433 states and 517 transitions. Word has length 63 [2022-11-23 14:21:36,698 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:36,698 INFO L495 AbstractCegarLoop]: Abstraction has 433 states and 517 transitions. [2022-11-23 14:21:36,698 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 12 states have (on average 5.5) internal successors, (66), 12 states have internal predecessors, (66), 5 states have call successors, (14), 3 states have call predecessors, (14), 6 states have return successors, (17), 7 states have call predecessors, (17), 5 states have call successors, (17) [2022-11-23 14:21:36,699 INFO L276 IsEmpty]: Start isEmpty. Operand 433 states and 517 transitions. [2022-11-23 14:21:36,706 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2022-11-23 14:21:36,710 INFO L187 NwaCegarLoop]: Found error trace [2022-11-23 14:21:36,710 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:21:36,719 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2022-11-23 14:21:36,911 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-23 14:21:36,911 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2022-11-23 14:21:36,911 INFO L144 PredicateUnifier]: Initialized classic predicate unifier [2022-11-23 14:21:36,911 INFO L85 PathProgramCache]: Analyzing trace with hash -658251347, now seen corresponding path program 1 times [2022-11-23 14:21:36,912 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2022-11-23 14:21:36,912 INFO L333 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [290661537] [2022-11-23 14:21:36,912 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:36,912 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2022-11-23 14:21:36,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:37,948 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 12 proven. 42 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-23 14:21:37,948 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2022-11-23 14:21:37,948 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [290661537] [2022-11-23 14:21:37,949 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [290661537] provided 0 perfect and 1 imperfect interpolant sequences [2022-11-23 14:21:37,949 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1999501178] [2022-11-23 14:21:37,949 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2022-11-23 14:21:37,949 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2022-11-23 14:21:37,949 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 [2022-11-23 14:21:37,950 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2022-11-23 14:21:37,977 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2022-11-23 14:21:38,063 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2022-11-23 14:21:38,065 INFO L263 TraceCheckSpWp]: Trace formula consists of 424 conjuncts, 34 conjunts are in the unsatisfiable core [2022-11-23 14:21:38,069 INFO L286 TraceCheckSpWp]: Computing forward predicates... [2022-11-23 14:21:38,535 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 23 proven. 51 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2022-11-23 14:21:38,536 INFO L328 TraceCheckSpWp]: Computing backward predicates... [2022-11-23 14:21:39,169 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 49 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2022-11-23 14:21:39,169 INFO L157 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1999501178] provided 0 perfect and 2 imperfect interpolant sequences [2022-11-23 14:21:39,169 INFO L333 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [1491789829] [2022-11-23 14:21:39,172 INFO L159 IcfgInterpreter]: Started Sifa with 37 locations of interest [2022-11-23 14:21:39,172 INFO L166 IcfgInterpreter]: Building call graph [2022-11-23 14:21:39,172 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2022-11-23 14:21:39,172 INFO L176 IcfgInterpreter]: Starting interpretation [2022-11-23 14:21:39,173 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2022-11-23 14:21:42,127 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 35 for LOIs [2022-11-23 14:21:42,132 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 49 for LOIs [2022-11-23 14:21:42,796 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 22 for LOIs [2022-11-23 14:21:42,798 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 29 for LOIs [2022-11-23 14:21:42,821 INFO L180 IcfgInterpreter]: Interpretation finished [2022-11-23 14:21:48,258 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '8798#(and (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 0)) (not (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| 2)) (= |timeShift_getWaterLevel_~retValue_acc~4#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |#NULL.base|) (= |timeShift_getWaterLevel_~retValue_acc~4#1| ~waterLevel~0) (<= 0 |old(~pumpRunning~0)|) (<= |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1| 1) (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__3_~tmp___0~0#1|) (= ~head~0.offset 0) (<= 1 ~systemActive~0) (<= |old(~pumpRunning~0)| 2147483647) (<= |#NULL.offset| 0) (<= ~methaneLevelCritical~0 0) (<= 0 ~head~0.base) (<= |#NULL.base| 0) (<= 0 ~methaneLevelCritical~0) (<= 0 (+ |timeShift_getWaterLevel_~retValue_acc~4#1| 2147483648)) (<= |timeShift_getWaterLevel_#res#1| 2147483647) (<= 0 ~pumpRunning~0) (<= ~head~0.base 0) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| |timeShift_getWaterLevel_#res#1|) (<= 0 |#NULL.offset|) (= ~switchedOnBeforeTS~0 0) (<= 0 |#StackHeapBarrier|) (<= ~systemActive~0 1) (= ~cleanupTimeShifts~0 4))' at error location [2022-11-23 14:21:48,258 WARN L310 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2022-11-23 14:21:48,258 INFO L184 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2022-11-23 14:21:48,258 INFO L197 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [18, 13, 11] total 32 [2022-11-23 14:21:48,258 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1312971744] [2022-11-23 14:21:48,259 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2022-11-23 14:21:48,259 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 32 states [2022-11-23 14:21:48,260 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2022-11-23 14:21:48,260 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 32 interpolants. [2022-11-23 14:21:48,261 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=386, Invalid=3154, Unknown=0, NotChecked=0, Total=3540 [2022-11-23 14:21:48,262 INFO L87 Difference]: Start difference. First operand 433 states and 517 transitions. Second operand has 32 states, 31 states have (on average 4.838709677419355) internal successors, (150), 31 states have internal predecessors, (150), 17 states have call successors, (29), 9 states have call predecessors, (29), 12 states have return successors, (27), 16 states have call predecessors, (27), 16 states have call successors, (27) [2022-11-23 14:21:53,060 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2022-11-23 14:21:53,061 INFO L93 Difference]: Finished difference Result 987 states and 1230 transitions. [2022-11-23 14:21:53,061 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 66 states. [2022-11-23 14:21:53,079 INFO L78 Accepts]: Start accepts. Automaton has has 32 states, 31 states have (on average 4.838709677419355) internal successors, (150), 31 states have internal predecessors, (150), 17 states have call successors, (29), 9 states have call predecessors, (29), 12 states have return successors, (27), 16 states have call predecessors, (27), 16 states have call successors, (27) Word has length 85 [2022-11-23 14:21:53,080 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2022-11-23 14:21:53,081 INFO L225 Difference]: With dead ends: 987 [2022-11-23 14:21:53,081 INFO L226 Difference]: Without dead ends: 0 [2022-11-23 14:21:53,089 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 372 GetRequests, 247 SyntacticMatches, 4 SemanticMatches, 121 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5710 ImplicationChecksByTransitivity, 8.7s TimeCoverageRelationStatistics Valid=1979, Invalid=13027, Unknown=0, NotChecked=0, Total=15006 [2022-11-23 14:21:53,096 INFO L413 NwaCegarLoop]: 84 mSDtfsCounter, 962 mSDsluCounter, 685 mSDsCounter, 0 mSdLazyCounter, 2397 mSolverCounterSat, 665 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 963 SdHoareTripleChecker+Valid, 769 SdHoareTripleChecker+Invalid, 3062 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 665 IncrementalHoareTripleChecker+Valid, 2397 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.8s IncrementalHoareTripleChecker+Time [2022-11-23 14:21:53,097 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [963 Valid, 769 Invalid, 3062 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [665 Valid, 2397 Invalid, 0 Unknown, 0 Unchecked, 1.8s Time] [2022-11-23 14:21:53,098 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2022-11-23 14:21:53,098 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2022-11-23 14:21:53,098 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2022-11-23 14:21:53,098 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2022-11-23 14:21:53,100 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 85 [2022-11-23 14:21:53,100 INFO L84 Accepts]: Finished accepts. word is rejected. [2022-11-23 14:21:53,100 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2022-11-23 14:21:53,100 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 32 states, 31 states have (on average 4.838709677419355) internal successors, (150), 31 states have internal predecessors, (150), 17 states have call successors, (29), 9 states have call predecessors, (29), 12 states have return successors, (27), 16 states have call predecessors, (27), 16 states have call successors, (27) [2022-11-23 14:21:53,100 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2022-11-23 14:21:53,101 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2022-11-23 14:21:53,103 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2022-11-23 14:21:53,132 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2022-11-23 14:21:53,313 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2022-11-23 14:21:53,314 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2022-11-23 14:22:00,415 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 822 828) no Hoare annotation was computed. [2022-11-23 14:22:00,416 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 822 828) the Hoare annotation is: true [2022-11-23 14:22:00,416 INFO L902 garLoopResultBuilder]: At program point changeMethaneLevelENTRY(lines 232 243) the Hoare annotation is: true [2022-11-23 14:22:00,416 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 232 243) no Hoare annotation was computed. [2022-11-23 14:22:00,417 INFO L895 garLoopResultBuilder]: At program point L870(line 870) the Hoare annotation is: (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse7 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 (or .cse3 .cse4) (<= ~waterLevel~0 0) .cse5) .cse6) (or .cse0 .cse1 .cse4 (not (<= |old(~waterLevel~0)| 0)) .cse6) (or (and .cse2 .cse3 .cse5) .cse1 .cse7 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 .cse7))) [2022-11-23 14:22:00,417 INFO L895 garLoopResultBuilder]: At program point L705(line 705) the Hoare annotation is: (let ((.cse9 (+ ~waterLevel~0 1))) (let ((.cse0 (not (<= |old(~waterLevel~0)| 1))) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse7 (not (= ~switchedOnBeforeTS~0 0))) (.cse3 (= ~pumpRunning~0 0)) (.cse10 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse11 (= |old(~waterLevel~0)| .cse9)) (.cse4 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| ~waterLevel~0)) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 .cse2 (and .cse3 .cse4 .cse5 .cse6)) (let ((.cse8 (or (and .cse11 (< 0 |old(~waterLevel~0)|)) .cse5))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 .cse2 (and .cse7 .cse3 .cse4 .cse8 (or (<= |old(~waterLevel~0)| 0) (<= .cse9 |old(~waterLevel~0)|))) (and .cse10 .cse4 (<= ~waterLevel~0 0) .cse8 .cse6) (= |old(~switchedOnBeforeTS~0)| 0))) (let ((.cse12 (or .cse1 (<= |old(~waterLevel~0)| ~waterLevel~0)))) (or .cse2 (and .cse7 .cse3 .cse4 (= ~waterLevel~0 1) .cse12) (and .cse10 .cse11 .cse4 .cse6 .cse12) (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))))))) [2022-11-23 14:22:00,417 INFO L899 garLoopResultBuilder]: For program point L705-1(line 705) no Hoare annotation was computed. [2022-11-23 14:22:00,418 INFO L895 garLoopResultBuilder]: At program point L875(line 875) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (<= |old(~waterLevel~0)| 2))) (.cse0 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse2) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (not (<= |old(~waterLevel~0)| 1)) .cse0 (= |old(~switchedOnBeforeTS~0)| 0)))) [2022-11-23 14:22:00,418 INFO L895 garLoopResultBuilder]: At program point L875-1(lines 856 880) the Hoare annotation is: (let ((.cse10 (+ ~waterLevel~0 1))) (let ((.cse5 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (<= |old(~waterLevel~0)| 0)) (.cse7 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse9 (= |old(~waterLevel~0)| .cse10)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse8 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= 2 ~waterLevel~0) .cse0) .cse1 (and .cse2 .cse0 .cse3) .cse4) (or .cse5 .cse1 .cse0 (not .cse6) .cse7) (or .cse5 .cse1 (and .cse8 .cse2 (or .cse9 .cse0) (or .cse6 (<= .cse10 |old(~waterLevel~0)|))) (and .cse11 (or .cse9 (not (< 0 |old(~waterLevel~0)|))) .cse3) .cse4 .cse7) (or (and .cse11 .cse9 .cse3) .cse1 (and .cse0 (or .cse11 (= ~pumpRunning~0 1))) (and .cse8 .cse2 (= ~waterLevel~0 1)) .cse4 (not (<= 2 |old(~waterLevel~0)|)))))) [2022-11-23 14:22:00,418 INFO L895 garLoopResultBuilder]: At program point L809-1(lines 809 815) the Hoare annotation is: (let ((.cse10 (+ ~waterLevel~0 1))) (let ((.cse5 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (<= |old(~waterLevel~0)| 0)) (.cse7 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse9 (= |old(~waterLevel~0)| .cse10)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse11 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse8 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~pumpRunning~0)| 0)) (and (= 2 ~waterLevel~0) .cse0) .cse1 (and .cse2 .cse0 .cse3) .cse4) (or .cse5 .cse1 .cse0 (not .cse6) .cse7) (or .cse5 .cse1 (and .cse8 .cse2 (or .cse9 .cse0) (or .cse6 (<= .cse10 |old(~waterLevel~0)|))) (and .cse11 (or .cse9 (not (< 0 |old(~waterLevel~0)|))) .cse3) .cse4 .cse7) (or (and .cse11 .cse9 .cse3) .cse1 (and .cse0 (or .cse11 (= ~pumpRunning~0 1))) (and .cse8 .cse2 (= ~waterLevel~0 1)) .cse4 (not (<= 2 |old(~waterLevel~0)|)))))) [2022-11-23 14:22:00,419 INFO L895 garLoopResultBuilder]: At program point L54(line 54) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= |old(~waterLevel~0)| 2)))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (not (<= |old(~waterLevel~0)| 1)) .cse0) (or .cse0 .cse1 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2022-11-23 14:22:00,419 INFO L895 garLoopResultBuilder]: At program point L690(line 690) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse3 (and (not (= ~switchedOnBeforeTS~0 0)) (= ~pumpRunning~0 0) .cse2) (= |old(~switchedOnBeforeTS~0)| 0)) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (and .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse3))) [2022-11-23 14:22:00,419 INFO L895 garLoopResultBuilder]: At program point L690-1(line 690) the Hoare annotation is: (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse6 (not (<= |old(~waterLevel~0)| 2))) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= ~pumpRunning~0 |timeShift___utac_acc__Specification5_spec__2_#t~ret34#1|)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse7 (not (<= 2 |old(~waterLevel~0)|)))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 .cse2) (or .cse0 .cse1 (and .cse3 .cse4 .cse5 .cse2) .cse6 (= |old(~switchedOnBeforeTS~0)| 0)) (or (not (<= |old(~waterLevel~0)| 1)) (not (= |old(~pumpRunning~0)| 0)) .cse1 (and (= ~pumpRunning~0 0) .cse4 .cse5)) (or .cse0 .cse1 .cse6 .cse2 .cse7) (or .cse1 .cse6 (and .cse3 .cse4 .cse5) .cse7))) [2022-11-23 14:22:00,420 INFO L899 garLoopResultBuilder]: For program point L707(lines 707 717) no Hoare annotation was computed. [2022-11-23 14:22:00,420 INFO L899 garLoopResultBuilder]: For program point L802-2(lines 798 820) no Hoare annotation was computed. [2022-11-23 14:22:00,422 INFO L895 garLoopResultBuilder]: At program point L864(lines 864 872) the Hoare annotation is: (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= |old(~waterLevel~0)| (+ ~waterLevel~0 1))) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse7 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (not (<= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 (or .cse3 .cse4) (<= ~waterLevel~0 0) .cse5) .cse6) (or .cse0 .cse1 .cse4 (not (<= |old(~waterLevel~0)| 0)) .cse6) (or (and .cse2 .cse3 .cse5) .cse1 .cse7 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse1 .cse7))) [2022-11-23 14:22:00,423 INFO L899 garLoopResultBuilder]: For program point L703(lines 703 720) no Hoare annotation was computed. [2022-11-23 14:22:00,423 INFO L895 garLoopResultBuilder]: At program point L703-1(lines 695 723) the Hoare annotation is: (let ((.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~4#1| ~waterLevel~0)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse6 (+ ~waterLevel~0 1)) (.cse9 (= 1 ~systemActive~0))) (let ((.cse13 (not (= |old(~pumpRunning~0)| 0))) (.cse0 (not .cse9)) (.cse1 (not (= ~switchedOnBeforeTS~0 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse12 (= |old(~waterLevel~0)| .cse6)) (.cse11 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse14 (and .cse9 .cse3 .cse5 (or .cse8 (= ~pumpRunning~0 1)))) (.cse7 (not (<= |old(~waterLevel~0)| 2)))) (and (let ((.cse10 (< 0 |old(~waterLevel~0)|))) (let ((.cse4 (and .cse12 .cse10))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (and .cse1 .cse2 .cse3 (or .cse4 .cse5) (or (<= |old(~waterLevel~0)| 0) (<= .cse6 |old(~waterLevel~0)|))) .cse7 (and .cse8 .cse9 .cse3 (or (and (not .cse10) .cse5) .cse4) .cse11) (= |old(~switchedOnBeforeTS~0)| 0)))) (or .cse13 .cse0 .cse14 .cse7) (or (not (<= |old(~waterLevel~0)| 1)) .cse13 (and .cse2 .cse11) .cse0) (or .cse0 (and .cse1 .cse2 .cse3 (= ~waterLevel~0 1)) (and .cse8 .cse12 .cse9 .cse3 .cse11) .cse14 .cse7 (not (<= 2 |old(~waterLevel~0)|)))))) [2022-11-23 14:22:00,424 INFO L895 garLoopResultBuilder]: At program point L860(lines 860 877) the Hoare annotation is: (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse6 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse1 (not (<= |old(~waterLevel~0)| 1))) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse7 (= ~pumpRunning~0 0)) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (and (or .cse0 .cse1 .cse2 (and .cse3 (or (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse4) (<= ~waterLevel~0 0) .cse5) .cse6) (or .cse0 .cse2 .cse4 (not (<= |old(~waterLevel~0)| 0)) .cse6) (or .cse1 (not (= |old(~pumpRunning~0)| 0)) .cse2 (and .cse7 .cse4 .cse5)) (or .cse2 (not (<= |old(~waterLevel~0)| 2)) (and .cse3 (or (and (not .cse7) (<= ~waterLevel~0 1) (<= 1 ~waterLevel~0)) (and .cse7 (<= 2 ~waterLevel~0) (<= ~waterLevel~0 2))) .cse5) (not (<= 2 |old(~waterLevel~0)|))))) [2022-11-23 14:22:00,424 INFO L895 garLoopResultBuilder]: At program point timeShiftENTRY(lines 795 821) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (not (<= |old(~waterLevel~0)| 2)))) (and (or .cse0 (and .cse1 .cse2) .cse3 (not (<= 2 |old(~waterLevel~0)|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse3 (and (not (= ~switchedOnBeforeTS~0 0)) (= ~pumpRunning~0 0) .cse2) (= |old(~switchedOnBeforeTS~0)| 0)) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (and .cse1 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse3))) [2022-11-23 14:22:00,424 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 795 821) no Hoare annotation was computed. [2022-11-23 14:22:00,424 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2022-11-23 14:22:00,424 INFO L899 garLoopResultBuilder]: For program point L708(lines 708 714) no Hoare annotation was computed. [2022-11-23 14:22:00,424 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 99 128) no Hoare annotation was computed. [2022-11-23 14:22:00,425 INFO L902 garLoopResultBuilder]: At program point cleanupENTRY(lines 99 128) the Hoare annotation is: true [2022-11-23 14:22:00,425 INFO L902 garLoopResultBuilder]: At program point L124(lines 99 128) the Hoare annotation is: true [2022-11-23 14:22:00,425 INFO L899 garLoopResultBuilder]: For program point L120(line 120) no Hoare annotation was computed. [2022-11-23 14:22:00,425 INFO L899 garLoopResultBuilder]: For program point L113(lines 113 117) no Hoare annotation was computed. [2022-11-23 14:22:00,425 INFO L902 garLoopResultBuilder]: At program point L113-1(lines 113 117) the Hoare annotation is: true [2022-11-23 14:22:00,425 INFO L902 garLoopResultBuilder]: At program point L109-2(lines 109 123) the Hoare annotation is: true [2022-11-23 14:22:00,425 INFO L902 garLoopResultBuilder]: At program point L105(line 105) the Hoare annotation is: true [2022-11-23 14:22:00,426 INFO L899 garLoopResultBuilder]: For program point L105-1(line 105) no Hoare annotation was computed. [2022-11-23 14:22:00,426 INFO L895 garLoopResultBuilder]: At program point L771-2(lines 765 776) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (<= ~waterLevel~0 1) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= ~waterLevel~0 2)))) [2022-11-23 14:22:00,426 INFO L902 garLoopResultBuilder]: At program point ULTIMATE.startENTRY(line -1) the Hoare annotation is: true [2022-11-23 14:22:00,426 INFO L899 garLoopResultBuilder]: For program point L755(lines 755 761) no Hoare annotation was computed. [2022-11-23 14:22:00,426 INFO L899 garLoopResultBuilder]: For program point L755-1(lines 755 761) no Hoare annotation was computed. [2022-11-23 14:22:00,426 INFO L902 garLoopResultBuilder]: At program point L784(lines 725 788) the Hoare annotation is: true [2022-11-23 14:22:00,427 INFO L895 garLoopResultBuilder]: At program point L747(line 747) the Hoare annotation is: (let ((.cse2 (<= ~waterLevel~0 1)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and .cse2 .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and (= ~pumpRunning~0 0) .cse2 .cse0 .cse1))) [2022-11-23 14:22:00,427 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2022-11-23 14:22:00,427 INFO L895 garLoopResultBuilder]: At program point L186(lines 186 193) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2022-11-23 14:22:00,427 INFO L902 garLoopResultBuilder]: At program point L186-2(lines 186 193) the Hoare annotation is: true [2022-11-23 14:22:00,427 INFO L895 garLoopResultBuilder]: At program point L781(lines 734 782) the Hoare annotation is: false [2022-11-23 14:22:00,427 INFO L899 garLoopResultBuilder]: For program point L736(lines 735 780) no Hoare annotation was computed. [2022-11-23 14:22:00,428 INFO L895 garLoopResultBuilder]: At program point L757(line 757) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and (<= ~waterLevel~0 1) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= ~waterLevel~0 2)))) [2022-11-23 14:22:00,428 INFO L895 garLoopResultBuilder]: At program point L778(lines 735 780) the Hoare annotation is: (let ((.cse2 (<= ~waterLevel~0 1)) (.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and .cse2 .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and (= ~pumpRunning~0 0) .cse2 .cse0 .cse1))) [2022-11-23 14:22:00,428 INFO L899 garLoopResultBuilder]: For program point L745(lines 745 751) no Hoare annotation was computed. [2022-11-23 14:22:00,428 INFO L899 garLoopResultBuilder]: For program point L745-1(lines 745 751) no Hoare annotation was computed. [2022-11-23 14:22:00,428 INFO L895 garLoopResultBuilder]: At program point processEnvironment__wrappee__highWaterSensorENTRY(lines 830 854) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-23 14:22:00,429 INFO L895 garLoopResultBuilder]: At program point L849(line 849) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (not (<= ~waterLevel~0 2))) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1 .cse2))) [2022-11-23 14:22:00,429 INFO L899 garLoopResultBuilder]: For program point L849-1(lines 830 854) no Hoare annotation was computed. [2022-11-23 14:22:00,429 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 830 854) no Hoare annotation was computed. [2022-11-23 14:22:00,429 INFO L895 garLoopResultBuilder]: At program point L844(line 844) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0) (not (<= ~waterLevel~0 1)) .cse1) (or .cse0 .cse2 (= ~switchedOnBeforeTS~0 0) .cse1) (or .cse0 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-23 14:22:00,429 INFO L895 garLoopResultBuilder]: At program point L838(lines 838 846) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not (<= ~waterLevel~0 2))) (.cse1 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (= |processEnvironment__wrappee__highWaterSensor_~tmp~6#1| 0) (not (<= ~waterLevel~0 1)) .cse1) (or .cse0 .cse2 (= ~switchedOnBeforeTS~0 0) .cse1) (or .cse0 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) [2022-11-23 14:22:00,429 INFO L895 garLoopResultBuilder]: At program point L834(lines 834 851) the Hoare annotation is: (or (not (= 1 ~systemActive~0)) (not (<= ~waterLevel~0 2)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|))) [2022-11-23 14:22:00,430 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 220 231) no Hoare annotation was computed. [2022-11-23 14:22:00,430 INFO L895 garLoopResultBuilder]: At program point waterRiseENTRY(lines 220 231) the Hoare annotation is: (let ((.cse2 (not (<= |old(~waterLevel~0)| 1))) (.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 (not (<= |old(~waterLevel~0)| 2)) (not (<= 2 |old(~waterLevel~0)|))) (or .cse2 .cse0 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1) (or .cse2 (not (= ~pumpRunning~0 0)) .cse0 .cse1))) [2022-11-23 14:22:00,430 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 926 934) no Hoare annotation was computed. [2022-11-23 14:22:00,430 INFO L902 garLoopResultBuilder]: At program point isPumpRunningENTRY(lines 926 934) the Hoare annotation is: true [2022-11-23 14:22:00,433 INFO L444 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2022-11-23 14:22:00,436 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2022-11-23 14:22:00,499 INFO L202 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 23.11 02:22:00 BoogieIcfgContainer [2022-11-23 14:22:00,500 INFO L132 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2022-11-23 14:22:00,500 INFO L113 PluginConnector]: ------------------------Witness Printer---------------------------- [2022-11-23 14:22:00,500 INFO L271 PluginConnector]: Initializing Witness Printer... [2022-11-23 14:22:00,501 INFO L275 PluginConnector]: Witness Printer initialized [2022-11-23 14:22:00,501 INFO L185 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 23.11 02:21:12" (3/4) ... [2022-11-23 14:22:00,504 INFO L137 WitnessPrinter]: Generating witness for correct program [2022-11-23 14:22:00,512 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2022-11-23 14:22:00,512 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2022-11-23 14:22:00,512 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2022-11-23 14:22:00,512 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2022-11-23 14:22:00,513 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2022-11-23 14:22:00,513 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2022-11-23 14:22:00,513 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2022-11-23 14:22:00,527 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 54 nodes and edges [2022-11-23 14:22:00,528 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 13 nodes and edges [2022-11-23 14:22:00,528 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 6 nodes and edges [2022-11-23 14:22:00,528 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-23 14:22:00,529 INFO L915 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2022-11-23 14:22:00,560 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || pumpRunning == switchedOnBeforeTS) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) [2022-11-23 14:22:00,561 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || !(0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-23 14:22:00,562 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && 1 == systemActive) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((1 == systemActive && tmp == waterLevel) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && pumpRunning == switchedOnBeforeTS)) || !(1 == systemActive))) && (((((!(1 == systemActive) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && waterLevel == 1)) || ((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && 1 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || (((1 == systemActive && tmp == waterLevel) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-23 14:22:00,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && waterLevel <= 0) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel))) [2022-11-23 14:22:00,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) && ((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-11-23 14:22:00,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || !(0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) [2022-11-23 14:22:00,563 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!(1 == systemActive) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) [2022-11-23 14:22:00,564 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && waterLevel <= 0) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) [2022-11-23 14:22:00,566 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!(1 == systemActive) || tmp == 0) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) && (((!(1 == systemActive) || !(waterLevel <= 2)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && (((!(1 == systemActive) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) [2022-11-23 14:22:00,622 INFO L141 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/witness.graphml [2022-11-23 14:22:00,622 INFO L132 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2022-11-23 14:22:00,623 INFO L158 Benchmark]: Toolchain (without parser) took 49294.76ms. Allocated memory was 159.4MB in the beginning and 587.2MB in the end (delta: 427.8MB). Free memory was 130.1MB in the beginning and 487.2MB in the end (delta: -357.1MB). Peak memory consumption was 70.4MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,623 INFO L158 Benchmark]: CDTParser took 0.15ms. Allocated memory is still 132.1MB. Free memory is still 99.0MB. There was no memory consumed. Max. memory is 16.1GB. [2022-11-23 14:22:00,624 INFO L158 Benchmark]: CACSL2BoogieTranslator took 483.92ms. Allocated memory is still 159.4MB. Free memory was 129.9MB in the beginning and 112.0MB in the end (delta: 17.9MB). Peak memory consumption was 19.3MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,624 INFO L158 Benchmark]: Boogie Procedure Inliner took 49.55ms. Allocated memory is still 159.4MB. Free memory was 112.0MB in the beginning and 109.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,624 INFO L158 Benchmark]: Boogie Preprocessor took 31.39ms. Allocated memory is still 159.4MB. Free memory was 109.9MB in the beginning and 108.4MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,625 INFO L158 Benchmark]: RCFGBuilder took 807.16ms. Allocated memory is still 159.4MB. Free memory was 108.4MB in the beginning and 80.1MB in the end (delta: 28.2MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,625 INFO L158 Benchmark]: TraceAbstraction took 47791.67ms. Allocated memory was 159.4MB in the beginning and 587.2MB in the end (delta: 427.8MB). Free memory was 79.6MB in the beginning and 492.4MB in the end (delta: -412.9MB). Peak memory consumption was 305.2MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,626 INFO L158 Benchmark]: Witness Printer took 122.10ms. Allocated memory is still 587.2MB. Free memory was 492.4MB in the beginning and 487.2MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2022-11-23 14:22:00,627 INFO L339 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.15ms. Allocated memory is still 132.1MB. Free memory is still 99.0MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 483.92ms. Allocated memory is still 159.4MB. Free memory was 129.9MB in the beginning and 112.0MB in the end (delta: 17.9MB). Peak memory consumption was 19.3MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 49.55ms. Allocated memory is still 159.4MB. Free memory was 112.0MB in the beginning and 109.9MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 31.39ms. Allocated memory is still 159.4MB. Free memory was 109.9MB in the beginning and 108.4MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 807.16ms. Allocated memory is still 159.4MB. Free memory was 108.4MB in the beginning and 80.1MB in the end (delta: 28.2MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. * TraceAbstraction took 47791.67ms. Allocated memory was 159.4MB in the beginning and 587.2MB in the end (delta: 427.8MB). Free memory was 79.6MB in the beginning and 492.4MB in the end (delta: -412.9MB). Peak memory consumption was 305.2MB. Max. memory is 16.1GB. * Witness Printer took 122.10ms. Allocated memory is still 587.2MB. Free memory was 492.4MB in the beginning and 487.2MB in the end (delta: 5.2MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: call to reach_error is unreachable For all program executions holds that call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 58 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 47.6s, OverallIterations: 10, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 9.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 7.1s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2102 SdHoareTripleChecker+Valid, 4.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2075 mSDsluCounter, 2406 SdHoareTripleChecker+Invalid, 3.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1794 mSDsCounter, 1218 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4543 IncrementalHoareTripleChecker+Invalid, 5761 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1218 mSolverCounterUnsat, 612 mSDtfsCounter, 4543 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 896 GetRequests, 604 SyntacticMatches, 8 SemanticMatches, 284 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8615 ImplicationChecksByTransitivity, 19.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=433occurred in iteration=9, InterpolantAutomatonStates: 176, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 10 MinimizatonAttempts, 149 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 35 LocationsWithAnnotation, 1320 PreInvPairs, 1579 NumberOfFragments, 1711 HoareAnnotationTreeSize, 1320 FomulaSimplifications, 5816 FormulaSimplificationTreeSizeReduction, 0.7s HoareSimplificationTime, 35 FomulaSimplificationsInter, 29095 FormulaSimplificationTreeSizeReductionInter, 6.3s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 4.7s InterpolantComputationTime, 612 NumberOfCodeBlocks, 612 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 804 ConstructedInterpolants, 0 QuantifiedInterpolants, 3094 SizeOfPredicates, 30 NumberOfNonLiveVariables, 1072 ConjunctsInSsa, 69 ConjunctsInUnsatCore, 16 InterpolantComputations, 7 PerfectInterpolantSequences, 260/398 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: -1]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 54]: Loop Invariant Derived loop invariant: (((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) && ((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) - InvariantResult [Line: 834]: Loop Invariant Derived loop invariant: ((!(1 == systemActive) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning)) - InvariantResult [Line: 856]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || !(0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 109]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 809]: Loop Invariant Derived loop invariant: ((((((!(\old(pumpRunning) == 0) || (2 == waterLevel && \old(waterLevel) == waterLevel)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || ((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || !(0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || (\old(waterLevel) == waterLevel && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || ((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && waterLevel == 1)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 690]: Loop Invariant Derived loop invariant: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) == 1)) || !(1 == systemActive)) || pumpRunning == switchedOnBeforeTS) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS)) || !(\old(waterLevel) <= 2)) || \old(switchedOnBeforeTS) == 0)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel))) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || pumpRunning == switchedOnBeforeTS) || !(2 <= \old(waterLevel)))) && (((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && pumpRunning == aux-isPumpRunning()-aux) && \old(waterLevel) == waterLevel)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 186]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 860]: Loop Invariant Derived loop invariant: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && waterLevel <= 0) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || !(1 == systemActive)) || ((pumpRunning == 0 && \old(waterLevel) == waterLevel) && pumpRunning == switchedOnBeforeTS))) && (((!(1 == systemActive) || !(\old(waterLevel) <= 2)) || ((pumpRunning == \old(pumpRunning) && (((!(pumpRunning == 0) && waterLevel <= 1) && 1 <= waterLevel) || ((pumpRunning == 0 && 2 <= waterLevel) && waterLevel <= 2))) && pumpRunning == switchedOnBeforeTS)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 838]: Loop Invariant Derived loop invariant: ((((!(1 == systemActive) || tmp == 0) || !(waterLevel <= 1)) || !(switchedOnBeforeTS == \old(pumpRunning))) && (((!(1 == systemActive) || !(waterLevel <= 2)) || switchedOnBeforeTS == 0) || !(switchedOnBeforeTS == \old(pumpRunning)))) && (((!(1 == systemActive) || !(waterLevel <= 2)) || pumpRunning == switchedOnBeforeTS) || !(switchedOnBeforeTS == \old(pumpRunning))) - InvariantResult [Line: 734]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 695]: Loop Invariant Derived loop invariant: (((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || ((((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && ((\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)) || \old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 0 || waterLevel + 1 <= \old(waterLevel)))) || !(\old(waterLevel) <= 2)) || ((((pumpRunning == \old(pumpRunning) && 1 == systemActive) && tmp == waterLevel) && ((!(0 < \old(waterLevel)) && \old(waterLevel) == waterLevel) || (\old(waterLevel) == waterLevel + 1 && 0 < \old(waterLevel)))) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && (((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || (((1 == systemActive && tmp == waterLevel) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || !(\old(waterLevel) <= 2))) && (((!(\old(waterLevel) <= 1) || !(\old(pumpRunning) == 0)) || (pumpRunning == 0 && pumpRunning == switchedOnBeforeTS)) || !(1 == systemActive))) && (((((!(1 == systemActive) || (((!(switchedOnBeforeTS == 0) && pumpRunning == 0) && tmp == waterLevel) && waterLevel == 1)) || ((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && 1 == systemActive) && tmp == waterLevel) && pumpRunning == switchedOnBeforeTS)) || (((1 == systemActive && tmp == waterLevel) && \old(waterLevel) == waterLevel) && (pumpRunning == \old(pumpRunning) || pumpRunning == 1))) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel))) - InvariantResult [Line: 735]: Loop Invariant Derived loop invariant: (((2 == waterLevel && 1 == systemActive) && splverifierCounter == 0) || (((waterLevel <= 1 && 1 == systemActive) && splverifierCounter == 0) && pumpRunning == switchedOnBeforeTS)) || (((pumpRunning == 0 && waterLevel <= 1) && 1 == systemActive) && splverifierCounter == 0) - InvariantResult [Line: 99]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 186]: Loop Invariant Derived loop invariant: ((pumpRunning == 0 && 1 == systemActive) && waterLevel == 1) && pumpRunning == switchedOnBeforeTS - InvariantResult [Line: 725]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 864]: Loop Invariant Derived loop invariant: ((((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(\old(waterLevel) <= 1)) || !(1 == systemActive)) || (((pumpRunning == \old(pumpRunning) && (\old(waterLevel) == waterLevel + 1 || \old(waterLevel) == waterLevel)) && waterLevel <= 0) && pumpRunning == switchedOnBeforeTS)) || \old(switchedOnBeforeTS) == 0) && ((((!(\old(switchedOnBeforeTS) == \old(pumpRunning)) || !(1 == systemActive)) || \old(waterLevel) == waterLevel) || !(\old(waterLevel) <= 0)) || \old(switchedOnBeforeTS) == 0)) && (((((pumpRunning == \old(pumpRunning) && \old(waterLevel) == waterLevel + 1) && pumpRunning == switchedOnBeforeTS) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) || !(2 <= \old(waterLevel)))) && ((!(\old(pumpRunning) == 0) || !(1 == systemActive)) || !(\old(waterLevel) <= 2)) RESULT: Ultimate proved your program to be correct! [2022-11-23 14:22:00,684 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ded9ff3e-d166-4533-b2c3-1f78d7498f14/bin/utaipan-Q6hlc19bkW/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE