./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 592117a566b45deb7ab0407540eecbf2be0f732724f0529483f85e7a6864867a --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:15:38,268 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:15:38,427 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:15:38,435 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:15:38,436 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:15:38,494 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:15:38,495 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:15:38,496 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:15:38,498 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:15:38,506 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:15:38,507 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:15:38,508 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:15:38,508 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:15:38,509 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:15:38,510 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:15:38,510 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:15:38,511 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:15:38,511 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:15:38,512 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:15:38,512 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:15:38,513 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:15:38,514 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:15:38,514 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:15:38,515 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:15:38,515 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:15:38,516 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:15:38,516 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:15:38,517 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:15:38,517 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:15:38,518 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:15:38,518 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:15:38,519 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:15:38,519 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:15:38,519 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:15:38,520 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:15:38,520 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:15:38,520 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:15:38,521 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:15:38,521 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:15:38,521 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 592117a566b45deb7ab0407540eecbf2be0f732724f0529483f85e7a6864867a [2023-11-06 22:15:38,915 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:15:38,947 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:15:38,950 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:15:38,951 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:15:38,952 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:15:38,953 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c [2023-11-06 22:15:41,996 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:15:42,458 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:15:42,459 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c [2023-11-06 22:15:42,489 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/data/a604e9da9/3b08c737e1a347509cc6358042253364/FLAG77f40701c [2023-11-06 22:15:42,510 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/data/a604e9da9/3b08c737e1a347509cc6358042253364 [2023-11-06 22:15:42,518 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:15:42,520 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:15:42,522 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:15:42,523 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:15:42,529 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:15:42,530 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:15:42" (1/1) ... [2023-11-06 22:15:42,531 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@3c019e03 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:42, skipping insertion in model container [2023-11-06 22:15:42,531 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:15:42" (1/1) ... [2023-11-06 22:15:42,586 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:15:42,952 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c[19185,19198] [2023-11-06 22:15:42,959 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:15:42,979 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:15:42,994 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [49] [2023-11-06 22:15:42,996 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [309] [2023-11-06 22:15:42,997 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [379] [2023-11-06 22:15:42,997 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [417] [2023-11-06 22:15:42,998 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [783] [2023-11-06 22:15:42,998 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [879] [2023-11-06 22:15:42,998 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification1_spec.i","") [983] [2023-11-06 22:15:42,999 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [1010] [2023-11-06 22:15:43,120 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/sv-benchmarks/c/product-lines/minepump_spec1_product62.cil.c[19185,19198] [2023-11-06 22:15:43,129 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:15:43,158 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:15:43,159 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43 WrapperNode [2023-11-06 22:15:43,159 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:15:43,160 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:15:43,160 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:15:43,161 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:15:43,169 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,193 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,223 INFO L138 Inliner]: procedures = 58, calls = 105, calls flagged for inlining = 23, calls inlined = 20, statements flattened = 218 [2023-11-06 22:15:43,224 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:15:43,225 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:15:43,225 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:15:43,225 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:15:43,239 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,244 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,248 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,248 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,254 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,260 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,265 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,270 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,273 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:15:43,275 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:15:43,275 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:15:43,275 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:15:43,276 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (1/1) ... [2023-11-06 22:15:43,303 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:15:43,329 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:15:43,381 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:15:43,433 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:15:43,467 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:15:43,467 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:15:43,467 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:15:43,468 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:15:43,470 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:15:43,470 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2023-11-06 22:15:43,471 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2023-11-06 22:15:43,471 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:15:43,472 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:15:43,472 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:15:43,472 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:15:43,472 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:15:43,472 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:15:43,472 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:15:43,473 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:15:43,473 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2023-11-06 22:15:43,474 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2023-11-06 22:15:43,474 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-06 22:15:43,474 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-06 22:15:43,475 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:15:43,475 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:15:43,476 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:15:43,477 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:15:43,477 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:15:43,637 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:15:43,644 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:15:44,130 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:15:44,137 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:15:44,137 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:15:44,140 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:15:44 BoogieIcfgContainer [2023-11-06 22:15:44,140 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:15:44,143 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:15:44,143 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:15:44,147 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:15:44,147 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:15:42" (1/3) ... [2023-11-06 22:15:44,148 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@221da424 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:15:44, skipping insertion in model container [2023-11-06 22:15:44,148 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:15:43" (2/3) ... [2023-11-06 22:15:44,148 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@221da424 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:15:44, skipping insertion in model container [2023-11-06 22:15:44,149 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:15:44" (3/3) ... [2023-11-06 22:15:44,150 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec1_product62.cil.c [2023-11-06 22:15:44,175 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:15:44,175 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:15:44,234 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:15:44,242 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@5044296f, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:15:44,242 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:15:44,247 INFO L276 IsEmpty]: Start isEmpty. Operand has 109 states, 79 states have (on average 1.3670886075949367) internal successors, (108), 89 states have internal predecessors, (108), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) [2023-11-06 22:15:44,259 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2023-11-06 22:15:44,259 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:44,260 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:44,260 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:44,267 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:44,268 INFO L85 PathProgramCache]: Analyzing trace with hash 1689838058, now seen corresponding path program 1 times [2023-11-06 22:15:44,278 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:44,278 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [283943875] [2023-11-06 22:15:44,279 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:44,279 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:44,391 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:44,492 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-06 22:15:44,496 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:44,502 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:44,503 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:44,503 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [283943875] [2023-11-06 22:15:44,504 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [283943875] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:44,504 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:44,504 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:15:44,506 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [642260425] [2023-11-06 22:15:44,507 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:44,511 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:15:44,511 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:44,541 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:15:44,542 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:15:44,545 INFO L87 Difference]: Start difference. First operand has 109 states, 79 states have (on average 1.3670886075949367) internal successors, (108), 89 states have internal predecessors, (108), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) Second operand has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:44,586 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:44,586 INFO L93 Difference]: Finished difference Result 210 states and 283 transitions. [2023-11-06 22:15:44,587 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:15:44,589 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 23 [2023-11-06 22:15:44,589 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:44,598 INFO L225 Difference]: With dead ends: 210 [2023-11-06 22:15:44,598 INFO L226 Difference]: Without dead ends: 100 [2023-11-06 22:15:44,602 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:15:44,606 INFO L413 NwaCegarLoop]: 138 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 138 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:44,607 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 138 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:15:44,623 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 100 states. [2023-11-06 22:15:44,654 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 100 to 100. [2023-11-06 22:15:44,655 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 100 states, 72 states have (on average 1.3055555555555556) internal successors, (94), 81 states have internal predecessors, (94), 18 states have call successors, (18), 10 states have call predecessors, (18), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2023-11-06 22:15:44,659 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 100 states to 100 states and 129 transitions. [2023-11-06 22:15:44,661 INFO L78 Accepts]: Start accepts. Automaton has 100 states and 129 transitions. Word has length 23 [2023-11-06 22:15:44,661 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:44,661 INFO L495 AbstractCegarLoop]: Abstraction has 100 states and 129 transitions. [2023-11-06 22:15:44,662 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 9.5) internal successors, (19), 2 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:44,662 INFO L276 IsEmpty]: Start isEmpty. Operand 100 states and 129 transitions. [2023-11-06 22:15:44,665 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2023-11-06 22:15:44,665 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:44,666 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:44,666 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:15:44,666 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:44,667 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:44,668 INFO L85 PathProgramCache]: Analyzing trace with hash 1112714422, now seen corresponding path program 1 times [2023-11-06 22:15:44,668 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:44,668 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [337713869] [2023-11-06 22:15:44,668 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:44,669 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:44,696 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:44,883 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2023-11-06 22:15:44,886 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:44,889 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:44,890 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:44,890 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [337713869] [2023-11-06 22:15:44,890 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [337713869] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:44,891 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:44,891 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:15:44,891 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1157543758] [2023-11-06 22:15:44,892 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:44,893 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:15:44,893 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:44,894 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:15:44,895 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:15:44,895 INFO L87 Difference]: Start difference. First operand 100 states and 129 transitions. Second operand has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:44,924 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:44,924 INFO L93 Difference]: Finished difference Result 165 states and 213 transitions. [2023-11-06 22:15:44,925 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:15:44,925 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 24 [2023-11-06 22:15:44,926 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:44,929 INFO L225 Difference]: With dead ends: 165 [2023-11-06 22:15:44,929 INFO L226 Difference]: Without dead ends: 91 [2023-11-06 22:15:44,931 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:15:44,933 INFO L413 NwaCegarLoop]: 116 mSDtfsCounter, 13 mSDsluCounter, 99 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 215 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:44,934 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 215 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:15:44,936 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 91 states. [2023-11-06 22:15:44,951 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 91 to 91. [2023-11-06 22:15:44,952 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 66 states have (on average 1.3181818181818181) internal successors, (87), 75 states have internal predecessors, (87), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2023-11-06 22:15:44,955 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 117 transitions. [2023-11-06 22:15:44,955 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 117 transitions. Word has length 24 [2023-11-06 22:15:44,956 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:44,956 INFO L495 AbstractCegarLoop]: Abstraction has 91 states and 117 transitions. [2023-11-06 22:15:44,956 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.666666666666667) internal successors, (20), 3 states have internal predecessors, (20), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:44,956 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 117 transitions. [2023-11-06 22:15:44,958 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 30 [2023-11-06 22:15:44,959 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:44,959 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:44,962 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:15:44,962 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:44,964 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:44,965 INFO L85 PathProgramCache]: Analyzing trace with hash -1697557311, now seen corresponding path program 1 times [2023-11-06 22:15:44,966 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:44,970 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [991280625] [2023-11-06 22:15:44,971 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:44,972 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:45,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,233 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:45,238 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,244 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:45,246 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:45,246 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [991280625] [2023-11-06 22:15:45,247 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [991280625] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:45,247 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:45,247 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:15:45,248 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1943556857] [2023-11-06 22:15:45,248 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:45,249 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:15:45,249 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:45,249 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:15:45,250 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:15:45,250 INFO L87 Difference]: Start difference. First operand 91 states and 117 transitions. Second operand has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:45,415 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:45,415 INFO L93 Difference]: Finished difference Result 175 states and 228 transitions. [2023-11-06 22:15:45,421 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:15:45,422 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 29 [2023-11-06 22:15:45,422 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:45,438 INFO L225 Difference]: With dead ends: 175 [2023-11-06 22:15:45,439 INFO L226 Difference]: Without dead ends: 91 [2023-11-06 22:15:45,440 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:15:45,442 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 142 mSDsluCounter, 188 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 142 SdHoareTripleChecker+Valid, 298 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:45,448 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [142 Valid, 298 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:15:45,449 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 91 states. [2023-11-06 22:15:45,471 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 91 to 91. [2023-11-06 22:15:45,474 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 91 states, 66 states have (on average 1.303030303030303) internal successors, (86), 75 states have internal predecessors, (86), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2023-11-06 22:15:45,477 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 91 states to 91 states and 116 transitions. [2023-11-06 22:15:45,485 INFO L78 Accepts]: Start accepts. Automaton has 91 states and 116 transitions. Word has length 29 [2023-11-06 22:15:45,485 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:45,485 INFO L495 AbstractCegarLoop]: Abstraction has 91 states and 116 transitions. [2023-11-06 22:15:45,486 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.2) internal successors, (26), 5 states have internal predecessors, (26), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:15:45,486 INFO L276 IsEmpty]: Start isEmpty. Operand 91 states and 116 transitions. [2023-11-06 22:15:45,489 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2023-11-06 22:15:45,489 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:45,489 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:45,490 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:15:45,490 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:45,491 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:45,491 INFO L85 PathProgramCache]: Analyzing trace with hash -189961352, now seen corresponding path program 1 times [2023-11-06 22:15:45,493 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:45,493 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [84943004] [2023-11-06 22:15:45,493 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:45,494 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:45,536 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,715 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:45,718 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,734 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:45,740 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,773 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:45,774 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,779 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2023-11-06 22:15:45,782 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:45,785 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:45,786 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:45,786 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [84943004] [2023-11-06 22:15:45,786 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [84943004] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:45,787 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:45,787 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:15:45,787 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [445723147] [2023-11-06 22:15:45,788 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:45,789 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:15:45,790 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:45,791 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:15:45,791 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:15:45,791 INFO L87 Difference]: Start difference. First operand 91 states and 116 transitions. Second operand has 5 states, 5 states have (on average 7.0) internal successors, (35), 5 states have internal predecessors, (35), 3 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:15:46,194 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:46,194 INFO L93 Difference]: Finished difference Result 261 states and 330 transitions. [2023-11-06 22:15:46,195 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:15:46,195 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 5 states have internal predecessors, (35), 3 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) Word has length 44 [2023-11-06 22:15:46,196 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:46,198 INFO L225 Difference]: With dead ends: 261 [2023-11-06 22:15:46,198 INFO L226 Difference]: Without dead ends: 177 [2023-11-06 22:15:46,200 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:15:46,201 INFO L413 NwaCegarLoop]: 120 mSDtfsCounter, 198 mSDsluCounter, 172 mSDsCounter, 0 mSdLazyCounter, 143 mSolverCounterSat, 77 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 200 SdHoareTripleChecker+Valid, 292 SdHoareTripleChecker+Invalid, 220 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 77 IncrementalHoareTripleChecker+Valid, 143 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:46,202 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [200 Valid, 292 Invalid, 220 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [77 Valid, 143 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:15:46,204 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 177 states. [2023-11-06 22:15:46,253 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 177 to 171. [2023-11-06 22:15:46,254 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 171 states, 125 states have (on average 1.232) internal successors, (154), 134 states have internal predecessors, (154), 22 states have call successors, (22), 18 states have call predecessors, (22), 23 states have return successors, (29), 24 states have call predecessors, (29), 22 states have call successors, (29) [2023-11-06 22:15:46,262 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 171 states to 171 states and 205 transitions. [2023-11-06 22:15:46,262 INFO L78 Accepts]: Start accepts. Automaton has 171 states and 205 transitions. Word has length 44 [2023-11-06 22:15:46,262 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:46,263 INFO L495 AbstractCegarLoop]: Abstraction has 171 states and 205 transitions. [2023-11-06 22:15:46,263 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.0) internal successors, (35), 5 states have internal predecessors, (35), 3 states have call successors, (5), 3 states have call predecessors, (5), 3 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:15:46,264 INFO L276 IsEmpty]: Start isEmpty. Operand 171 states and 205 transitions. [2023-11-06 22:15:46,269 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 51 [2023-11-06 22:15:46,269 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:46,270 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:46,270 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:15:46,270 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:46,271 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:46,272 INFO L85 PathProgramCache]: Analyzing trace with hash 963666416, now seen corresponding path program 1 times [2023-11-06 22:15:46,272 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:46,272 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [827925682] [2023-11-06 22:15:46,272 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:46,273 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:46,304 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:46,482 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:46,492 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:46,507 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:46,511 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:46,520 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:46,521 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:46,525 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 41 [2023-11-06 22:15:46,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:46,532 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:46,533 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:46,533 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [827925682] [2023-11-06 22:15:46,533 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [827925682] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:46,534 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:46,534 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:15:46,536 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1142485370] [2023-11-06 22:15:46,536 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:46,537 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:15:46,537 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:46,538 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:15:46,538 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:15:46,538 INFO L87 Difference]: Start difference. First operand 171 states and 205 transitions. Second operand has 6 states, 6 states have (on average 6.833333333333333) internal successors, (41), 5 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:15:46,846 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:46,846 INFO L93 Difference]: Finished difference Result 183 states and 216 transitions. [2023-11-06 22:15:46,847 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2023-11-06 22:15:46,848 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.833333333333333) internal successors, (41), 5 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) Word has length 50 [2023-11-06 22:15:46,854 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:46,855 INFO L225 Difference]: With dead ends: 183 [2023-11-06 22:15:46,855 INFO L226 Difference]: Without dead ends: 181 [2023-11-06 22:15:46,857 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 11 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:15:46,865 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 143 mSDsluCounter, 286 mSDsCounter, 0 mSdLazyCounter, 179 mSolverCounterSat, 37 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 149 SdHoareTripleChecker+Valid, 380 SdHoareTripleChecker+Invalid, 216 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 37 IncrementalHoareTripleChecker+Valid, 179 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:46,865 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [149 Valid, 380 Invalid, 216 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [37 Valid, 179 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:15:46,866 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 181 states. [2023-11-06 22:15:46,899 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 181 to 171. [2023-11-06 22:15:46,900 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 171 states, 125 states have (on average 1.216) internal successors, (152), 134 states have internal predecessors, (152), 22 states have call successors, (22), 18 states have call predecessors, (22), 23 states have return successors, (29), 24 states have call predecessors, (29), 22 states have call successors, (29) [2023-11-06 22:15:46,901 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 171 states to 171 states and 203 transitions. [2023-11-06 22:15:46,904 INFO L78 Accepts]: Start accepts. Automaton has 171 states and 203 transitions. Word has length 50 [2023-11-06 22:15:46,906 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:46,906 INFO L495 AbstractCegarLoop]: Abstraction has 171 states and 203 transitions. [2023-11-06 22:15:46,906 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.833333333333333) internal successors, (41), 5 states have internal predecessors, (41), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:15:46,906 INFO L276 IsEmpty]: Start isEmpty. Operand 171 states and 203 transitions. [2023-11-06 22:15:46,911 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2023-11-06 22:15:46,911 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:46,911 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:46,912 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:15:46,912 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:46,913 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:46,913 INFO L85 PathProgramCache]: Analyzing trace with hash -158889570, now seen corresponding path program 1 times [2023-11-06 22:15:46,913 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:46,913 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [683419063] [2023-11-06 22:15:46,914 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:46,914 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:46,941 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,039 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:47,045 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,063 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:47,068 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,106 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:47,108 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,111 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:47,112 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,114 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2023-11-06 22:15:47,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,117 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:15:47,117 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:47,117 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [683419063] [2023-11-06 22:15:47,118 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [683419063] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:47,118 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:47,118 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:15:47,118 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [8346461] [2023-11-06 22:15:47,118 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:47,119 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:15:47,119 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:47,120 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:15:47,120 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:15:47,120 INFO L87 Difference]: Start difference. First operand 171 states and 203 transitions. Second operand has 6 states, 6 states have (on average 7.833333333333333) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2023-11-06 22:15:47,380 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:47,381 INFO L93 Difference]: Finished difference Result 345 states and 418 transitions. [2023-11-06 22:15:47,381 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:15:47,381 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.833333333333333) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 60 [2023-11-06 22:15:47,382 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:47,386 INFO L225 Difference]: With dead ends: 345 [2023-11-06 22:15:47,386 INFO L226 Difference]: Without dead ends: 181 [2023-11-06 22:15:47,387 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=29, Invalid=61, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:15:47,397 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 74 mSDsluCounter, 300 mSDsCounter, 0 mSdLazyCounter, 162 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 79 SdHoareTripleChecker+Valid, 392 SdHoareTripleChecker+Invalid, 188 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 162 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:47,399 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [79 Valid, 392 Invalid, 188 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 162 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:15:47,401 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 181 states. [2023-11-06 22:15:47,435 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 181 to 174. [2023-11-06 22:15:47,436 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 174 states, 128 states have (on average 1.2109375) internal successors, (155), 137 states have internal predecessors, (155), 22 states have call successors, (22), 18 states have call predecessors, (22), 23 states have return successors, (29), 24 states have call predecessors, (29), 22 states have call successors, (29) [2023-11-06 22:15:47,438 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 174 states to 174 states and 206 transitions. [2023-11-06 22:15:47,438 INFO L78 Accepts]: Start accepts. Automaton has 174 states and 206 transitions. Word has length 60 [2023-11-06 22:15:47,439 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:47,439 INFO L495 AbstractCegarLoop]: Abstraction has 174 states and 206 transitions. [2023-11-06 22:15:47,440 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.833333333333333) internal successors, (47), 5 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2023-11-06 22:15:47,440 INFO L276 IsEmpty]: Start isEmpty. Operand 174 states and 206 transitions. [2023-11-06 22:15:47,442 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2023-11-06 22:15:47,443 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:47,443 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:47,443 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:15:47,444 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:47,444 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:47,444 INFO L85 PathProgramCache]: Analyzing trace with hash 115870044, now seen corresponding path program 1 times [2023-11-06 22:15:47,444 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:47,445 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1808296531] [2023-11-06 22:15:47,445 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:47,445 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:47,466 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,545 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:47,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,594 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:47,600 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,649 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:47,651 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,657 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:47,658 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,664 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2023-11-06 22:15:47,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:47,668 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:15:47,669 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:47,669 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1808296531] [2023-11-06 22:15:47,669 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1808296531] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:47,669 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:47,670 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:15:47,670 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [600285752] [2023-11-06 22:15:47,670 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:47,672 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:15:47,672 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:47,673 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:15:47,673 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:15:47,674 INFO L87 Difference]: Start difference. First operand 174 states and 206 transitions. Second operand has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2023-11-06 22:15:47,942 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:47,942 INFO L93 Difference]: Finished difference Result 351 states and 424 transitions. [2023-11-06 22:15:47,942 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:15:47,943 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) Word has length 60 [2023-11-06 22:15:47,943 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:47,946 INFO L225 Difference]: With dead ends: 351 [2023-11-06 22:15:47,946 INFO L226 Difference]: Without dead ends: 184 [2023-11-06 22:15:47,947 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 24 GetRequests, 15 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=30, Invalid=80, Unknown=0, NotChecked=0, Total=110 [2023-11-06 22:15:47,950 INFO L413 NwaCegarLoop]: 92 mSDtfsCounter, 111 mSDsluCounter, 350 mSDsCounter, 0 mSdLazyCounter, 210 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 117 SdHoareTripleChecker+Valid, 442 SdHoareTripleChecker+Invalid, 236 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 210 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:47,951 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [117 Valid, 442 Invalid, 236 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 210 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:15:47,953 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 184 states. [2023-11-06 22:15:47,985 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 184 to 176. [2023-11-06 22:15:47,985 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 176 states, 130 states have (on average 1.2076923076923076) internal successors, (157), 139 states have internal predecessors, (157), 22 states have call successors, (22), 18 states have call predecessors, (22), 23 states have return successors, (29), 24 states have call predecessors, (29), 22 states have call successors, (29) [2023-11-06 22:15:47,987 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 176 states to 176 states and 208 transitions. [2023-11-06 22:15:47,987 INFO L78 Accepts]: Start accepts. Automaton has 176 states and 208 transitions. Word has length 60 [2023-11-06 22:15:47,989 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:47,989 INFO L495 AbstractCegarLoop]: Abstraction has 176 states and 208 transitions. [2023-11-06 22:15:47,989 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.714285714285714) internal successors, (47), 6 states have internal predecessors, (47), 2 states have call successors, (6), 2 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 2 states have call successors, (5) [2023-11-06 22:15:47,990 INFO L276 IsEmpty]: Start isEmpty. Operand 176 states and 208 transitions. [2023-11-06 22:15:47,990 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 61 [2023-11-06 22:15:47,990 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:47,991 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:47,991 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:15:47,992 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:47,992 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:47,992 INFO L85 PathProgramCache]: Analyzing trace with hash -2128113254, now seen corresponding path program 1 times [2023-11-06 22:15:47,992 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:47,993 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1545065327] [2023-11-06 22:15:47,993 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:47,993 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:48,011 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,076 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:48,081 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,096 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:48,100 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,114 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:48,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,118 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:48,119 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,121 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 51 [2023-11-06 22:15:48,122 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,124 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:15:48,124 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:48,124 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1545065327] [2023-11-06 22:15:48,125 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1545065327] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:48,125 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:48,125 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:15:48,125 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2140922407] [2023-11-06 22:15:48,126 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:48,126 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:15:48,126 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:48,127 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:15:48,127 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:15:48,127 INFO L87 Difference]: Start difference. First operand 176 states and 208 transitions. Second operand has 5 states, 5 states have (on average 9.4) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2023-11-06 22:15:48,433 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:48,433 INFO L93 Difference]: Finished difference Result 472 states and 588 transitions. [2023-11-06 22:15:48,434 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:15:48,434 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 9.4) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) Word has length 60 [2023-11-06 22:15:48,434 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:48,438 INFO L225 Difference]: With dead ends: 472 [2023-11-06 22:15:48,438 INFO L226 Difference]: Without dead ends: 303 [2023-11-06 22:15:48,439 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 13 SyntacticMatches, 1 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:15:48,440 INFO L413 NwaCegarLoop]: 134 mSDtfsCounter, 221 mSDsluCounter, 184 mSDsCounter, 0 mSdLazyCounter, 160 mSolverCounterSat, 70 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 229 SdHoareTripleChecker+Valid, 318 SdHoareTripleChecker+Invalid, 230 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 70 IncrementalHoareTripleChecker+Valid, 160 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:48,441 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [229 Valid, 318 Invalid, 230 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [70 Valid, 160 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:15:48,442 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 303 states. [2023-11-06 22:15:48,476 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 303 to 301. [2023-11-06 22:15:48,477 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 301 states, 223 states have (on average 1.201793721973094) internal successors, (268), 236 states have internal predecessors, (268), 39 states have call successors, (39), 35 states have call predecessors, (39), 38 states have return successors, (58), 40 states have call predecessors, (58), 39 states have call successors, (58) [2023-11-06 22:15:48,480 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 301 states to 301 states and 365 transitions. [2023-11-06 22:15:48,480 INFO L78 Accepts]: Start accepts. Automaton has 301 states and 365 transitions. Word has length 60 [2023-11-06 22:15:48,480 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:48,481 INFO L495 AbstractCegarLoop]: Abstraction has 301 states and 365 transitions. [2023-11-06 22:15:48,481 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 9.4) internal successors, (47), 4 states have internal predecessors, (47), 4 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 3 states have call predecessors, (5), 4 states have call successors, (5) [2023-11-06 22:15:48,481 INFO L276 IsEmpty]: Start isEmpty. Operand 301 states and 365 transitions. [2023-11-06 22:15:48,482 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 65 [2023-11-06 22:15:48,482 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:48,483 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:48,483 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2023-11-06 22:15:48,483 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:48,483 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:48,484 INFO L85 PathProgramCache]: Analyzing trace with hash -183762560, now seen corresponding path program 1 times [2023-11-06 22:15:48,484 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:48,484 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [314835309] [2023-11-06 22:15:48,484 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:48,484 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:48,500 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,590 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:15:48,592 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,614 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2023-11-06 22:15:48,619 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,627 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:48,630 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,639 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:48,640 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,643 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:48,644 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,646 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2023-11-06 22:15:48,647 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:48,669 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2023-11-06 22:15:48,669 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:48,669 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [314835309] [2023-11-06 22:15:48,669 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [314835309] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:48,670 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:15:48,670 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2023-11-06 22:15:48,670 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1027918594] [2023-11-06 22:15:48,670 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:48,671 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-06 22:15:48,671 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:48,673 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-06 22:15:48,673 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:15:48,673 INFO L87 Difference]: Start difference. First operand 301 states and 365 transitions. Second operand has 8 states, 8 states have (on average 6.375) internal successors, (51), 5 states have internal predecessors, (51), 2 states have call successors, (7), 4 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 2 states have call successors, (6) [2023-11-06 22:15:49,524 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:49,525 INFO L93 Difference]: Finished difference Result 943 states and 1174 transitions. [2023-11-06 22:15:49,525 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 23 states. [2023-11-06 22:15:49,525 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.375) internal successors, (51), 5 states have internal predecessors, (51), 2 states have call successors, (7), 4 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 2 states have call successors, (6) Word has length 64 [2023-11-06 22:15:49,527 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:49,533 INFO L225 Difference]: With dead ends: 943 [2023-11-06 22:15:49,533 INFO L226 Difference]: Without dead ends: 649 [2023-11-06 22:15:49,535 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 37 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 23 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 128 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=133, Invalid=467, Unknown=0, NotChecked=0, Total=600 [2023-11-06 22:15:49,538 INFO L413 NwaCegarLoop]: 58 mSDtfsCounter, 352 mSDsluCounter, 262 mSDsCounter, 0 mSdLazyCounter, 459 mSolverCounterSat, 146 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 358 SdHoareTripleChecker+Valid, 320 SdHoareTripleChecker+Invalid, 605 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 146 IncrementalHoareTripleChecker+Valid, 459 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:49,538 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [358 Valid, 320 Invalid, 605 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [146 Valid, 459 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2023-11-06 22:15:49,540 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 649 states. [2023-11-06 22:15:49,637 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 649 to 637. [2023-11-06 22:15:49,639 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 637 states, 466 states have (on average 1.1759656652360515) internal successors, (548), 497 states have internal predecessors, (548), 88 states have call successors, (88), 70 states have call predecessors, (88), 82 states have return successors, (137), 90 states have call predecessors, (137), 88 states have call successors, (137) [2023-11-06 22:15:49,645 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 637 states to 637 states and 773 transitions. [2023-11-06 22:15:49,646 INFO L78 Accepts]: Start accepts. Automaton has 637 states and 773 transitions. Word has length 64 [2023-11-06 22:15:49,646 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:49,646 INFO L495 AbstractCegarLoop]: Abstraction has 637 states and 773 transitions. [2023-11-06 22:15:49,646 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.375) internal successors, (51), 5 states have internal predecessors, (51), 2 states have call successors, (7), 4 states have call predecessors, (7), 2 states have return successors, (6), 3 states have call predecessors, (6), 2 states have call successors, (6) [2023-11-06 22:15:49,647 INFO L276 IsEmpty]: Start isEmpty. Operand 637 states and 773 transitions. [2023-11-06 22:15:49,648 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 69 [2023-11-06 22:15:49,648 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:49,649 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:49,649 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2023-11-06 22:15:49,649 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:49,650 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:49,650 INFO L85 PathProgramCache]: Analyzing trace with hash 2085614340, now seen corresponding path program 1 times [2023-11-06 22:15:49,650 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:49,650 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [274933964] [2023-11-06 22:15:49,651 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:49,651 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:49,669 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:49,807 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:15:49,808 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:49,817 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2023-11-06 22:15:49,821 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:49,841 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2023-11-06 22:15:49,846 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:49,891 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:49,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:49,969 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:49,971 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:50,073 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:50,076 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:50,097 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 59 [2023-11-06 22:15:50,098 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:50,100 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2023-11-06 22:15:50,100 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:50,100 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [274933964] [2023-11-06 22:15:50,100 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [274933964] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:15:50,101 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [679640924] [2023-11-06 22:15:50,101 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:50,101 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:15:50,101 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:15:50,107 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:15:50,135 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-06 22:15:50,222 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:50,243 INFO L262 TraceCheckSpWp]: Trace formula consists of 253 conjuncts, 9 conjunts are in the unsatisfiable core [2023-11-06 22:15:50,251 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:15:50,557 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 3 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:15:50,557 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:15:50,558 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [679640924] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:50,558 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:15:50,558 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2023-11-06 22:15:50,558 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1572090421] [2023-11-06 22:15:50,559 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:50,559 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-06 22:15:50,559 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:50,560 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-06 22:15:50,562 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=56, Invalid=324, Unknown=0, NotChecked=0, Total=380 [2023-11-06 22:15:50,563 INFO L87 Difference]: Start difference. First operand 637 states and 773 transitions. Second operand has 8 states, 8 states have (on average 6.625) internal successors, (53), 6 states have internal predecessors, (53), 3 states have call successors, (8), 3 states have call predecessors, (8), 5 states have return successors, (7), 5 states have call predecessors, (7), 3 states have call successors, (7) [2023-11-06 22:15:50,823 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:50,823 INFO L93 Difference]: Finished difference Result 1242 states and 1513 transitions. [2023-11-06 22:15:50,824 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:15:50,824 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.625) internal successors, (53), 6 states have internal predecessors, (53), 3 states have call successors, (8), 3 states have call predecessors, (8), 5 states have return successors, (7), 5 states have call predecessors, (7), 3 states have call successors, (7) Word has length 68 [2023-11-06 22:15:50,825 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:50,829 INFO L225 Difference]: With dead ends: 1242 [2023-11-06 22:15:50,829 INFO L226 Difference]: Without dead ends: 612 [2023-11-06 22:15:50,832 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 93 GetRequests, 75 SyntacticMatches, 0 SemanticMatches, 18 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 37 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=56, Invalid=324, Unknown=0, NotChecked=0, Total=380 [2023-11-06 22:15:50,832 INFO L413 NwaCegarLoop]: 210 mSDtfsCounter, 73 mSDsluCounter, 456 mSDsCounter, 0 mSdLazyCounter, 181 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 75 SdHoareTripleChecker+Valid, 666 SdHoareTripleChecker+Invalid, 182 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 181 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:50,834 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [75 Valid, 666 Invalid, 182 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 181 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:15:50,835 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 612 states. [2023-11-06 22:15:50,922 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 612 to 612. [2023-11-06 22:15:50,923 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 612 states, 447 states have (on average 1.1633109619686801) internal successors, (520), 477 states have internal predecessors, (520), 86 states have call successors, (86), 68 states have call predecessors, (86), 78 states have return successors, (122), 86 states have call predecessors, (122), 86 states have call successors, (122) [2023-11-06 22:15:50,928 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 612 states to 612 states and 728 transitions. [2023-11-06 22:15:50,929 INFO L78 Accepts]: Start accepts. Automaton has 612 states and 728 transitions. Word has length 68 [2023-11-06 22:15:50,929 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:50,929 INFO L495 AbstractCegarLoop]: Abstraction has 612 states and 728 transitions. [2023-11-06 22:15:50,929 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.625) internal successors, (53), 6 states have internal predecessors, (53), 3 states have call successors, (8), 3 states have call predecessors, (8), 5 states have return successors, (7), 5 states have call predecessors, (7), 3 states have call successors, (7) [2023-11-06 22:15:50,930 INFO L276 IsEmpty]: Start isEmpty. Operand 612 states and 728 transitions. [2023-11-06 22:15:50,932 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 124 [2023-11-06 22:15:50,932 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:15:50,933 INFO L195 NwaCegarLoop]: trace histogram [4, 4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:50,946 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-06 22:15:51,146 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2023-11-06 22:15:51,147 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:15:51,148 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:15:51,148 INFO L85 PathProgramCache]: Analyzing trace with hash 971206854, now seen corresponding path program 1 times [2023-11-06 22:15:51,148 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:15:51,148 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [193799668] [2023-11-06 22:15:51,149 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:51,149 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:15:51,172 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,332 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:15:51,334 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,349 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:15:51,353 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,369 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:15:51,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,377 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:51,380 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,383 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:15:51,385 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,386 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:51,387 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,388 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 34 [2023-11-06 22:15:51,389 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,400 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 70 [2023-11-06 22:15:51,401 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,418 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2023-11-06 22:15:51,420 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,493 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:15:51,499 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,544 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 94 [2023-11-06 22:15:51,547 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:15:51,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,552 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:15:51,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,554 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 114 [2023-11-06 22:15:51,555 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,556 INFO L134 CoverageAnalysis]: Checked inductivity of 49 backedges. 18 proven. 3 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2023-11-06 22:15:51,557 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:15:51,557 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [193799668] [2023-11-06 22:15:51,557 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [193799668] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:15:51,557 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1354210655] [2023-11-06 22:15:51,558 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:15:51,558 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:15:51,558 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:15:51,559 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:15:51,583 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-06 22:15:51,687 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:15:51,690 INFO L262 TraceCheckSpWp]: Trace formula consists of 385 conjuncts, 9 conjunts are in the unsatisfiable core [2023-11-06 22:15:51,696 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:15:51,848 INFO L134 CoverageAnalysis]: Checked inductivity of 49 backedges. 40 proven. 0 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2023-11-06 22:15:51,849 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:15:51,849 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1354210655] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:15:51,849 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:15:51,849 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [15] total 20 [2023-11-06 22:15:51,850 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1854307840] [2023-11-06 22:15:51,850 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:15:51,850 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-06 22:15:51,851 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:15:51,851 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-06 22:15:51,852 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=51, Invalid=329, Unknown=0, NotChecked=0, Total=380 [2023-11-06 22:15:51,852 INFO L87 Difference]: Start difference. First operand 612 states and 728 transitions. Second operand has 8 states, 8 states have (on average 11.0) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (15), 3 states have call predecessors, (15), 5 states have return successors, (14), 5 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:15:52,030 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:15:52,030 INFO L93 Difference]: Finished difference Result 1045 states and 1259 transitions. [2023-11-06 22:15:52,030 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:15:52,031 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 11.0) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (15), 3 states have call predecessors, (15), 5 states have return successors, (14), 5 states have call predecessors, (14), 3 states have call successors, (14) Word has length 123 [2023-11-06 22:15:52,031 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:15:52,032 INFO L225 Difference]: With dead ends: 1045 [2023-11-06 22:15:52,032 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:15:52,036 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 162 GetRequests, 142 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 47 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=63, Invalid=399, Unknown=0, NotChecked=0, Total=462 [2023-11-06 22:15:52,036 INFO L413 NwaCegarLoop]: 190 mSDtfsCounter, 63 mSDsluCounter, 756 mSDsCounter, 0 mSdLazyCounter, 113 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 66 SdHoareTripleChecker+Valid, 946 SdHoareTripleChecker+Invalid, 115 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 113 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:15:52,037 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [66 Valid, 946 Invalid, 115 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 113 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:15:52,037 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:15:52,037 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:15:52,038 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:15:52,038 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:15:52,038 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 123 [2023-11-06 22:15:52,038 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:15:52,038 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:15:52,039 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 11.0) internal successors, (88), 6 states have internal predecessors, (88), 3 states have call successors, (15), 3 states have call predecessors, (15), 5 states have return successors, (14), 5 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:15:52,039 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:15:52,039 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:15:52,041 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:15:52,052 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-06 22:15:52,247 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:15:52,249 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:15:56,098 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 199 206) no Hoare annotation was computed. [2023-11-06 22:15:56,099 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 199 206) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse1 (= |old(~pumpRunning~0)| 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) .cse2) (or .cse0 .cse1 .cse2 (< ~methaneLevelCritical~0 1)))) [2023-11-06 22:15:56,099 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 199 206) no Hoare annotation was computed. [2023-11-06 22:15:56,099 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 89 95) no Hoare annotation was computed. [2023-11-06 22:15:56,099 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 89 95) the Hoare annotation is: true [2023-11-06 22:15:56,099 INFO L899 garLoopResultBuilder]: For program point L291-2(lines 291 295) no Hoare annotation was computed. [2023-11-06 22:15:56,100 INFO L895 garLoopResultBuilder]: At program point isLowWaterSensorDry_returnLabel#1(lines 974 982) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse2 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2023-11-06 22:15:56,100 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 123 147) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 0)) .cse0))) [2023-11-06 22:15:56,100 INFO L895 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse2 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2023-11-06 22:15:56,100 INFO L895 garLoopResultBuilder]: At program point L133(line 133) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse2 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2023-11-06 22:15:56,100 INFO L899 garLoopResultBuilder]: For program point L131(lines 131 139) no Hoare annotation was computed. [2023-11-06 22:15:56,101 INFO L899 garLoopResultBuilder]: For program point L127(lines 127 144) no Hoare annotation was computed. [2023-11-06 22:15:56,101 INFO L895 garLoopResultBuilder]: At program point isLowWaterLevel_returnLabel#1(lines 282 300) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse2 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2023-11-06 22:15:56,101 INFO L895 garLoopResultBuilder]: At program point L142(line 142) the Hoare annotation is: (let ((.cse0 (= |old(~pumpRunning~0)| 0)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or (not .cse0) .cse1 .cse2 (< ~methaneLevelCritical~0 1)) (or .cse0 .cse3 .cse2) (or .cse1 .cse3 .cse2))) [2023-11-06 22:15:56,101 INFO L899 garLoopResultBuilder]: For program point L142-1(lines 123 147) no Hoare annotation was computed. [2023-11-06 22:15:56,101 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 123 147) no Hoare annotation was computed. [2023-11-06 22:15:56,101 INFO L899 garLoopResultBuilder]: For program point L291(lines 291 295) no Hoare annotation was computed. [2023-11-06 22:15:56,101 INFO L899 garLoopResultBuilder]: For program point L911-1(lines 907 918) no Hoare annotation was computed. [2023-11-06 22:15:56,102 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 907 918) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (<= 1 ~methaneLevelCritical~0) (not (= ~pumpRunning~0 0)) (< |old(~methaneLevelCritical~0)| 1) .cse0) (or (not (= |old(~methaneLevelCritical~0)| 0)) (= ~methaneLevelCritical~0 0) .cse0))) [2023-11-06 22:15:56,102 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 907 918) no Hoare annotation was computed. [2023-11-06 22:15:56,102 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 785 814) no Hoare annotation was computed. [2023-11-06 22:15:56,102 INFO L899 garLoopResultBuilder]: For program point L799(lines 799 803) no Hoare annotation was computed. [2023-11-06 22:15:56,102 INFO L902 garLoopResultBuilder]: At program point L799-1(lines 799 803) the Hoare annotation is: true [2023-11-06 22:15:56,102 INFO L899 garLoopResultBuilder]: For program point L796(line 796) no Hoare annotation was computed. [2023-11-06 22:15:56,102 INFO L902 garLoopResultBuilder]: At program point L795-2(lines 795 809) the Hoare annotation is: true [2023-11-06 22:15:56,102 INFO L902 garLoopResultBuilder]: At program point L791(line 791) the Hoare annotation is: true [2023-11-06 22:15:56,102 INFO L899 garLoopResultBuilder]: For program point L791-1(line 791) no Hoare annotation was computed. [2023-11-06 22:15:56,103 INFO L902 garLoopResultBuilder]: At program point L810(lines 785 814) the Hoare annotation is: true [2023-11-06 22:15:56,103 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 785 814) the Hoare annotation is: true [2023-11-06 22:15:56,103 INFO L899 garLoopResultBuilder]: For program point L806(line 806) no Hoare annotation was computed. [2023-11-06 22:15:56,103 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 919 927) the Hoare annotation is: true [2023-11-06 22:15:56,103 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 919 927) no Hoare annotation was computed. [2023-11-06 22:15:56,103 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 919 927) no Hoare annotation was computed. [2023-11-06 22:15:56,103 INFO L899 garLoopResultBuilder]: For program point L993(lines 993 1006) no Hoare annotation was computed. [2023-11-06 22:15:56,104 INFO L895 garLoopResultBuilder]: At program point L993-1(lines 985 1009) the Hoare annotation is: (let ((.cse4 (= 0 ~systemActive~0)) (.cse1 (= |old(~pumpRunning~0)| 0))) (let ((.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not .cse1)) (.cse0 (= ~pumpRunning~0 0)) (.cse3 (not .cse4))) (and (or (and .cse0 .cse1 .cse2 .cse3) .cse4 (and .cse5 .cse0 .cse3) (< ~methaneLevelCritical~0 1)) (let ((.cse6 (= |timeShift___utac_acc__Specification1_spec__1_~tmp~11#1| 0))) (or (and .cse6 (<= 2 ~waterLevel~0) .cse2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse5 .cse6) (not (= ~methaneLevelCritical~0 0)) .cse4 (and .cse0 .cse6 .cse1 .cse2 .cse3) (and .cse5 .cse0 .cse6 .cse3)))))) [2023-11-06 22:15:56,104 INFO L895 garLoopResultBuilder]: At program point L159(line 159) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or (and .cse0 (<= 1 |timeShift_processEnvironment_~tmp~2#1|) .cse1) .cse2 (< ~methaneLevelCritical~0 1)) (or (and .cse0 .cse1) (not (= ~methaneLevelCritical~0 0)) .cse2))) [2023-11-06 22:15:56,104 INFO L895 garLoopResultBuilder]: At program point L155(line 155) the Hoare annotation is: (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 0)))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (< ~methaneLevelCritical~0 1)) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1))) [2023-11-06 22:15:56,104 INFO L899 garLoopResultBuilder]: For program point L155-1(line 155) no Hoare annotation was computed. [2023-11-06 22:15:56,105 INFO L895 garLoopResultBuilder]: At program point L168(line 168) the Hoare annotation is: (let ((.cse0 (and (= ~pumpRunning~0 0) (= |old(~pumpRunning~0)| 0) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1) (or .cse0 .cse1 (< ~methaneLevelCritical~0 1)))) [2023-11-06 22:15:56,105 INFO L895 garLoopResultBuilder]: At program point L168-1(lines 149 173) the Hoare annotation is: (let ((.cse4 (= |old(~pumpRunning~0)| 0))) (let ((.cse2 (not .cse4)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (= 0 ~systemActive~0))) (and (or (and .cse0 .cse1) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse2) (and .cse2 .cse0) (not (= ~methaneLevelCritical~0 0)) (and (<= 2 ~waterLevel~0) .cse1) .cse3) (or (and (<= 1 |timeShift_processEnvironment_~tmp~2#1|) .cse2 .cse0) (and .cse0 .cse4 .cse1) .cse3 (< ~methaneLevelCritical~0 1))))) [2023-11-06 22:15:56,105 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 65 88) no Hoare annotation was computed. [2023-11-06 22:15:56,105 INFO L899 garLoopResultBuilder]: For program point L69-1(lines 68 87) no Hoare annotation was computed. [2023-11-06 22:15:56,105 INFO L899 garLoopResultBuilder]: For program point L887(lines 887 891) no Hoare annotation was computed. [2023-11-06 22:15:56,105 INFO L899 garLoopResultBuilder]: For program point L1015(line 1015) no Hoare annotation was computed. [2023-11-06 22:15:56,106 INFO L895 garLoopResultBuilder]: At program point L887-2(lines 883 894) the Hoare annotation is: (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 0)))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (< ~methaneLevelCritical~0 1)) (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1))) [2023-11-06 22:15:56,106 INFO L895 garLoopResultBuilder]: At program point L991(line 991) the Hoare annotation is: (let ((.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse0 (and .cse5 .cse3)) (.cse2 (and .cse1 .cse5)) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1) .cse2 (not (= ~methaneLevelCritical~0 0)) (and (<= 2 ~waterLevel~0) .cse3) .cse4) (or .cse0 .cse2 .cse4 (< ~methaneLevelCritical~0 1))))) [2023-11-06 22:15:56,106 INFO L899 garLoopResultBuilder]: For program point L991-1(line 991) no Hoare annotation was computed. [2023-11-06 22:15:56,106 INFO L899 garLoopResultBuilder]: For program point L157(lines 157 165) no Hoare annotation was computed. [2023-11-06 22:15:56,106 INFO L899 garLoopResultBuilder]: For program point L153(lines 153 170) no Hoare annotation was computed. [2023-11-06 22:15:56,106 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 1011 1018) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (< ~methaneLevelCritical~0 1)) (or (not (= ~methaneLevelCritical~0 0)) .cse0))) [2023-11-06 22:15:56,107 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 65 88) the Hoare annotation is: (let ((.cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |old(~waterLevel~0)| ~waterLevel~0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1) (or .cse0 .cse1 (< ~methaneLevelCritical~0 1)))) [2023-11-06 22:15:56,107 INFO L899 garLoopResultBuilder]: For program point L76-1(lines 76 82) no Hoare annotation was computed. [2023-11-06 22:15:56,107 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 65 88) no Hoare annotation was computed. [2023-11-06 22:15:56,116 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 218 226) the Hoare annotation is: (let ((.cse2 (= 0 ~systemActive~0))) (and (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |timeShift_isPumpRunning_#res#1| 0))) (or (and .cse0 .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (and (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) .cse2 (< ~methaneLevelCritical~0 1))) (or (not (= ~methaneLevelCritical~0 0)) .cse2))) [2023-11-06 22:15:56,116 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 1015) no Hoare annotation was computed. [2023-11-06 22:15:56,116 INFO L899 garLoopResultBuilder]: For program point L997(lines 997 1003) no Hoare annotation was computed. [2023-11-06 22:15:56,116 INFO L895 garLoopResultBuilder]: At program point L163(line 163) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or .cse0 (< ~methaneLevelCritical~0 1)) (or (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 0))) (not (= ~methaneLevelCritical~0 0)) .cse0))) [2023-11-06 22:15:56,117 INFO L899 garLoopResultBuilder]: For program point L353(lines 353 366) no Hoare annotation was computed. [2023-11-06 22:15:56,117 INFO L895 garLoopResultBuilder]: At program point startSystem_returnLabel#1(lines 301 308) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3) (and (<= 1 ~methaneLevelCritical~0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:15:56,117 INFO L895 garLoopResultBuilder]: At program point L345(line 345) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and (= ~pumpRunning~0 0) (<= 1 ~methaneLevelCritical~0) .cse0 .cse1 .cse2 .cse3) (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:15:56,117 INFO L902 garLoopResultBuilder]: At program point L374(lines 313 378) the Hoare annotation is: true [2023-11-06 22:15:56,117 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 846 855) the Hoare annotation is: true [2023-11-06 22:15:56,118 INFO L899 garLoopResultBuilder]: For program point L333(lines 333 339) no Hoare annotation was computed. [2023-11-06 22:15:56,119 INFO L899 garLoopResultBuilder]: For program point L333-1(lines 333 339) no Hoare annotation was computed. [2023-11-06 22:15:56,120 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 394 400) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:15:56,120 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 856 878) the Hoare annotation is: true [2023-11-06 22:15:56,120 INFO L899 garLoopResultBuilder]: For program point L325(lines 325 329) no Hoare annotation was computed. [2023-11-06 22:15:56,120 INFO L899 garLoopResultBuilder]: For program point L866(lines 866 873) no Hoare annotation was computed. [2023-11-06 22:15:56,120 INFO L899 garLoopResultBuilder]: For program point L866-2(lines 866 873) no Hoare annotation was computed. [2023-11-06 22:15:56,120 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:15:56,121 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:15:56,121 INFO L895 garLoopResultBuilder]: At program point L371(lines 322 372) the Hoare annotation is: false [2023-11-06 22:15:56,121 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 839 845) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (= |ULTIMATE.start_main_~tmp~10#1| 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:15:56,121 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:15:56,121 INFO L899 garLoopResultBuilder]: For program point L343(lines 343 349) no Hoare annotation was computed. [2023-11-06 22:15:56,122 INFO L899 garLoopResultBuilder]: For program point L343-1(lines 343 349) no Hoare annotation was computed. [2023-11-06 22:15:56,122 INFO L895 garLoopResultBuilder]: At program point L368(lines 323 370) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and (= ~pumpRunning~0 0) (<= 1 ~methaneLevelCritical~0) .cse0 .cse1 .cse2 .cse3) (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:15:56,122 INFO L895 garLoopResultBuilder]: At program point L335(line 335) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and (= ~pumpRunning~0 0) (<= 1 ~methaneLevelCritical~0) .cse0 .cse1 .cse2 .cse3) (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:15:56,122 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:15:56,123 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 401 407) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:15:56,123 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 408 416) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~methaneLevelCritical~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:15:56,123 INFO L899 garLoopResultBuilder]: For program point L361(lines 361 365) no Hoare annotation was computed. [2023-11-06 22:15:56,123 INFO L895 garLoopResultBuilder]: At program point L361-2(lines 353 366) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~10#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and (= ~methaneLevelCritical~0 0) .cse0 .cse1 .cse2 .cse3) (and (<= 1 ~methaneLevelCritical~0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:15:56,123 INFO L899 garLoopResultBuilder]: For program point L324(lines 323 370) no Hoare annotation was computed. [2023-11-06 22:15:56,124 INFO L895 garLoopResultBuilder]: At program point L116(line 116) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 .cse2 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1 .cse2))) [2023-11-06 22:15:56,124 INFO L899 garLoopResultBuilder]: For program point L116-1(lines 97 121) no Hoare annotation was computed. [2023-11-06 22:15:56,124 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 97 121) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse0 (< ~methaneLevelCritical~0 1)) (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~methaneLevelCritical~0 0)) .cse0))) [2023-11-06 22:15:56,125 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 960 973) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0))) (let ((.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse4 (= |old(~pumpRunning~0)| 0)) (.cse0 (and .cse5 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))) (.cse2 (and .cse5 (<= 2 ~waterLevel~0))) (.cse3 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse1 .cse3) (or (not .cse4) .cse0 .cse2 .cse3 (< ~methaneLevelCritical~0 1))))) [2023-11-06 22:15:56,125 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 263 281) the Hoare annotation is: (let ((.cse2 (= ~pumpRunning~0 0)) (.cse0 (= |old(~pumpRunning~0)| 0)) (.cse4 (= 0 ~systemActive~0))) (let ((.cse1 (and .cse2 .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (not .cse4))) (.cse3 (<= 2 ~waterLevel~0))) (and (or (not .cse0) .cse1 (and .cse2 .cse3) .cse4 (< ~methaneLevelCritical~0 1)) (or .cse1 (not (= ~methaneLevelCritical~0 0)) (and .cse2 .cse3 .cse0) .cse4)))) [2023-11-06 22:15:56,125 INFO L899 garLoopResultBuilder]: For program point L189(lines 189 195) no Hoare annotation was computed. [2023-11-06 22:15:56,125 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 97 121) no Hoare annotation was computed. [2023-11-06 22:15:56,126 INFO L895 garLoopResultBuilder]: At program point L187(line 187) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse0 (= |old(~pumpRunning~0)| 0)) (.cse3 (= 0 ~systemActive~0))) (and (or (not .cse0) (and .cse1 .cse2) .cse3 (< ~methaneLevelCritical~0 1)) (or (not (= ~methaneLevelCritical~0 0)) (and .cse1 .cse2 .cse0) .cse3))) [2023-11-06 22:15:56,126 INFO L895 garLoopResultBuilder]: At program point L189-2(lines 182 198) the Hoare annotation is: (let ((.cse1 (= |old(~pumpRunning~0)| 0)) (.cse0 (<= 2 ~waterLevel~0)) (.cse3 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or (and (= ~pumpRunning~0 0) (<= ~methaneLevelCritical~0 |processEnvironment__wrappee__highWaterSensor_activatePump_~tmp~3#1|) .cse0) (not .cse1) .cse2 (< ~methaneLevelCritical~0 1)) (or .cse1 .cse3 .cse2) (or .cse0 .cse3 .cse2))) [2023-11-06 22:15:56,127 INFO L899 garLoopResultBuilder]: For program point L187-1(line 187) no Hoare annotation was computed. [2023-11-06 22:15:56,127 INFO L899 garLoopResultBuilder]: For program point L272(lines 272 276) no Hoare annotation was computed. [2023-11-06 22:15:56,127 INFO L895 garLoopResultBuilder]: At program point L111(line 111) the Hoare annotation is: (let ((.cse2 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) .cse2)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (= ~methaneLevelCritical~0 0)) .cse1) (or (not .cse2) .cse0 .cse1 (< ~methaneLevelCritical~0 1))))) [2023-11-06 22:15:56,127 INFO L899 garLoopResultBuilder]: For program point L272-2(lines 272 276) no Hoare annotation was computed. [2023-11-06 22:15:56,128 INFO L899 garLoopResultBuilder]: For program point L105(lines 105 113) no Hoare annotation was computed. [2023-11-06 22:15:56,128 INFO L899 garLoopResultBuilder]: For program point L101(lines 101 118) no Hoare annotation was computed. [2023-11-06 22:15:56,129 INFO L895 garLoopResultBuilder]: At program point activatePump__wrappee__lowWaterSensor_returnLabel#1(lines 174 181) the Hoare annotation is: (let ((.cse0 (= |old(~pumpRunning~0)| 0)) (.cse1 (not (= ~methaneLevelCritical~0 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or (not .cse0) .cse2 (< ~methaneLevelCritical~0 1)) (or (<= 2 ~waterLevel~0) .cse1 .cse2))) [2023-11-06 22:15:56,129 INFO L899 garLoopResultBuilder]: For program point L964(lines 964 970) no Hoare annotation was computed. [2023-11-06 22:15:56,129 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 895 906) no Hoare annotation was computed. [2023-11-06 22:15:56,129 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 895 906) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~pumpRunning~0 0)) .cse0 .cse1 (< ~methaneLevelCritical~0 1)) (or (not (= ~methaneLevelCritical~0 0)) .cse0 .cse1))) [2023-11-06 22:15:56,130 INFO L899 garLoopResultBuilder]: For program point L899-1(lines 895 906) no Hoare annotation was computed. [2023-11-06 22:15:56,130 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 207 217) no Hoare annotation was computed. [2023-11-06 22:15:56,130 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 207 217) the Hoare annotation is: true [2023-11-06 22:15:56,130 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 207 217) no Hoare annotation was computed. [2023-11-06 22:15:56,130 INFO L902 garLoopResultBuilder]: At program point L212(line 212) the Hoare annotation is: true [2023-11-06 22:15:56,130 INFO L899 garLoopResultBuilder]: For program point L212-1(line 212) no Hoare annotation was computed. [2023-11-06 22:15:56,134 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:15:56,136 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:15:56,208 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:15:56 BoogieIcfgContainer [2023-11-06 22:15:56,208 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:15:56,209 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:15:56,209 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:15:56,209 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:15:56,210 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:15:44" (3/4) ... [2023-11-06 22:15:56,212 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:15:56,218 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-06 22:15:56,219 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:15:56,219 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:15:56,219 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:15:56,219 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2023-11-06 22:15:56,219 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:15:56,220 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:15:56,220 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:15:56,220 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:15:56,220 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2023-11-06 22:15:56,239 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 18 nodes and edges [2023-11-06 22:15:56,239 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:15:56,240 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:15:56,241 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:15:56,242 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:15:56,278 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:15:56,279 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && (tmp == 1)) && !((0 == systemActive))) [2023-11-06 22:15:56,279 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && (1 <= methaneLevelCritical)) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:15:56,281 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && ((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,282 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) || ((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0)))) || (!((\old(pumpRunning) == 0)) && (pumpRunning == 0))) || !((methaneLevelCritical == 0))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && ((((((1 <= tmp) && !((\old(pumpRunning) == 0))) && (pumpRunning == 0)) || (((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) [2023-11-06 22:15:56,284 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive))) || (0 == systemActive)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && !((0 == systemActive)))) || (methaneLevelCritical < 1)) && ((((((((tmp == 0) && (2 <= waterLevel)) && (\old(waterLevel) == waterLevel)) || (((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) && (tmp == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive)) || (((((pumpRunning == 0) && (tmp == 0)) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (tmp == 0)) && !((0 == systemActive))))) [2023-11-06 22:15:56,285 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((1 <= methaneLevelCritical) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:15:56,286 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (\result == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (!((methaneLevelCritical == 0)) || (0 == systemActive))) [2023-11-06 22:15:56,287 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (methaneLevelCritical <= tmp)) && (2 <= waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,287 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,287 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,288 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && !((\result == 0))) || !((methaneLevelCritical == 0))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && ((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) [2023-11-06 22:15:56,292 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,292 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive))) || !((methaneLevelCritical == 0))) || (((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,363 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:15:56,363 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && (tmp == 1)) && !((0 == systemActive))) [2023-11-06 22:15:56,364 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && (1 <= methaneLevelCritical)) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:15:56,364 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && ((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,365 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) || ((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0)))) || (!((\old(pumpRunning) == 0)) && (pumpRunning == 0))) || !((methaneLevelCritical == 0))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && ((((((1 <= tmp) && !((\old(pumpRunning) == 0))) && (pumpRunning == 0)) || (((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) [2023-11-06 22:15:56,365 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive))) || (0 == systemActive)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && !((0 == systemActive)))) || (methaneLevelCritical < 1)) && ((((((((tmp == 0) && (2 <= waterLevel)) && (\old(waterLevel) == waterLevel)) || (((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) && (tmp == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive)) || (((((pumpRunning == 0) && (tmp == 0)) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (tmp == 0)) && !((0 == systemActive))))) [2023-11-06 22:15:56,366 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((1 <= methaneLevelCritical) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:15:56,366 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (\result == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (!((methaneLevelCritical == 0)) || (0 == systemActive))) [2023-11-06 22:15:56,366 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == 0) && (methaneLevelCritical <= tmp)) && (2 <= waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,367 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,367 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,367 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((pumpRunning == 0) && !((\result == 0))) || !((methaneLevelCritical == 0))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && ((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) [2023-11-06 22:15:56,368 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,370 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive))) || !((methaneLevelCritical == 0))) || (((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0))) || (0 == systemActive))) [2023-11-06 22:15:56,400 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:15:56,400 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:15:56,400 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:15:56,401 INFO L158 Benchmark]: Toolchain (without parser) took 13881.59ms. Allocated memory was 172.0MB in the beginning and 251.7MB in the end (delta: 79.7MB). Free memory was 141.5MB in the beginning and 129.0MB in the end (delta: 12.5MB). Peak memory consumption was 92.2MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,402 INFO L158 Benchmark]: CDTParser took 0.26ms. Allocated memory is still 125.8MB. Free memory is still 97.9MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:15:56,402 INFO L158 Benchmark]: CACSL2BoogieTranslator took 636.85ms. Allocated memory is still 172.0MB. Free memory was 141.5MB in the beginning and 121.8MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,403 INFO L158 Benchmark]: Boogie Procedure Inliner took 64.32ms. Allocated memory is still 172.0MB. Free memory was 121.8MB in the beginning and 118.9MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,403 INFO L158 Benchmark]: Boogie Preprocessor took 48.77ms. Allocated memory is still 172.0MB. Free memory was 118.9MB in the beginning and 117.6MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,404 INFO L158 Benchmark]: RCFGBuilder took 865.46ms. Allocated memory is still 172.0MB. Free memory was 117.6MB in the beginning and 124.8MB in the end (delta: -7.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,405 INFO L158 Benchmark]: TraceAbstraction took 12065.58ms. Allocated memory was 172.0MB in the beginning and 251.7MB in the end (delta: 79.7MB). Free memory was 124.0MB in the beginning and 137.4MB in the end (delta: -13.4MB). Peak memory consumption was 139.4MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,405 INFO L158 Benchmark]: Witness Printer took 191.49ms. Allocated memory is still 251.7MB. Free memory was 136.4MB in the beginning and 129.0MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2023-11-06 22:15:56,409 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.26ms. Allocated memory is still 125.8MB. Free memory is still 97.9MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 636.85ms. Allocated memory is still 172.0MB. Free memory was 141.5MB in the beginning and 121.8MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 64.32ms. Allocated memory is still 172.0MB. Free memory was 121.8MB in the beginning and 118.9MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 48.77ms. Allocated memory is still 172.0MB. Free memory was 118.9MB in the beginning and 117.6MB in the end (delta: 1.3MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 865.46ms. Allocated memory is still 172.0MB. Free memory was 117.6MB in the beginning and 124.8MB in the end (delta: -7.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * TraceAbstraction took 12065.58ms. Allocated memory was 172.0MB in the beginning and 251.7MB in the end (delta: 79.7MB). Free memory was 124.0MB in the beginning and 137.4MB in the end (delta: -13.4MB). Peak memory consumption was 139.4MB. Max. memory is 16.1GB. * Witness Printer took 191.49ms. Allocated memory is still 251.7MB. Free memory was 136.4MB in the beginning and 129.0MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [49] - GenericResultAtLocation [Line: 309]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [309] - GenericResultAtLocation [Line: 379]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [379] - GenericResultAtLocation [Line: 417]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [417] - GenericResultAtLocation [Line: 783]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [783] - GenericResultAtLocation [Line: 879]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [879] - GenericResultAtLocation [Line: 983]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification1_spec.i","") [983] - GenericResultAtLocation [Line: 1010]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [1010] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 1015]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 11 procedures, 109 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 11.9s, OverallIterations: 11, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1431 SdHoareTripleChecker+Valid, 1.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1390 mSDsluCounter, 4407 SdHoareTripleChecker+Invalid, 1.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3053 mSDsCounter, 394 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1617 IncrementalHoareTripleChecker+Invalid, 2011 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 394 mSolverCounterUnsat, 1354 mSDtfsCounter, 1617 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 418 GetRequests, 312 SyntacticMatches, 1 SemanticMatches, 105 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 237 ImplicationChecksByTransitivity, 1.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=637occurred in iteration=9, InterpolantAutomatonStates: 89, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 11 MinimizatonAttempts, 45 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 50 LocationsWithAnnotation, 1412 PreInvPairs, 1618 NumberOfFragments, 1366 HoareAnnotationTreeSize, 1412 FomulaSimplifications, 631 FormulaSimplificationTreeSizeReduction, 0.3s HoareSimplificationTime, 50 FomulaSimplificationsInter, 8514 FormulaSimplificationTreeSizeReductionInter, 3.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 3.0s InterpolantComputationTime, 796 NumberOfCodeBlocks, 796 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 783 ConstructedInterpolants, 0 QuantifiedInterpolants, 1507 SizeOfPredicates, 6 NumberOfNonLiveVariables, 638 ConjunctsInSsa, 18 ConjunctsInUnsatCore, 13 InterpolantComputations, 11 PerfectInterpolantSequences, 111/116 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 149]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) || ((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0)))) || (!((\old(pumpRunning) == 0)) && (pumpRunning == 0))) || !((methaneLevelCritical == 0))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && ((((((1 <= tmp) && !((\old(pumpRunning) == 0))) && (pumpRunning == 0)) || (((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) - InvariantResult [Line: 839]: Loop Invariant Derived loop invariant: ((((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && (tmp == 1)) && !((0 == systemActive))) - InvariantResult [Line: 785]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 174]: Loop Invariant Derived loop invariant: (((((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) - InvariantResult [Line: 301]: Loop Invariant Derived loop invariant: ((((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((1 <= methaneLevelCritical) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 1011]: Loop Invariant Derived loop invariant: (((0 == systemActive) || (methaneLevelCritical < 1)) && (!((methaneLevelCritical == 0)) || (0 == systemActive))) - InvariantResult [Line: 394]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 408]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 323]: Loop Invariant Derived loop invariant: (((((((pumpRunning == 0) && (1 <= methaneLevelCritical)) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) || (((((methaneLevelCritical == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 401]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 795]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 985]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive))) || (0 == systemActive)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && !((0 == systemActive)))) || (methaneLevelCritical < 1)) && ((((((((tmp == 0) && (2 <= waterLevel)) && (\old(waterLevel) == waterLevel)) || (((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) && (tmp == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive)) || (((((pumpRunning == 0) && (tmp == 0)) && (\old(pumpRunning) == 0)) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (tmp == 0)) && !((0 == systemActive))))) - InvariantResult [Line: 282]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) - InvariantResult [Line: 974]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || !((methaneLevelCritical == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (methaneLevelCritical < 1))) && (((pumpRunning == \old(pumpRunning)) || !((methaneLevelCritical == 0))) || (0 == systemActive))) - InvariantResult [Line: 856]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 218]: Loop Invariant Derived loop invariant: (((((((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)) || ((!((\old(pumpRunning) == 0)) && (pumpRunning == 0)) && (\result == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (!((methaneLevelCritical == 0)) || (0 == systemActive))) - InvariantResult [Line: 182]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == 0) && (methaneLevelCritical <= tmp)) && (2 <= waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && (((2 <= waterLevel) || !((methaneLevelCritical == 0))) || (0 == systemActive))) - InvariantResult [Line: 960]: Loop Invariant Derived loop invariant: (((((((pumpRunning == 0) && !((\result == 0))) || !((methaneLevelCritical == 0))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) && (((\old(pumpRunning) == 0) || !((methaneLevelCritical == 0))) || (0 == systemActive))) && ((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1))) - InvariantResult [Line: 322]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 263]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && (((((((((pumpRunning == 0) && (\old(pumpRunning) == 0)) && !((tmp == 0))) && (\result == 0)) && (tmp___0 == 0)) && !((0 == systemActive))) || !((methaneLevelCritical == 0))) || (((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0))) || (0 == systemActive))) - InvariantResult [Line: 883]: Loop Invariant Derived loop invariant: (((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (methaneLevelCritical < 1)) && ((((pumpRunning == \old(pumpRunning)) && !((\old(pumpRunning) == 0))) || !((methaneLevelCritical == 0))) || (0 == systemActive))) - InvariantResult [Line: 846]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 313]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:15:56,482 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_24148bcc-26fd-440c-991f-b9a46989d618/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE