./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 750fa47004e8b71818a419cd0705c167dc764081be79a2bed3ff642b9979f0ab --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:27:47,000 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:27:47,113 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:27:47,118 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:27:47,118 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:27:47,142 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:27:47,143 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:27:47,143 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:27:47,144 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:27:47,145 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:27:47,146 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:27:47,146 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:27:47,147 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:27:47,148 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:27:47,148 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:27:47,149 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:27:47,149 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:27:47,150 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:27:47,151 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:27:47,151 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:27:47,152 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:27:47,152 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:27:47,153 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:27:47,153 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:27:47,154 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:27:47,154 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:27:47,155 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:27:47,155 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:27:47,156 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:27:47,156 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:27:47,157 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:27:47,157 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:27:47,157 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:27:47,158 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:27:47,158 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:27:47,158 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:27:47,159 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:27:47,159 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:27:47,159 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:27:47,159 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 750fa47004e8b71818a419cd0705c167dc764081be79a2bed3ff642b9979f0ab [2023-11-06 22:27:47,415 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:27:47,448 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:27:47,451 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:27:47,452 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:27:47,453 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:27:47,454 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c [2023-11-06 22:27:50,545 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:27:50,824 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:27:50,825 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c [2023-11-06 22:27:50,854 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/data/812be6bd6/a277729bd2fd4e579a2e091d5b80ddc4/FLAGe7d52b76a [2023-11-06 22:27:50,871 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/data/812be6bd6/a277729bd2fd4e579a2e091d5b80ddc4 [2023-11-06 22:27:50,878 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:27:50,879 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:27:50,883 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:27:50,883 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:27:50,888 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:27:50,891 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:27:50" (1/1) ... [2023-11-06 22:27:50,892 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@4ae9ba41 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:50, skipping insertion in model container [2023-11-06 22:27:50,892 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:27:50" (1/1) ... [2023-11-06 22:27:50,958 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:27:51,237 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c[16171,16184] [2023-11-06 22:27:51,261 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:27:51,279 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:27:51,289 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [49] [2023-11-06 22:27:51,291 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [121] [2023-11-06 22:27:51,291 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [221] [2023-11-06 22:27:51,291 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [389] [2023-11-06 22:27:51,292 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification3_spec.i","") [755] [2023-11-06 22:27:51,293 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [791] [2023-11-06 22:27:51,293 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [800] [2023-11-06 22:27:51,293 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [894] [2023-11-06 22:27:51,409 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/sv-benchmarks/c/product-lines/minepump_spec3_product34.cil.c[16171,16184] [2023-11-06 22:27:51,414 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:27:51,434 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:27:51,435 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51 WrapperNode [2023-11-06 22:27:51,435 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:27:51,436 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:27:51,436 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:27:51,436 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:27:51,446 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,461 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,488 INFO L138 Inliner]: procedures = 53, calls = 95, calls flagged for inlining = 21, calls inlined = 18, statements flattened = 179 [2023-11-06 22:27:51,489 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:27:51,489 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:27:51,489 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:27:51,490 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:27:51,499 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,499 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,502 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,502 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,525 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,530 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,532 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,534 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,536 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:27:51,537 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:27:51,537 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:27:51,538 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:27:51,539 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (1/1) ... [2023-11-06 22:27:51,545 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:27:51,561 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:27:51,572 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:27:51,608 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:27:51,620 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:27:51,621 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:27:51,621 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:27:51,621 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2023-11-06 22:27:51,623 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2023-11-06 22:27:51,623 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:27:51,624 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:27:51,624 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:27:51,624 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:27:51,625 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:27:51,625 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:27:51,625 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:27:51,625 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:27:51,625 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:27:51,626 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:27:51,626 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:27:51,761 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:27:51,763 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:27:52,023 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:27:52,031 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:27:52,031 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:27:52,033 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:27:52 BoogieIcfgContainer [2023-11-06 22:27:52,033 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:27:52,036 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:27:52,036 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:27:52,039 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:27:52,040 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:27:50" (1/3) ... [2023-11-06 22:27:52,040 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@741b7fe6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:27:52, skipping insertion in model container [2023-11-06 22:27:52,041 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:27:51" (2/3) ... [2023-11-06 22:27:52,041 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@741b7fe6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:27:52, skipping insertion in model container [2023-11-06 22:27:52,041 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:27:52" (3/3) ... [2023-11-06 22:27:52,043 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product34.cil.c [2023-11-06 22:27:52,062 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:27:52,063 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:27:52,114 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:27:52,120 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@5f9ad05b, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:27:52,121 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:27:52,125 INFO L276 IsEmpty]: Start isEmpty. Operand has 77 states, 60 states have (on average 1.4) internal successors, (84), 66 states have internal predecessors, (84), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 8 states have call predecessors, (9), 9 states have call successors, (9) [2023-11-06 22:27:52,135 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2023-11-06 22:27:52,136 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:52,136 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:52,137 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:52,142 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:52,143 INFO L85 PathProgramCache]: Analyzing trace with hash 77119383, now seen corresponding path program 1 times [2023-11-06 22:27:52,152 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:52,153 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1451802189] [2023-11-06 22:27:52,153 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:52,154 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:52,271 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,366 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-06 22:27:52,369 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,375 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:52,376 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:52,376 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1451802189] [2023-11-06 22:27:52,376 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1451802189] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:52,377 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:52,377 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:27:52,378 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [924918833] [2023-11-06 22:27:52,379 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:52,383 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:27:52,384 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:52,411 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:27:52,411 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:27:52,414 INFO L87 Difference]: Start difference. First operand has 77 states, 60 states have (on average 1.4) internal successors, (84), 66 states have internal predecessors, (84), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 8 states have call predecessors, (9), 9 states have call successors, (9) Second operand has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:52,447 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:52,447 INFO L93 Difference]: Finished difference Result 146 states and 199 transitions. [2023-11-06 22:27:52,448 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:27:52,449 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 25 [2023-11-06 22:27:52,450 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:52,458 INFO L225 Difference]: With dead ends: 146 [2023-11-06 22:27:52,458 INFO L226 Difference]: Without dead ends: 68 [2023-11-06 22:27:52,462 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:27:52,466 INFO L413 NwaCegarLoop]: 96 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 96 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:52,467 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 96 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:52,481 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 68 states. [2023-11-06 22:27:52,503 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 68 to 68. [2023-11-06 22:27:52,505 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 68 states, 53 states have (on average 1.320754716981132) internal successors, (70), 58 states have internal predecessors, (70), 9 states have call successors, (9), 6 states have call predecessors, (9), 5 states have return successors, (8), 7 states have call predecessors, (8), 8 states have call successors, (8) [2023-11-06 22:27:52,507 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 68 states to 68 states and 87 transitions. [2023-11-06 22:27:52,509 INFO L78 Accepts]: Start accepts. Automaton has 68 states and 87 transitions. Word has length 25 [2023-11-06 22:27:52,509 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:52,509 INFO L495 AbstractCegarLoop]: Abstraction has 68 states and 87 transitions. [2023-11-06 22:27:52,510 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 10.5) internal successors, (21), 2 states have internal predecessors, (21), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:52,510 INFO L276 IsEmpty]: Start isEmpty. Operand 68 states and 87 transitions. [2023-11-06 22:27:52,512 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 27 [2023-11-06 22:27:52,513 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:52,513 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:52,513 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:27:52,513 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:52,514 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:52,514 INFO L85 PathProgramCache]: Analyzing trace with hash -736072085, now seen corresponding path program 1 times [2023-11-06 22:27:52,515 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:52,515 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [991958661] [2023-11-06 22:27:52,515 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:52,515 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:52,540 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,657 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2023-11-06 22:27:52,660 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,667 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:52,673 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:52,673 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [991958661] [2023-11-06 22:27:52,674 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [991958661] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:52,674 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:52,674 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:27:52,675 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1268731694] [2023-11-06 22:27:52,675 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:52,676 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:27:52,677 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:52,678 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:27:52,679 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:52,679 INFO L87 Difference]: Start difference. First operand 68 states and 87 transitions. Second operand has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:52,700 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:52,703 INFO L93 Difference]: Finished difference Result 101 states and 129 transitions. [2023-11-06 22:27:52,704 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:27:52,704 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 26 [2023-11-06 22:27:52,705 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:52,711 INFO L225 Difference]: With dead ends: 101 [2023-11-06 22:27:52,711 INFO L226 Difference]: Without dead ends: 59 [2023-11-06 22:27:52,712 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 5 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:52,714 INFO L413 NwaCegarLoop]: 74 mSDtfsCounter, 13 mSDsluCounter, 57 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 131 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:52,715 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 131 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:52,716 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 59 states. [2023-11-06 22:27:52,726 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 59 to 59. [2023-11-06 22:27:52,733 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 59 states, 47 states have (on average 1.3404255319148937) internal successors, (63), 52 states have internal predecessors, (63), 6 states have call successors, (6), 5 states have call predecessors, (6), 5 states have return successors, (6), 5 states have call predecessors, (6), 6 states have call successors, (6) [2023-11-06 22:27:52,735 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 59 states to 59 states and 75 transitions. [2023-11-06 22:27:52,738 INFO L78 Accepts]: Start accepts. Automaton has 59 states and 75 transitions. Word has length 26 [2023-11-06 22:27:52,739 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:52,739 INFO L495 AbstractCegarLoop]: Abstraction has 59 states and 75 transitions. [2023-11-06 22:27:52,739 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.333333333333333) internal successors, (22), 3 states have internal predecessors, (22), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:52,740 INFO L276 IsEmpty]: Start isEmpty. Operand 59 states and 75 transitions. [2023-11-06 22:27:52,741 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 32 [2023-11-06 22:27:52,742 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:52,742 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:52,743 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:27:52,743 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:52,744 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:52,746 INFO L85 PathProgramCache]: Analyzing trace with hash 1036891216, now seen corresponding path program 1 times [2023-11-06 22:27:52,746 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:52,747 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [711488767] [2023-11-06 22:27:52,747 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:52,747 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:52,792 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,927 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:27:52,930 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:52,932 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:52,932 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:52,933 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [711488767] [2023-11-06 22:27:52,933 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [711488767] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:52,933 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:52,933 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:27:52,934 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1986568711] [2023-11-06 22:27:52,934 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:52,934 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:27:52,935 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:52,935 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:27:52,936 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:27:52,936 INFO L87 Difference]: Start difference. First operand 59 states and 75 transitions. Second operand has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,012 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:53,013 INFO L93 Difference]: Finished difference Result 111 states and 144 transitions. [2023-11-06 22:27:53,013 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:27:53,014 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 31 [2023-11-06 22:27:53,014 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:53,015 INFO L225 Difference]: With dead ends: 111 [2023-11-06 22:27:53,015 INFO L226 Difference]: Without dead ends: 59 [2023-11-06 22:27:53,016 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:27:53,017 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 100 mSDsluCounter, 104 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 100 SdHoareTripleChecker+Valid, 172 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:53,018 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [100 Valid, 172 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:53,019 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 59 states. [2023-11-06 22:27:53,028 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 59 to 59. [2023-11-06 22:27:53,029 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 59 states, 47 states have (on average 1.3191489361702127) internal successors, (62), 52 states have internal predecessors, (62), 6 states have call successors, (6), 5 states have call predecessors, (6), 5 states have return successors, (6), 5 states have call predecessors, (6), 6 states have call successors, (6) [2023-11-06 22:27:53,030 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 59 states to 59 states and 74 transitions. [2023-11-06 22:27:53,030 INFO L78 Accepts]: Start accepts. Automaton has 59 states and 74 transitions. Word has length 31 [2023-11-06 22:27:53,031 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:53,031 INFO L495 AbstractCegarLoop]: Abstraction has 59 states and 74 transitions. [2023-11-06 22:27:53,031 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.6) internal successors, (28), 5 states have internal predecessors, (28), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,031 INFO L276 IsEmpty]: Start isEmpty. Operand 59 states and 74 transitions. [2023-11-06 22:27:53,033 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 37 [2023-11-06 22:27:53,033 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:53,033 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:53,033 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:27:53,033 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:53,034 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:53,034 INFO L85 PathProgramCache]: Analyzing trace with hash -349370363, now seen corresponding path program 1 times [2023-11-06 22:27:53,034 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:53,035 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [711863179] [2023-11-06 22:27:53,035 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:53,035 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:53,054 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,150 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:27:53,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,153 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2023-11-06 22:27:53,155 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,157 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:53,157 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:53,157 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [711863179] [2023-11-06 22:27:53,157 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [711863179] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:53,157 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:53,158 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:27:53,158 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [547372478] [2023-11-06 22:27:53,158 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:53,158 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:27:53,159 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:53,159 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:27:53,159 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:53,160 INFO L87 Difference]: Start difference. First operand 59 states and 74 transitions. Second operand has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:27:53,203 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:53,203 INFO L93 Difference]: Finished difference Result 152 states and 195 transitions. [2023-11-06 22:27:53,203 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:27:53,204 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 36 [2023-11-06 22:27:53,204 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:53,205 INFO L225 Difference]: With dead ends: 152 [2023-11-06 22:27:53,205 INFO L226 Difference]: Without dead ends: 100 [2023-11-06 22:27:53,206 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:53,208 INFO L413 NwaCegarLoop]: 90 mSDtfsCounter, 47 mSDsluCounter, 51 mSDsCounter, 0 mSdLazyCounter, 7 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 47 SdHoareTripleChecker+Valid, 141 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 7 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:53,209 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [47 Valid, 141 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 7 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:53,210 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 100 states. [2023-11-06 22:27:53,227 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 100 to 98. [2023-11-06 22:27:53,227 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 98 states, 77 states have (on average 1.3116883116883118) internal successors, (101), 83 states have internal predecessors, (101), 10 states have call successors, (10), 10 states have call predecessors, (10), 10 states have return successors, (12), 10 states have call predecessors, (12), 10 states have call successors, (12) [2023-11-06 22:27:53,230 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 98 states to 98 states and 123 transitions. [2023-11-06 22:27:53,230 INFO L78 Accepts]: Start accepts. Automaton has 98 states and 123 transitions. Word has length 36 [2023-11-06 22:27:53,230 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:53,230 INFO L495 AbstractCegarLoop]: Abstraction has 98 states and 123 transitions. [2023-11-06 22:27:53,231 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 10.333333333333334) internal successors, (31), 3 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:27:53,231 INFO L276 IsEmpty]: Start isEmpty. Operand 98 states and 123 transitions. [2023-11-06 22:27:53,232 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2023-11-06 22:27:53,232 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:53,232 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:53,233 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:27:53,233 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:53,233 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:53,234 INFO L85 PathProgramCache]: Analyzing trace with hash 2107801392, now seen corresponding path program 1 times [2023-11-06 22:27:53,234 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:53,234 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1237999628] [2023-11-06 22:27:53,234 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:53,234 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:53,251 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,326 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2023-11-06 22:27:53,328 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,330 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:53,330 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:53,330 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1237999628] [2023-11-06 22:27:53,330 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1237999628] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:53,331 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:53,331 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:27:53,331 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [626350289] [2023-11-06 22:27:53,331 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:53,332 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:27:53,332 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:53,332 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:27:53,333 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:27:53,333 INFO L87 Difference]: Start difference. First operand 98 states and 123 transitions. Second operand has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,443 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:53,443 INFO L93 Difference]: Finished difference Result 207 states and 265 transitions. [2023-11-06 22:27:53,443 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:27:53,444 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 40 [2023-11-06 22:27:53,444 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:53,447 INFO L225 Difference]: With dead ends: 207 [2023-11-06 22:27:53,448 INFO L226 Difference]: Without dead ends: 116 [2023-11-06 22:27:53,449 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:27:53,456 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 18 mSDsluCounter, 242 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 330 SdHoareTripleChecker+Invalid, 20 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:53,457 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 330 Invalid, 20 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:53,461 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 116 states. [2023-11-06 22:27:53,493 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 116 to 101. [2023-11-06 22:27:53,494 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 101 states, 80 states have (on average 1.3) internal successors, (104), 86 states have internal predecessors, (104), 10 states have call successors, (10), 10 states have call predecessors, (10), 10 states have return successors, (12), 10 states have call predecessors, (12), 10 states have call successors, (12) [2023-11-06 22:27:53,496 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 101 states to 101 states and 126 transitions. [2023-11-06 22:27:53,497 INFO L78 Accepts]: Start accepts. Automaton has 101 states and 126 transitions. Word has length 40 [2023-11-06 22:27:53,497 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:53,497 INFO L495 AbstractCegarLoop]: Abstraction has 101 states and 126 transitions. [2023-11-06 22:27:53,497 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,497 INFO L276 IsEmpty]: Start isEmpty. Operand 101 states and 126 transitions. [2023-11-06 22:27:53,505 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2023-11-06 22:27:53,506 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:53,506 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:53,507 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:27:53,508 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:53,511 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:53,512 INFO L85 PathProgramCache]: Analyzing trace with hash 113656686, now seen corresponding path program 1 times [2023-11-06 22:27:53,513 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:53,513 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1686133341] [2023-11-06 22:27:53,513 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:53,514 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:53,535 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,648 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2023-11-06 22:27:53,655 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,659 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:53,659 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:53,659 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1686133341] [2023-11-06 22:27:53,659 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1686133341] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:53,660 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:53,660 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-06 22:27:53,660 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [866308220] [2023-11-06 22:27:53,660 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:53,661 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2023-11-06 22:27:53,661 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:53,664 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2023-11-06 22:27:53,664 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2023-11-06 22:27:53,665 INFO L87 Difference]: Start difference. First operand 101 states and 126 transitions. Second operand has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,710 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:53,711 INFO L93 Difference]: Finished difference Result 215 states and 275 transitions. [2023-11-06 22:27:53,711 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2023-11-06 22:27:53,712 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 40 [2023-11-06 22:27:53,714 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:53,715 INFO L225 Difference]: With dead ends: 215 [2023-11-06 22:27:53,715 INFO L226 Difference]: Without dead ends: 121 [2023-11-06 22:27:53,716 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:27:53,725 INFO L413 NwaCegarLoop]: 90 mSDtfsCounter, 21 mSDsluCounter, 159 mSDsCounter, 0 mSdLazyCounter, 10 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 23 SdHoareTripleChecker+Valid, 249 SdHoareTripleChecker+Invalid, 10 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 10 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:53,729 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [23 Valid, 249 Invalid, 10 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 10 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:53,730 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 121 states. [2023-11-06 22:27:53,754 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 121 to 103. [2023-11-06 22:27:53,755 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 103 states, 82 states have (on average 1.2926829268292683) internal successors, (106), 88 states have internal predecessors, (106), 10 states have call successors, (10), 10 states have call predecessors, (10), 10 states have return successors, (12), 10 states have call predecessors, (12), 10 states have call successors, (12) [2023-11-06 22:27:53,757 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 103 states to 103 states and 128 transitions. [2023-11-06 22:27:53,757 INFO L78 Accepts]: Start accepts. Automaton has 103 states and 128 transitions. Word has length 40 [2023-11-06 22:27:53,757 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:53,757 INFO L495 AbstractCegarLoop]: Abstraction has 103 states and 128 transitions. [2023-11-06 22:27:53,758 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 9.25) internal successors, (37), 4 states have internal predecessors, (37), 2 states have call successors, (2), 1 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,758 INFO L276 IsEmpty]: Start isEmpty. Operand 103 states and 128 transitions. [2023-11-06 22:27:53,759 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2023-11-06 22:27:53,759 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:53,759 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:53,759 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:27:53,760 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:53,760 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:53,760 INFO L85 PathProgramCache]: Analyzing trace with hash -703991764, now seen corresponding path program 1 times [2023-11-06 22:27:53,760 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:53,761 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [741660860] [2023-11-06 22:27:53,761 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:53,761 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:53,791 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,870 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 29 [2023-11-06 22:27:53,871 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:53,876 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:53,876 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:53,876 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [741660860] [2023-11-06 22:27:53,876 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [741660860] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:53,877 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:53,877 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:27:53,877 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1353795971] [2023-11-06 22:27:53,877 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:53,878 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:27:53,878 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:53,878 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:27:53,878 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:53,879 INFO L87 Difference]: Start difference. First operand 103 states and 128 transitions. Second operand has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,918 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:53,919 INFO L93 Difference]: Finished difference Result 245 states and 308 transitions. [2023-11-06 22:27:53,919 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:27:53,920 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 40 [2023-11-06 22:27:53,920 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:53,921 INFO L225 Difference]: With dead ends: 245 [2023-11-06 22:27:53,922 INFO L226 Difference]: Without dead ends: 149 [2023-11-06 22:27:53,922 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:27:53,923 INFO L413 NwaCegarLoop]: 71 mSDtfsCounter, 39 mSDsluCounter, 60 mSDsCounter, 0 mSdLazyCounter, 10 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 39 SdHoareTripleChecker+Valid, 131 SdHoareTripleChecker+Invalid, 11 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 10 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:53,924 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [39 Valid, 131 Invalid, 11 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 10 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:53,927 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 149 states. [2023-11-06 22:27:53,960 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 149 to 147. [2023-11-06 22:27:53,962 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 147 states, 117 states have (on average 1.2735042735042734) internal successors, (149), 124 states have internal predecessors, (149), 15 states have call successors, (15), 15 states have call predecessors, (15), 14 states have return successors, (17), 14 states have call predecessors, (17), 15 states have call successors, (17) [2023-11-06 22:27:53,963 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 147 states to 147 states and 181 transitions. [2023-11-06 22:27:53,963 INFO L78 Accepts]: Start accepts. Automaton has 147 states and 181 transitions. Word has length 40 [2023-11-06 22:27:53,963 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:53,964 INFO L495 AbstractCegarLoop]: Abstraction has 147 states and 181 transitions. [2023-11-06 22:27:53,964 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 12.333333333333334) internal successors, (37), 3 states have internal predecessors, (37), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:27:53,964 INFO L276 IsEmpty]: Start isEmpty. Operand 147 states and 181 transitions. [2023-11-06 22:27:53,967 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 43 [2023-11-06 22:27:53,967 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:53,967 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:53,968 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:27:53,968 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:53,969 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:53,969 INFO L85 PathProgramCache]: Analyzing trace with hash -430431235, now seen corresponding path program 1 times [2023-11-06 22:27:53,969 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:53,969 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1848751406] [2023-11-06 22:27:53,969 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:53,970 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:53,993 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,126 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 26 [2023-11-06 22:27:54,127 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,129 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2023-11-06 22:27:54,131 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,133 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:54,133 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:54,134 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1848751406] [2023-11-06 22:27:54,134 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1848751406] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:54,134 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:54,134 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:27:54,134 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2029651512] [2023-11-06 22:27:54,134 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:54,135 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:27:54,135 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:54,135 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:27:54,135 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:27:54,135 INFO L87 Difference]: Start difference. First operand 147 states and 181 transitions. Second operand has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:27:54,195 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:54,195 INFO L93 Difference]: Finished difference Result 288 states and 356 transitions. [2023-11-06 22:27:54,195 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:27:54,196 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 42 [2023-11-06 22:27:54,196 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:54,198 INFO L225 Difference]: With dead ends: 288 [2023-11-06 22:27:54,198 INFO L226 Difference]: Without dead ends: 148 [2023-11-06 22:27:54,198 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:27:54,199 INFO L413 NwaCegarLoop]: 72 mSDtfsCounter, 28 mSDsluCounter, 199 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 28 SdHoareTripleChecker+Valid, 271 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:54,199 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [28 Valid, 271 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:27:54,200 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 148 states. [2023-11-06 22:27:54,245 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 148 to 145. [2023-11-06 22:27:54,246 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 145 states, 115 states have (on average 1.2608695652173914) internal successors, (145), 122 states have internal predecessors, (145), 15 states have call successors, (15), 15 states have call predecessors, (15), 14 states have return successors, (17), 14 states have call predecessors, (17), 15 states have call successors, (17) [2023-11-06 22:27:54,247 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 145 states to 145 states and 177 transitions. [2023-11-06 22:27:54,247 INFO L78 Accepts]: Start accepts. Automaton has 145 states and 177 transitions. Word has length 42 [2023-11-06 22:27:54,247 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:54,248 INFO L495 AbstractCegarLoop]: Abstraction has 145 states and 177 transitions. [2023-11-06 22:27:54,248 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.4) internal successors, (37), 5 states have internal predecessors, (37), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:27:54,248 INFO L276 IsEmpty]: Start isEmpty. Operand 145 states and 177 transitions. [2023-11-06 22:27:54,249 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2023-11-06 22:27:54,249 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:54,249 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:54,249 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2023-11-06 22:27:54,249 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:54,250 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:54,250 INFO L85 PathProgramCache]: Analyzing trace with hash -994693806, now seen corresponding path program 1 times [2023-11-06 22:27:54,250 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:54,250 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [30162934] [2023-11-06 22:27:54,250 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:54,250 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:54,265 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,338 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:27:54,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,341 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2023-11-06 22:27:54,343 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,345 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:54,346 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:54,346 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [30162934] [2023-11-06 22:27:54,346 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [30162934] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:54,346 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:54,346 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:27:54,347 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1090348023] [2023-11-06 22:27:54,347 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:54,347 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:27:54,347 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:54,348 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:27:54,348 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:27:54,348 INFO L87 Difference]: Start difference. First operand 145 states and 177 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:27:54,575 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:54,575 INFO L93 Difference]: Finished difference Result 267 states and 332 transitions. [2023-11-06 22:27:54,575 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-06 22:27:54,576 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 44 [2023-11-06 22:27:54,576 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:54,577 INFO L225 Difference]: With dead ends: 267 [2023-11-06 22:27:54,577 INFO L226 Difference]: Without dead ends: 104 [2023-11-06 22:27:54,578 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=40, Invalid=70, Unknown=0, NotChecked=0, Total=110 [2023-11-06 22:27:54,579 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 104 mSDsluCounter, 282 mSDsCounter, 0 mSdLazyCounter, 141 mSolverCounterSat, 11 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 108 SdHoareTripleChecker+Valid, 379 SdHoareTripleChecker+Invalid, 152 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 11 IncrementalHoareTripleChecker+Valid, 141 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:54,579 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [108 Valid, 379 Invalid, 152 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [11 Valid, 141 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:27:54,580 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 104 states. [2023-11-06 22:27:54,595 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 104 to 101. [2023-11-06 22:27:54,595 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 101 states, 80 states have (on average 1.2125) internal successors, (97), 85 states have internal predecessors, (97), 10 states have call successors, (10), 10 states have call predecessors, (10), 10 states have return successors, (11), 9 states have call predecessors, (11), 10 states have call successors, (11) [2023-11-06 22:27:54,596 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 101 states to 101 states and 118 transitions. [2023-11-06 22:27:54,596 INFO L78 Accepts]: Start accepts. Automaton has 101 states and 118 transitions. Word has length 44 [2023-11-06 22:27:54,596 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:54,596 INFO L495 AbstractCegarLoop]: Abstraction has 101 states and 118 transitions. [2023-11-06 22:27:54,597 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:27:54,597 INFO L276 IsEmpty]: Start isEmpty. Operand 101 states and 118 transitions. [2023-11-06 22:27:54,597 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2023-11-06 22:27:54,597 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:54,598 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:54,598 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2023-11-06 22:27:54,598 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:54,598 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:54,598 INFO L85 PathProgramCache]: Analyzing trace with hash -622219357, now seen corresponding path program 1 times [2023-11-06 22:27:54,598 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:54,599 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [537556281] [2023-11-06 22:27:54,599 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:54,599 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:54,612 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,679 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:27:54,680 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,682 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-06 22:27:54,683 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,684 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2023-11-06 22:27:54,685 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,687 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:54,687 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:54,688 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [537556281] [2023-11-06 22:27:54,688 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [537556281] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:54,688 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:54,688 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:27:54,688 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1518263908] [2023-11-06 22:27:54,688 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:54,688 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:27:54,689 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:54,689 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:27:54,689 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:27:54,689 INFO L87 Difference]: Start difference. First operand 101 states and 118 transitions. Second operand has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:54,838 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:54,839 INFO L93 Difference]: Finished difference Result 204 states and 246 transitions. [2023-11-06 22:27:54,839 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:27:54,839 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2023-11-06 22:27:54,839 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:54,841 INFO L225 Difference]: With dead ends: 204 [2023-11-06 22:27:54,841 INFO L226 Difference]: Without dead ends: 152 [2023-11-06 22:27:54,841 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 17 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=32, Invalid=58, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:27:54,842 INFO L413 NwaCegarLoop]: 52 mSDtfsCounter, 106 mSDsluCounter, 165 mSDsCounter, 0 mSdLazyCounter, 85 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 109 SdHoareTripleChecker+Valid, 217 SdHoareTripleChecker+Invalid, 102 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 85 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:54,842 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [109 Valid, 217 Invalid, 102 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 85 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:27:54,843 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 152 states. [2023-11-06 22:27:54,867 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 152 to 145. [2023-11-06 22:27:54,867 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 145 states, 114 states have (on average 1.2280701754385965) internal successors, (140), 121 states have internal predecessors, (140), 15 states have call successors, (15), 15 states have call predecessors, (15), 15 states have return successors, (18), 14 states have call predecessors, (18), 15 states have call successors, (18) [2023-11-06 22:27:54,869 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 145 states to 145 states and 173 transitions. [2023-11-06 22:27:54,869 INFO L78 Accepts]: Start accepts. Automaton has 145 states and 173 transitions. Word has length 46 [2023-11-06 22:27:54,869 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:54,869 INFO L495 AbstractCegarLoop]: Abstraction has 145 states and 173 transitions. [2023-11-06 22:27:54,869 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.5) internal successors, (39), 5 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:54,869 INFO L276 IsEmpty]: Start isEmpty. Operand 145 states and 173 transitions. [2023-11-06 22:27:54,870 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2023-11-06 22:27:54,870 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:54,870 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:54,870 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2023-11-06 22:27:54,871 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:54,871 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:54,871 INFO L85 PathProgramCache]: Analyzing trace with hash -403364639, now seen corresponding path program 1 times [2023-11-06 22:27:54,871 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:54,871 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [80754679] [2023-11-06 22:27:54,872 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:54,872 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:54,882 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,926 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:27:54,927 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,928 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-06 22:27:54,929 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,930 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2023-11-06 22:27:54,931 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:54,932 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:54,932 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:54,933 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [80754679] [2023-11-06 22:27:54,933 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [80754679] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:54,933 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:54,933 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:27:54,933 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1328199723] [2023-11-06 22:27:54,933 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:54,934 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:27:54,934 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:54,934 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:27:54,934 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:27:54,934 INFO L87 Difference]: Start difference. First operand 145 states and 173 transitions. Second operand has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:55,060 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:55,060 INFO L93 Difference]: Finished difference Result 255 states and 309 transitions. [2023-11-06 22:27:55,061 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:27:55,061 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2023-11-06 22:27:55,061 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:55,062 INFO L225 Difference]: With dead ends: 255 [2023-11-06 22:27:55,062 INFO L226 Difference]: Without dead ends: 159 [2023-11-06 22:27:55,063 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 7 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:27:55,064 INFO L413 NwaCegarLoop]: 67 mSDtfsCounter, 54 mSDsluCounter, 130 mSDsCounter, 0 mSdLazyCounter, 61 mSolverCounterSat, 6 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 56 SdHoareTripleChecker+Valid, 197 SdHoareTripleChecker+Invalid, 67 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 6 IncrementalHoareTripleChecker+Valid, 61 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:55,064 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [56 Valid, 197 Invalid, 67 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [6 Valid, 61 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:27:55,065 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 159 states. [2023-11-06 22:27:55,089 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 159 to 159. [2023-11-06 22:27:55,090 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 159 states, 125 states have (on average 1.2) internal successors, (150), 133 states have internal predecessors, (150), 17 states have call successors, (17), 15 states have call predecessors, (17), 16 states have return successors, (21), 16 states have call predecessors, (21), 17 states have call successors, (21) [2023-11-06 22:27:55,091 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 159 states to 159 states and 188 transitions. [2023-11-06 22:27:55,091 INFO L78 Accepts]: Start accepts. Automaton has 159 states and 188 transitions. Word has length 46 [2023-11-06 22:27:55,091 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:55,091 INFO L495 AbstractCegarLoop]: Abstraction has 159 states and 188 transitions. [2023-11-06 22:27:55,091 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.8) internal successors, (39), 4 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:55,092 INFO L276 IsEmpty]: Start isEmpty. Operand 159 states and 188 transitions. [2023-11-06 22:27:55,092 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2023-11-06 22:27:55,092 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:27:55,092 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:55,093 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10 [2023-11-06 22:27:55,093 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:27:55,093 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:27:55,093 INFO L85 PathProgramCache]: Analyzing trace with hash -1221013089, now seen corresponding path program 1 times [2023-11-06 22:27:55,093 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:27:55,094 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [879414152] [2023-11-06 22:27:55,094 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:27:55,094 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:27:55,104 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:55,184 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:27:55,185 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:55,186 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-06 22:27:55,187 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:55,188 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 35 [2023-11-06 22:27:55,188 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:27:55,190 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:27:55,190 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:27:55,190 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [879414152] [2023-11-06 22:27:55,190 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [879414152] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:27:55,190 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:27:55,190 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2023-11-06 22:27:55,190 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1249689788] [2023-11-06 22:27:55,191 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:27:55,191 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-06 22:27:55,191 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:27:55,192 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-06 22:27:55,192 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:27:55,192 INFO L87 Difference]: Start difference. First operand 159 states and 188 transitions. Second operand has 8 states, 8 states have (on average 4.875) internal successors, (39), 7 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:55,344 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:27:55,344 INFO L93 Difference]: Finished difference Result 230 states and 275 transitions. [2023-11-06 22:27:55,345 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:27:55,345 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 4.875) internal successors, (39), 7 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2023-11-06 22:27:55,345 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:27:55,346 INFO L225 Difference]: With dead ends: 230 [2023-11-06 22:27:55,346 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:27:55,346 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=100, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:27:55,347 INFO L413 NwaCegarLoop]: 47 mSDtfsCounter, 63 mSDsluCounter, 200 mSDsCounter, 0 mSdLazyCounter, 116 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 247 SdHoareTripleChecker+Invalid, 126 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 116 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:27:55,347 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 247 Invalid, 126 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 116 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:27:55,348 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:27:55,348 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:27:55,348 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:27:55,348 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:27:55,348 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 46 [2023-11-06 22:27:55,349 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:27:55,349 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:27:55,349 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 4.875) internal successors, (39), 7 states have internal predecessors, (39), 2 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:27:55,349 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:27:55,349 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:27:55,351 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:27:55,352 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2023-11-06 22:27:55,354 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:27:57,042 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 257 263) no Hoare annotation was computed. [2023-11-06 22:27:57,042 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 257 263) the Hoare annotation is: true [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point L831-1(lines 827 838) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 827 838) the Hoare annotation is: true [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 827 838) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 839 847) the Hoare annotation is: true [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalFINAL(lines 839 847) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point isMethaneLevelCriticalEXIT(lines 839 847) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L902 garLoopResultBuilder]: At program point L129(line 129) the Hoare annotation is: true [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point L129-1(line 129) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 123 152) no Hoare annotation was computed. [2023-11-06 22:27:57,043 INFO L902 garLoopResultBuilder]: At program point L148(lines 123 152) the Hoare annotation is: true [2023-11-06 22:27:57,044 INFO L899 garLoopResultBuilder]: For program point L144(line 144) no Hoare annotation was computed. [2023-11-06 22:27:57,044 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 123 152) the Hoare annotation is: true [2023-11-06 22:27:57,044 INFO L899 garLoopResultBuilder]: For program point L137(lines 137 141) no Hoare annotation was computed. [2023-11-06 22:27:57,044 INFO L902 garLoopResultBuilder]: At program point L137-1(lines 137 141) the Hoare annotation is: true [2023-11-06 22:27:57,044 INFO L899 garLoopResultBuilder]: For program point L134(line 134) no Hoare annotation was computed. [2023-11-06 22:27:57,044 INFO L902 garLoopResultBuilder]: At program point L133-2(lines 133 147) the Hoare annotation is: true [2023-11-06 22:27:57,045 INFO L895 garLoopResultBuilder]: At program point L279(line 279) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (and (= ~pumpRunning~0 0) (= |timeShift_processEnvironment_~tmp~2#1| 0) (not (= 2 ~waterLevel~0)) (= |old(~waterLevel~0)| ~waterLevel~0))) (or (not (= |old(~pumpRunning~0)| 1)) .cse0))) [2023-11-06 22:27:57,045 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 233 256) no Hoare annotation was computed. [2023-11-06 22:27:57,045 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 880 893) the Hoare annotation is: (let ((.cse0 (= |timeShift_isHighWaterSensorDry_#res#1| 1)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| 1)) .cse2) (let ((.cse3 (= ~pumpRunning~0 0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (and .cse0 .cse3 (not (= 2 ~waterLevel~0)) .cse4) .cse1 .cse2 (and .cse3 (= |timeShift_isHighWaterSensorDry_#res#1| 0) .cse4))) (or (not (= |old(~pumpRunning~0)| 1)) .cse2))) [2023-11-06 22:27:57,045 INFO L899 garLoopResultBuilder]: For program point L767(lines 767 787) no Hoare annotation was computed. [2023-11-06 22:27:57,045 INFO L895 garLoopResultBuilder]: At program point L284(line 284) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 (= ~pumpRunning~0 1)) (or (not (= |old(~pumpRunning~0)| 0)) .cse0))) [2023-11-06 22:27:57,045 INFO L899 garLoopResultBuilder]: For program point L796(line 796) no Hoare annotation was computed. [2023-11-06 22:27:57,046 INFO L895 garLoopResultBuilder]: At program point L284-1(lines 265 289) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (= |timeShift_processEnvironment_~tmp~2#1| 0)) (.cse5 (not .cse0)) (.cse1 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 .cse1) (or .cse2 (not (= |old(~waterLevel~0)| 1)) (and .cse3 .cse4 .cse5) .cse0) (let ((.cse6 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse2 (and .cse3 .cse4 (not (= 2 ~waterLevel~0)) .cse6 .cse5) .cse0 (and .cse6 .cse1)))))) [2023-11-06 22:27:57,046 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 871 879) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 1)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 .cse1) (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse2 (and .cse3 (not (= 2 |timeShift_getWaterLevel_#res#1|)) (not (= 2 ~waterLevel~0)) .cse4) .cse0 (and .cse4 .cse1))) (or .cse2 (not (= |old(~waterLevel~0)| 1)) (and .cse3 (= |timeShift_getWaterLevel_#res#1| 1)) .cse0))) [2023-11-06 22:27:57,046 INFO L899 garLoopResultBuilder]: For program point L371(lines 371 375) no Hoare annotation was computed. [2023-11-06 22:27:57,046 INFO L899 garLoopResultBuilder]: For program point L371-2(lines 371 375) no Hoare annotation was computed. [2023-11-06 22:27:57,046 INFO L895 garLoopResultBuilder]: At program point activatePump_returnLabel#1(lines 290 297) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (and (= |old(~waterLevel~0)| ~waterLevel~0) (= ~pumpRunning~0 1))) (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1) (or (not (= |old(~pumpRunning~0)| 1)) .cse1))) [2023-11-06 22:27:57,046 INFO L899 garLoopResultBuilder]: For program point L884(lines 884 890) no Hoare annotation was computed. [2023-11-06 22:27:57,046 INFO L899 garLoopResultBuilder]: For program point L244-1(lines 244 250) no Hoare annotation was computed. [2023-11-06 22:27:57,047 INFO L899 garLoopResultBuilder]: For program point L273(lines 273 281) no Hoare annotation was computed. [2023-11-06 22:27:57,047 INFO L899 garLoopResultBuilder]: For program point L269(lines 269 286) no Hoare annotation was computed. [2023-11-06 22:27:57,047 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 792 799) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0) (or (not (= |old(~pumpRunning~0)| 1)) .cse0))) [2023-11-06 22:27:57,047 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 233 256) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 (and .cse1 (= ~pumpRunning~0 1))) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse1) .cse0))) [2023-11-06 22:27:57,047 INFO L899 garLoopResultBuilder]: For program point L777(lines 777 783) no Hoare annotation was computed. [2023-11-06 22:27:57,047 INFO L899 garLoopResultBuilder]: For program point L773(lines 773 786) no Hoare annotation was computed. [2023-11-06 22:27:57,048 INFO L895 garLoopResultBuilder]: At program point L773-1(lines 758 790) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (let ((.cse1 (= ~pumpRunning~0 1)) (.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0)) (.cse5 (not .cse0))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 .cse1) (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse2 (and .cse3 (not (= 2 ~waterLevel~0)) .cse4 .cse5) .cse0 (and .cse4 .cse1))) (or .cse2 (not (= |old(~waterLevel~0)| 1)) (and .cse3 .cse5) .cse0)))) [2023-11-06 22:27:57,048 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 362 380) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= |timeShift_isHighWaterLevel_~tmp___0~1#1| 0)) (.cse2 (= |timeShift_isHighWaterLevel_#res#1| 0)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (not (= |old(~waterLevel~0)| 1)) .cse1 (and .cse2 .cse3)) (or (not (= |old(~pumpRunning~0)| 1)) .cse1) (let ((.cse4 (= ~pumpRunning~0 0)) (.cse5 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse0 (and .cse4 (not .cse3) (= |timeShift_isHighWaterLevel_~tmp~3#1| 0) (= |timeShift_isHighWaterSensorDry_#res#1| 0) .cse5 (not .cse2)) (and .cse4 (not (= 2 ~waterLevel~0)) .cse5) .cse1)))) [2023-11-06 22:27:57,048 INFO L895 garLoopResultBuilder]: At program point L765(line 765) the Hoare annotation is: (let ((.cse2 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= ~pumpRunning~0 0)) (.cse0 (= 0 ~systemActive~0)) (.cse1 (= ~pumpRunning~0 1))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 .cse1) (or .cse2 .cse3 (not (= |old(~waterLevel~0)| 1)) .cse0) (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0))) (or .cse2 (and .cse3 (not (= 2 ~waterLevel~0)) .cse4) .cse0 (and .cse4 .cse1))))) [2023-11-06 22:27:57,048 INFO L899 garLoopResultBuilder]: For program point L765-1(line 765) no Hoare annotation was computed. [2023-11-06 22:27:57,048 INFO L899 garLoopResultBuilder]: For program point L237-1(lines 236 255) no Hoare annotation was computed. [2023-11-06 22:27:57,048 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 233 256) no Hoare annotation was computed. [2023-11-06 22:27:57,049 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 317 325) the Hoare annotation is: (let ((.cse0 (= |timeShift_isPumpRunning_#res#1| 1)) (.cse1 (= ~pumpRunning~0 1)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 1)) (and .cse0 .cse1) .cse2) (or .cse3 .cse2 (and .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) .cse1)) (or .cse3 (not (= |old(~waterLevel~0)| 1)) .cse2))) [2023-11-06 22:27:57,049 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 796) no Hoare annotation was computed. [2023-11-06 22:27:57,049 INFO L899 garLoopResultBuilder]: For program point L807(lines 807 811) no Hoare annotation was computed. [2023-11-06 22:27:57,049 INFO L895 garLoopResultBuilder]: At program point L807-2(lines 803 814) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 1)) .cse0 (= ~pumpRunning~0 1)) (or (not (= |old(~pumpRunning~0)| 0)) .cse0))) [2023-11-06 22:27:57,049 INFO L895 garLoopResultBuilder]: At program point startSystem_returnLabel#1(lines 381 388) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:27:57,049 INFO L899 garLoopResultBuilder]: For program point L85(lines 85 91) no Hoare annotation was computed. [2023-11-06 22:27:57,049 INFO L899 garLoopResultBuilder]: For program point L85-1(lines 85 91) no Hoare annotation was computed. [2023-11-06 22:27:57,050 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 185 194) the Hoare annotation is: true [2023-11-06 22:27:57,050 INFO L895 garLoopResultBuilder]: At program point L110(lines 65 112) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 (not (= 2 ~waterLevel~0)) .cse1 .cse2 .cse3))) [2023-11-06 22:27:57,050 INFO L895 garLoopResultBuilder]: At program point L77(line 77) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 (not (= 2 ~waterLevel~0)) .cse1 .cse2 .cse3))) [2023-11-06 22:27:57,050 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 906 912) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:27:57,050 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 198 220) the Hoare annotation is: true [2023-11-06 22:27:57,050 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:27:57,050 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:27:57,051 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 178 184) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~1#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:27:57,051 INFO L899 garLoopResultBuilder]: For program point L103(lines 103 107) no Hoare annotation was computed. [2023-11-06 22:27:57,051 INFO L895 garLoopResultBuilder]: At program point L103-2(lines 95 108) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:27:57,051 INFO L899 garLoopResultBuilder]: For program point L66(lines 65 112) no Hoare annotation was computed. [2023-11-06 22:27:57,051 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:27:57,051 INFO L899 garLoopResultBuilder]: For program point L95(lines 95 108) no Hoare annotation was computed. [2023-11-06 22:27:57,051 INFO L895 garLoopResultBuilder]: At program point L87(line 87) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse2 (= |ULTIMATE.start_main_~tmp~1#1| 1)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 .cse3))) [2023-11-06 22:27:57,051 INFO L902 garLoopResultBuilder]: At program point L116(lines 55 120) the Hoare annotation is: true [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point L75(lines 75 81) no Hoare annotation was computed. [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point L75-1(lines 75 81) no Hoare annotation was computed. [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:27:57,052 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 913 919) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point L67(lines 67 71) no Hoare annotation was computed. [2023-11-06 22:27:57,052 INFO L895 garLoopResultBuilder]: At program point L113(lines 64 114) the Hoare annotation is: false [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point L208(lines 208 215) no Hoare annotation was computed. [2023-11-06 22:27:57,052 INFO L899 garLoopResultBuilder]: For program point L208-2(lines 208 215) no Hoare annotation was computed. [2023-11-06 22:27:57,053 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 920 928) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:27:57,053 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 815 826) no Hoare annotation was computed. [2023-11-06 22:27:57,053 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 815 826) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~pumpRunning~0 1)) .cse0 .cse1) (or (not (= ~pumpRunning~0 0)) .cse0 .cse1 (= |old(~waterLevel~0)| 2)))) [2023-11-06 22:27:57,053 INFO L899 garLoopResultBuilder]: For program point L819-1(lines 815 826) no Hoare annotation was computed. [2023-11-06 22:27:57,055 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:27:57,058 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:27:57,085 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:27:57 BoogieIcfgContainer [2023-11-06 22:27:57,085 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:27:57,085 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:27:57,085 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:27:57,086 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:27:57,086 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:27:52" (3/4) ... [2023-11-06 22:27:57,088 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:27:57,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:27:57,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:27:57,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2023-11-06 22:27:57,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:27:57,092 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:27:57,093 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:27:57,100 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 16 nodes and edges [2023-11-06 22:27:57,101 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:27:57,101 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:27:57,102 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:27:57,102 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:27:57,129 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:27:57,130 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:27:57,130 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || ((((((pumpRunning == 0) && (\result == 1)) && !((2 == waterLevel))) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:27:57,131 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (!((\old(pumpRunning) == 0)) || (0 == systemActive))) [2023-11-06 22:27:57,131 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (tmp == 0)) && !((0 == systemActive)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (((((pumpRunning == 0) && (tmp == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) [2023-11-06 22:27:57,132 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && !((0 == systemActive)))) || (0 == systemActive))) [2023-11-06 22:27:57,132 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || (((((pumpRunning == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:27:57,133 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == \result))) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive))) [2023-11-06 22:27:57,133 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) || !((\old(pumpRunning) == 0))) || !((\old(waterLevel) == 1))) || (0 == systemActive)) && (((((((\result == 1) && (pumpRunning == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,133 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive)) || ((\result == 0) && (tmp___0 == 0))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && !((tmp___0 == 0))) && (tmp == 0)) && (\result == 0)) && (\old(waterLevel) == waterLevel)) && !((\result == 0)))) || (((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive))) [2023-11-06 22:27:57,133 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || ((\result == 1) && (pumpRunning == 1))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (((\result == 1) && (\old(waterLevel) == waterLevel)) && (pumpRunning == 1)))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) [2023-11-06 22:27:57,134 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,134 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,163 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:27:57,164 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:27:57,164 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || ((((((pumpRunning == 0) && (\result == 1)) && !((2 == waterLevel))) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:27:57,164 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (!((\old(pumpRunning) == 0)) || (0 == systemActive))) [2023-11-06 22:27:57,164 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (tmp == 0)) && !((0 == systemActive)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (((((pumpRunning == 0) && (tmp == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) [2023-11-06 22:27:57,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && !((0 == systemActive)))) || (0 == systemActive))) [2023-11-06 22:27:57,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || (((((pumpRunning == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) [2023-11-06 22:27:57,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == \result))) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive))) [2023-11-06 22:27:57,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) || !((\old(pumpRunning) == 0))) || !((\old(waterLevel) == 1))) || (0 == systemActive)) && (((((((\result == 1) && (pumpRunning == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive)) || ((\result == 0) && (tmp___0 == 0))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && !((tmp___0 == 0))) && (tmp == 0)) && (\result == 0)) && (\old(waterLevel) == waterLevel)) && !((\result == 0)))) || (((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive))) [2023-11-06 22:27:57,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 1)) || ((\result == 1) && (pumpRunning == 1))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (((\result == 1) && (\old(waterLevel) == waterLevel)) && (pumpRunning == 1)))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) [2023-11-06 22:27:57,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) [2023-11-06 22:27:57,180 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:27:57,181 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:27:57,181 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:27:57,181 INFO L158 Benchmark]: Toolchain (without parser) took 6302.09ms. Allocated memory was 167.8MB in the beginning and 201.3MB in the end (delta: 33.6MB). Free memory was 128.1MB in the beginning and 100.8MB in the end (delta: 27.3MB). Peak memory consumption was 61.3MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,182 INFO L158 Benchmark]: CDTParser took 0.25ms. Allocated memory is still 113.2MB. Free memory is still 61.8MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:27:57,182 INFO L158 Benchmark]: CACSL2BoogieTranslator took 552.74ms. Allocated memory is still 167.8MB. Free memory was 127.6MB in the beginning and 108.7MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,182 INFO L158 Benchmark]: Boogie Procedure Inliner took 52.61ms. Allocated memory is still 167.8MB. Free memory was 108.7MB in the beginning and 106.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,183 INFO L158 Benchmark]: Boogie Preprocessor took 47.15ms. Allocated memory is still 167.8MB. Free memory was 106.6MB in the beginning and 105.0MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,183 INFO L158 Benchmark]: RCFGBuilder took 496.30ms. Allocated memory is still 167.8MB. Free memory was 105.0MB in the beginning and 89.4MB in the end (delta: 15.6MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,184 INFO L158 Benchmark]: TraceAbstraction took 5049.11ms. Allocated memory was 167.8MB in the beginning and 201.3MB in the end (delta: 33.6MB). Free memory was 88.9MB in the beginning and 107.1MB in the end (delta: -18.2MB). Peak memory consumption was 61.8MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,184 INFO L158 Benchmark]: Witness Printer took 95.48ms. Allocated memory is still 201.3MB. Free memory was 107.1MB in the beginning and 100.8MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2023-11-06 22:27:57,186 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.25ms. Allocated memory is still 113.2MB. Free memory is still 61.8MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 552.74ms. Allocated memory is still 167.8MB. Free memory was 127.6MB in the beginning and 108.7MB in the end (delta: 18.9MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 52.61ms. Allocated memory is still 167.8MB. Free memory was 108.7MB in the beginning and 106.6MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 47.15ms. Allocated memory is still 167.8MB. Free memory was 106.6MB in the beginning and 105.0MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 496.30ms. Allocated memory is still 167.8MB. Free memory was 105.0MB in the beginning and 89.4MB in the end (delta: 15.6MB). Peak memory consumption was 14.7MB. Max. memory is 16.1GB. * TraceAbstraction took 5049.11ms. Allocated memory was 167.8MB in the beginning and 201.3MB in the end (delta: 33.6MB). Free memory was 88.9MB in the beginning and 107.1MB in the end (delta: -18.2MB). Peak memory consumption was 61.8MB. Max. memory is 16.1GB. * Witness Printer took 95.48ms. Allocated memory is still 201.3MB. Free memory was 107.1MB in the beginning and 100.8MB in the end (delta: 6.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [49] - GenericResultAtLocation [Line: 121]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [121] - GenericResultAtLocation [Line: 221]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [221] - GenericResultAtLocation [Line: 389]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [389] - GenericResultAtLocation [Line: 755]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification3_spec.i","") [755] - GenericResultAtLocation [Line: 791]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [791] - GenericResultAtLocation [Line: 800]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [800] - GenericResultAtLocation [Line: 894]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [894] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 796]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 7 procedures, 77 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 5.0s, OverallIterations: 12, TraceHistogramMax: 1, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 1.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 1.7s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 611 SdHoareTripleChecker+Valid, 0.5s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 593 mSDsluCounter, 2561 SdHoareTripleChecker+Invalid, 0.4s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 1649 mSDsCounter, 60 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 482 IncrementalHoareTripleChecker+Invalid, 542 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 60 mSolverCounterUnsat, 912 mSDtfsCounter, 482 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 123 GetRequests, 70 SyntacticMatches, 0 SemanticMatches, 53 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 16 ImplicationChecksByTransitivity, 0.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=159occurred in iteration=11, InterpolantAutomatonStates: 62, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.3s AutomataMinimizationTime, 12 MinimizatonAttempts, 50 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 35 LocationsWithAnnotation, 473 PreInvPairs, 584 NumberOfFragments, 843 HoareAnnotationTreeSize, 473 FomulaSimplifications, 206 FormulaSimplificationTreeSizeReduction, 0.1s HoareSimplificationTime, 35 FomulaSimplificationsInter, 2243 FormulaSimplificationTreeSizeReductionInter, 1.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.0s SsaConstructionTime, 0.1s SatisfiabilityAnalysisTime, 1.2s InterpolantComputationTime, 462 NumberOfCodeBlocks, 462 NumberOfCodeBlocksAsserted, 12 NumberOfCheckSat, 450 ConstructedInterpolants, 0 QuantifiedInterpolants, 708 SizeOfPredicates, 0 NumberOfNonLiveVariables, 0 ConjunctsInSsa, 0 ConjunctsInUnsatCore, 12 InterpolantComputations, 12 PerfectInterpolantSequences, 0/0 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 65]: Loop Invariant Derived loop invariant: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || ((((((pumpRunning == 0) && (\result == 1)) && !((2 == waterLevel))) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 178]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 123]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 381]: Loop Invariant Derived loop invariant: ((((((\result == 1) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive))) && (pumpRunning == 1)) || (((((pumpRunning == 0) && (\result == 1)) && (splverifierCounter == 0)) && (tmp == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 792]: Loop Invariant Derived loop invariant: ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) - InvariantResult [Line: 290]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) - InvariantResult [Line: 906]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 871]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == \result))) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive))) - InvariantResult [Line: 920]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 265]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (tmp == 0)) && !((0 == systemActive)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (((((pumpRunning == 0) && (tmp == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) - InvariantResult [Line: 803]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (!((\old(pumpRunning) == 0)) || (0 == systemActive))) - InvariantResult [Line: 913]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 880]: Loop Invariant Derived loop invariant: ((((((\result == 1) || !((\old(pumpRunning) == 0))) || !((\old(waterLevel) == 1))) || (0 == systemActive)) && (((((((\result == 1) && (pumpRunning == 0)) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) || (((pumpRunning == 0) && (\result == 0)) && (\old(waterLevel) == waterLevel)))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) - InvariantResult [Line: 198]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 317]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 1)) || ((\result == 1) && (pumpRunning == 1))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (0 == systemActive)) || (((\result == 1) && (\old(waterLevel) == waterLevel)) && (pumpRunning == 1)))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive))) - InvariantResult [Line: 55]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 758]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 1)) || (0 == systemActive)) || (pumpRunning == 1)) && (((!((\old(pumpRunning) == 0)) || ((((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (0 == systemActive)) || ((\old(waterLevel) == waterLevel) && (pumpRunning == 1)))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && !((0 == systemActive)))) || (0 == systemActive))) - InvariantResult [Line: 133]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 362]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (0 == systemActive)) || ((\result == 0) && (tmp___0 == 0))) && (!((\old(pumpRunning) == 1)) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || ((((((pumpRunning == 0) && !((tmp___0 == 0))) && (tmp == 0)) && (\result == 0)) && (\old(waterLevel) == waterLevel)) && !((\result == 0)))) || (((pumpRunning == 0) && !((2 == waterLevel))) && (\old(waterLevel) == waterLevel))) || (0 == systemActive))) - InvariantResult [Line: 185]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:27:57,218 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_5fc1a7cc-d823-44a1-b9a6-3ef31ca38aa5/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE