./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash a5340faf3ec1f0e0bc66d280fc3b45c510e704ff1d108d74101ee8606e665888 --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:57:08,717 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:57:08,848 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:57:08,866 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:57:08,867 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:57:08,911 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:57:08,912 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:57:08,912 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:57:08,913 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:57:08,919 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:57:08,921 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:57:08,921 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:57:08,922 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:57:08,924 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:57:08,924 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:57:08,925 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:57:08,925 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:57:08,926 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:57:08,926 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:57:08,927 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:57:08,927 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:57:08,928 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:57:08,929 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:57:08,931 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:57:08,931 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:57:08,932 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:57:08,933 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:57:08,933 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:57:08,934 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:57:08,934 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:57:08,936 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:57:08,936 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:57:08,937 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:57:08,937 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:57:08,937 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:57:08,937 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:57:08,938 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:57:08,938 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:57:08,938 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:57:08,939 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> a5340faf3ec1f0e0bc66d280fc3b45c510e704ff1d108d74101ee8606e665888 [2023-11-06 22:57:09,276 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:57:09,301 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:57:09,304 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:57:09,306 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:57:09,307 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:57:09,308 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c [2023-11-06 22:57:12,541 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:57:12,874 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:57:12,874 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c [2023-11-06 22:57:12,890 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/data/5d2126535/ccd0c9c5dbf14971ad1b52830e6a4066/FLAG5bafc0f49 [2023-11-06 22:57:12,906 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/data/5d2126535/ccd0c9c5dbf14971ad1b52830e6a4066 [2023-11-06 22:57:12,909 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:57:12,910 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:57:12,912 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:57:12,912 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:57:12,918 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:57:12,919 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:57:12" (1/1) ... [2023-11-06 22:57:12,920 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@6498fbb1 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:12, skipping insertion in model container [2023-11-06 22:57:12,921 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:57:12" (1/1) ... [2023-11-06 22:57:12,979 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:57:13,171 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c[1605,1618] [2023-11-06 22:57:13,294 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:57:13,307 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:57:13,319 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] [2023-11-06 22:57:13,321 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [58] [2023-11-06 22:57:13,321 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [96] [2023-11-06 22:57:13,322 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [347] [2023-11-06 22:57:13,322 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [415] [2023-11-06 22:57:13,322 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [519] [2023-11-06 22:57:13,323 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [545] [2023-11-06 22:57:13,323 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [911] [2023-11-06 22:57:13,327 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/sv-benchmarks/c/product-lines/minepump_spec4_product61.cil.c[1605,1618] [2023-11-06 22:57:13,389 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:57:13,413 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:57:13,414 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13 WrapperNode [2023-11-06 22:57:13,414 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:57:13,416 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:57:13,416 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:57:13,416 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:57:13,425 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,442 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,478 INFO L138 Inliner]: procedures = 57, calls = 104, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 236 [2023-11-06 22:57:13,478 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:57:13,480 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:57:13,481 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:57:13,481 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:57:13,492 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,493 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,496 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,496 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,503 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,508 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,510 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,512 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,516 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:57:13,517 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:57:13,518 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:57:13,518 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:57:13,519 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (1/1) ... [2023-11-06 22:57:13,526 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:57:13,541 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:57:13,561 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:57:13,593 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:57:13,620 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:57:13,620 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:57:13,621 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:57:13,621 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:57:13,621 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:57:13,622 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:57:13,622 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:57:13,622 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:57:13,622 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:57:13,623 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:57:13,623 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:57:13,623 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:57:13,623 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:57:13,624 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2023-11-06 22:57:13,624 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2023-11-06 22:57:13,624 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-06 22:57:13,624 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-06 22:57:13,625 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:57:13,625 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:57:13,625 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:57:13,625 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:57:13,625 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:57:13,727 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:57:13,730 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:57:14,138 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:57:14,148 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:57:14,151 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:57:14,153 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:57:14 BoogieIcfgContainer [2023-11-06 22:57:14,154 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:57:14,158 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:57:14,158 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:57:14,162 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:57:14,162 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:57:12" (1/3) ... [2023-11-06 22:57:14,163 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@13f25f7a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:57:14, skipping insertion in model container [2023-11-06 22:57:14,164 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:57:13" (2/3) ... [2023-11-06 22:57:14,165 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@13f25f7a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:57:14, skipping insertion in model container [2023-11-06 22:57:14,166 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:57:14" (3/3) ... [2023-11-06 22:57:14,168 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product61.cil.c [2023-11-06 22:57:14,188 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:57:14,188 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:57:14,296 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:57:14,304 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@7a649fcd, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:57:14,304 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:57:14,308 INFO L276 IsEmpty]: Start isEmpty. Operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2023-11-06 22:57:14,315 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2023-11-06 22:57:14,315 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:14,315 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:14,316 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:14,320 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:14,320 INFO L85 PathProgramCache]: Analyzing trace with hash 332135154, now seen corresponding path program 1 times [2023-11-06 22:57:14,328 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:14,329 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1124955114] [2023-11-06 22:57:14,329 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:14,329 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:14,455 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:14,562 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:14,562 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:14,563 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1124955114] [2023-11-06 22:57:14,564 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1124955114] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:14,564 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:14,564 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:57:14,566 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1912491579] [2023-11-06 22:57:14,567 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:14,573 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:57:14,574 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:14,621 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:57:14,622 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:57:14,626 INFO L87 Difference]: Start difference. First operand has 103 states, 76 states have (on average 1.381578947368421) internal successors, (105), 86 states have internal predecessors, (105), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:14,705 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:14,705 INFO L93 Difference]: Finished difference Result 198 states and 269 transitions. [2023-11-06 22:57:14,706 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:57:14,708 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2023-11-06 22:57:14,708 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:14,721 INFO L225 Difference]: With dead ends: 198 [2023-11-06 22:57:14,722 INFO L226 Difference]: Without dead ends: 94 [2023-11-06 22:57:14,728 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:57:14,732 INFO L413 NwaCegarLoop]: 131 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 131 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:14,734 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 131 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:57:14,751 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 94 states. [2023-11-06 22:57:14,788 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 94 to 94. [2023-11-06 22:57:14,790 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 94 states, 69 states have (on average 1.318840579710145) internal successors, (91), 78 states have internal predecessors, (91), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2023-11-06 22:57:14,798 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 94 states to 94 states and 122 transitions. [2023-11-06 22:57:14,800 INFO L78 Accepts]: Start accepts. Automaton has 94 states and 122 transitions. Word has length 19 [2023-11-06 22:57:14,801 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:14,802 INFO L495 AbstractCegarLoop]: Abstraction has 94 states and 122 transitions. [2023-11-06 22:57:14,802 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:14,802 INFO L276 IsEmpty]: Start isEmpty. Operand 94 states and 122 transitions. [2023-11-06 22:57:14,806 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2023-11-06 22:57:14,806 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:14,806 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:14,807 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:57:14,807 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:14,810 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:14,810 INFO L85 PathProgramCache]: Analyzing trace with hash 2057254746, now seen corresponding path program 1 times [2023-11-06 22:57:14,810 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:14,811 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [837562283] [2023-11-06 22:57:14,811 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:14,811 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:14,859 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,017 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:15,017 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:15,018 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [837562283] [2023-11-06 22:57:15,018 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [837562283] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:15,018 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:15,019 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:57:15,019 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [604737462] [2023-11-06 22:57:15,019 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:15,021 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:57:15,022 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:15,023 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:57:15,023 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:57:15,024 INFO L87 Difference]: Start difference. First operand 94 states and 122 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:15,049 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:15,050 INFO L93 Difference]: Finished difference Result 154 states and 200 transitions. [2023-11-06 22:57:15,050 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:57:15,051 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2023-11-06 22:57:15,051 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:15,053 INFO L225 Difference]: With dead ends: 154 [2023-11-06 22:57:15,053 INFO L226 Difference]: Without dead ends: 85 [2023-11-06 22:57:15,054 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:57:15,056 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 12 mSDsluCounter, 93 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 15 SdHoareTripleChecker+Valid, 202 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:15,057 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [15 Valid, 202 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:57:15,058 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2023-11-06 22:57:15,068 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2023-11-06 22:57:15,068 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3333333333333333) internal successors, (84), 72 states have internal predecessors, (84), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-06 22:57:15,069 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 110 transitions. [2023-11-06 22:57:15,070 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 110 transitions. Word has length 20 [2023-11-06 22:57:15,070 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:15,070 INFO L495 AbstractCegarLoop]: Abstraction has 85 states and 110 transitions. [2023-11-06 22:57:15,071 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:15,071 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 110 transitions. [2023-11-06 22:57:15,072 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2023-11-06 22:57:15,072 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:15,073 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:15,073 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:57:15,073 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:15,074 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:15,074 INFO L85 PathProgramCache]: Analyzing trace with hash 1387625524, now seen corresponding path program 1 times [2023-11-06 22:57:15,074 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:15,075 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1718581577] [2023-11-06 22:57:15,075 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:15,075 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:15,101 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,239 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:15,239 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:15,240 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1718581577] [2023-11-06 22:57:15,240 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1718581577] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:15,242 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:15,242 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:57:15,242 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [714191798] [2023-11-06 22:57:15,242 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:15,243 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:57:15,245 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:15,245 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:57:15,246 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:57:15,246 INFO L87 Difference]: Start difference. First operand 85 states and 110 transitions. Second operand has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:15,273 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:15,273 INFO L93 Difference]: Finished difference Result 163 states and 214 transitions. [2023-11-06 22:57:15,273 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:57:15,274 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2023-11-06 22:57:15,274 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:15,276 INFO L225 Difference]: With dead ends: 163 [2023-11-06 22:57:15,278 INFO L226 Difference]: Without dead ends: 85 [2023-11-06 22:57:15,279 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:57:15,283 INFO L413 NwaCegarLoop]: 108 mSDtfsCounter, 92 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 92 SdHoareTripleChecker+Valid, 108 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:15,286 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [92 Valid, 108 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:57:15,287 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 85 states. [2023-11-06 22:57:15,299 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 85 to 85. [2023-11-06 22:57:15,303 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 85 states, 63 states have (on average 1.3174603174603174) internal successors, (83), 72 states have internal predecessors, (83), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-06 22:57:15,304 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 85 states to 85 states and 109 transitions. [2023-11-06 22:57:15,305 INFO L78 Accepts]: Start accepts. Automaton has 85 states and 109 transitions. Word has length 24 [2023-11-06 22:57:15,306 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:15,306 INFO L495 AbstractCegarLoop]: Abstraction has 85 states and 109 transitions. [2023-11-06 22:57:15,306 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 7.666666666666667) internal successors, (23), 2 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:15,307 INFO L276 IsEmpty]: Start isEmpty. Operand 85 states and 109 transitions. [2023-11-06 22:57:15,316 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2023-11-06 22:57:15,317 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:15,317 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:15,317 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:57:15,317 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:15,322 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:15,322 INFO L85 PathProgramCache]: Analyzing trace with hash 610675451, now seen corresponding path program 1 times [2023-11-06 22:57:15,322 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:15,322 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1837475614] [2023-11-06 22:57:15,323 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:15,323 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:15,359 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,464 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:57:15,467 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,474 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 26 [2023-11-06 22:57:15,475 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,478 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:15,478 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:15,479 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1837475614] [2023-11-06 22:57:15,479 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1837475614] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:15,479 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:15,479 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-06 22:57:15,480 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2141427457] [2023-11-06 22:57:15,480 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:15,480 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2023-11-06 22:57:15,481 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:15,482 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2023-11-06 22:57:15,482 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2023-11-06 22:57:15,483 INFO L87 Difference]: Start difference. First operand 85 states and 109 transitions. Second operand has 4 states, 4 states have (on average 8.0) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:57:15,750 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:15,750 INFO L93 Difference]: Finished difference Result 238 states and 306 transitions. [2023-11-06 22:57:15,751 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:57:15,751 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 8.0) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 37 [2023-11-06 22:57:15,751 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:15,758 INFO L225 Difference]: With dead ends: 238 [2023-11-06 22:57:15,759 INFO L226 Difference]: Without dead ends: 160 [2023-11-06 22:57:15,760 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:57:15,761 INFO L413 NwaCegarLoop]: 79 mSDtfsCounter, 153 mSDsluCounter, 106 mSDsCounter, 0 mSdLazyCounter, 77 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 185 SdHoareTripleChecker+Invalid, 118 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 77 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:15,762 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [157 Valid, 185 Invalid, 118 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 77 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:57:15,763 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 160 states. [2023-11-06 22:57:15,792 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 160 to 154. [2023-11-06 22:57:15,793 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 154 states, 117 states have (on average 1.2735042735042734) internal successors, (149), 126 states have internal predecessors, (149), 16 states have call successors, (16), 15 states have call predecessors, (16), 20 states have return successors, (27), 18 states have call predecessors, (27), 16 states have call successors, (27) [2023-11-06 22:57:15,795 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 154 states to 154 states and 192 transitions. [2023-11-06 22:57:15,795 INFO L78 Accepts]: Start accepts. Automaton has 154 states and 192 transitions. Word has length 37 [2023-11-06 22:57:15,796 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:15,796 INFO L495 AbstractCegarLoop]: Abstraction has 154 states and 192 transitions. [2023-11-06 22:57:15,796 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 8.0) internal successors, (32), 3 states have internal predecessors, (32), 2 states have call successors, (3), 3 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:57:15,797 INFO L276 IsEmpty]: Start isEmpty. Operand 154 states and 192 transitions. [2023-11-06 22:57:15,798 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 46 [2023-11-06 22:57:15,798 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:15,799 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:15,799 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:57:15,799 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:15,800 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:15,800 INFO L85 PathProgramCache]: Analyzing trace with hash -1599675381, now seen corresponding path program 1 times [2023-11-06 22:57:15,800 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:15,800 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1141666807] [2023-11-06 22:57:15,801 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:15,801 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:15,820 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,953 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:57:15,959 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,968 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:15,972 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,981 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:15,983 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:15,986 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:15,986 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:15,986 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1141666807] [2023-11-06 22:57:15,987 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1141666807] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:15,987 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:15,987 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:57:15,989 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [488292875] [2023-11-06 22:57:15,989 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:15,991 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:57:15,991 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:15,992 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:57:15,993 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:57:15,993 INFO L87 Difference]: Start difference. First operand 154 states and 192 transitions. Second operand has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:57:16,714 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:16,714 INFO L93 Difference]: Finished difference Result 581 states and 770 transitions. [2023-11-06 22:57:16,715 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2023-11-06 22:57:16,715 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 45 [2023-11-06 22:57:16,716 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:16,726 INFO L225 Difference]: With dead ends: 581 [2023-11-06 22:57:16,726 INFO L226 Difference]: Without dead ends: 434 [2023-11-06 22:57:16,728 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 58 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=105, Invalid=237, Unknown=0, NotChecked=0, Total=342 [2023-11-06 22:57:16,740 INFO L413 NwaCegarLoop]: 94 mSDtfsCounter, 349 mSDsluCounter, 396 mSDsCounter, 0 mSdLazyCounter, 288 mSolverCounterSat, 111 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 354 SdHoareTripleChecker+Valid, 490 SdHoareTripleChecker+Invalid, 399 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 111 IncrementalHoareTripleChecker+Valid, 288 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:16,741 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [354 Valid, 490 Invalid, 399 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [111 Valid, 288 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-06 22:57:16,743 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 434 states. [2023-11-06 22:57:16,859 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 434 to 424. [2023-11-06 22:57:16,861 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 424 states, 317 states have (on average 1.2460567823343849) internal successors, (395), 342 states have internal predecessors, (395), 46 states have call successors, (46), 43 states have call predecessors, (46), 60 states have return successors, (105), 54 states have call predecessors, (105), 46 states have call successors, (105) [2023-11-06 22:57:16,867 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 424 states to 424 states and 546 transitions. [2023-11-06 22:57:16,867 INFO L78 Accepts]: Start accepts. Automaton has 424 states and 546 transitions. Word has length 45 [2023-11-06 22:57:16,868 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:16,868 INFO L495 AbstractCegarLoop]: Abstraction has 424 states and 546 transitions. [2023-11-06 22:57:16,869 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.428571428571429) internal successors, (38), 6 states have internal predecessors, (38), 3 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:57:16,870 INFO L276 IsEmpty]: Start isEmpty. Operand 424 states and 546 transitions. [2023-11-06 22:57:16,876 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 50 [2023-11-06 22:57:16,877 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:16,877 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:16,878 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:57:16,878 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:16,879 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:16,880 INFO L85 PathProgramCache]: Analyzing trace with hash 414561125, now seen corresponding path program 1 times [2023-11-06 22:57:16,880 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:16,881 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [590863537] [2023-11-06 22:57:16,885 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:16,886 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:16,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,078 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:17,080 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,091 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:57:17,095 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,103 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:17,107 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,116 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:17,118 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,120 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:17,120 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:17,121 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [590863537] [2023-11-06 22:57:17,121 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [590863537] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:17,121 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:17,122 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:57:17,122 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [140207925] [2023-11-06 22:57:17,122 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:17,123 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:57:17,123 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:17,124 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:57:17,124 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:57:17,124 INFO L87 Difference]: Start difference. First operand 424 states and 546 transitions. Second operand has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:57:17,837 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:17,837 INFO L93 Difference]: Finished difference Result 507 states and 654 transitions. [2023-11-06 22:57:17,837 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2023-11-06 22:57:17,838 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) Word has length 49 [2023-11-06 22:57:17,838 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:17,842 INFO L225 Difference]: With dead ends: 507 [2023-11-06 22:57:17,842 INFO L226 Difference]: Without dead ends: 505 [2023-11-06 22:57:17,843 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 91 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=127, Invalid=335, Unknown=0, NotChecked=0, Total=462 [2023-11-06 22:57:17,844 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 226 mSDsluCounter, 253 mSDsCounter, 0 mSdLazyCounter, 369 mSolverCounterSat, 71 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 228 SdHoareTripleChecker+Valid, 306 SdHoareTripleChecker+Invalid, 440 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 71 IncrementalHoareTripleChecker+Valid, 369 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:17,844 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [228 Valid, 306 Invalid, 440 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [71 Valid, 369 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-06 22:57:17,846 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 505 states. [2023-11-06 22:57:17,911 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 505 to 465. [2023-11-06 22:57:17,913 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 465 states, 350 states have (on average 1.2314285714285715) internal successors, (431), 378 states have internal predecessors, (431), 50 states have call successors, (50), 43 states have call predecessors, (50), 64 states have return successors, (119), 59 states have call predecessors, (119), 50 states have call successors, (119) [2023-11-06 22:57:17,917 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 465 states to 465 states and 600 transitions. [2023-11-06 22:57:17,917 INFO L78 Accepts]: Start accepts. Automaton has 465 states and 600 transitions. Word has length 49 [2023-11-06 22:57:17,918 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:17,918 INFO L495 AbstractCegarLoop]: Abstraction has 465 states and 600 transitions. [2023-11-06 22:57:17,918 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 5.714285714285714) internal successors, (40), 5 states have internal predecessors, (40), 2 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 1 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:57:17,919 INFO L276 IsEmpty]: Start isEmpty. Operand 465 states and 600 transitions. [2023-11-06 22:57:17,920 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:57:17,920 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:17,921 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:17,921 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:57:17,921 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:17,921 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:17,922 INFO L85 PathProgramCache]: Analyzing trace with hash -1510129521, now seen corresponding path program 1 times [2023-11-06 22:57:17,922 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:17,922 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [346924170] [2023-11-06 22:57:17,922 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:17,922 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:17,936 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,988 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:17,989 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:17,994 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:57:17,999 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,016 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:18,020 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,059 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:18,060 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,063 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:18,063 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:18,063 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [346924170] [2023-11-06 22:57:18,063 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [346924170] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:18,064 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:18,064 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:57:18,064 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1525390982] [2023-11-06 22:57:18,064 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:18,065 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:57:18,065 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:18,065 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:57:18,066 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:57:18,066 INFO L87 Difference]: Start difference. First operand 465 states and 600 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:57:18,540 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:18,540 INFO L93 Difference]: Finished difference Result 971 states and 1329 transitions. [2023-11-06 22:57:18,541 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-06 22:57:18,541 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2023-11-06 22:57:18,542 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:18,546 INFO L225 Difference]: With dead ends: 971 [2023-11-06 22:57:18,547 INFO L226 Difference]: Without dead ends: 513 [2023-11-06 22:57:18,550 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=43, Invalid=89, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:57:18,551 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 160 mSDsluCounter, 228 mSDsCounter, 0 mSdLazyCounter, 328 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 285 SdHoareTripleChecker+Invalid, 386 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 328 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:18,551 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [161 Valid, 285 Invalid, 386 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 328 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:57:18,553 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 513 states. [2023-11-06 22:57:18,646 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 513 to 474. [2023-11-06 22:57:18,648 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 474 states, 359 states have (on average 1.2256267409470751) internal successors, (440), 387 states have internal predecessors, (440), 50 states have call successors, (50), 43 states have call predecessors, (50), 64 states have return successors, (119), 59 states have call predecessors, (119), 50 states have call successors, (119) [2023-11-06 22:57:18,655 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 474 states to 474 states and 609 transitions. [2023-11-06 22:57:18,655 INFO L78 Accepts]: Start accepts. Automaton has 474 states and 609 transitions. Word has length 55 [2023-11-06 22:57:18,657 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:18,657 INFO L495 AbstractCegarLoop]: Abstraction has 474 states and 609 transitions. [2023-11-06 22:57:18,657 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:57:18,658 INFO L276 IsEmpty]: Start isEmpty. Operand 474 states and 609 transitions. [2023-11-06 22:57:18,660 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:57:18,660 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:18,660 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:18,661 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:57:18,661 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:18,662 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:18,662 INFO L85 PathProgramCache]: Analyzing trace with hash -1644143027, now seen corresponding path program 1 times [2023-11-06 22:57:18,662 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:18,663 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1110455732] [2023-11-06 22:57:18,663 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:18,663 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:18,681 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,767 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:18,768 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,776 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:57:18,787 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,806 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:18,811 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,845 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:18,847 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:18,852 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:18,853 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:18,854 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1110455732] [2023-11-06 22:57:18,857 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1110455732] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:18,857 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:57:18,858 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:57:18,858 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [175947275] [2023-11-06 22:57:18,858 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:18,860 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:57:18,860 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:18,861 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:57:18,861 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:57:18,863 INFO L87 Difference]: Start difference. First operand 474 states and 609 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:57:19,287 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:19,288 INFO L93 Difference]: Finished difference Result 942 states and 1257 transitions. [2023-11-06 22:57:19,289 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:57:19,289 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) Word has length 55 [2023-11-06 22:57:19,289 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:19,294 INFO L225 Difference]: With dead ends: 942 [2023-11-06 22:57:19,294 INFO L226 Difference]: Without dead ends: 475 [2023-11-06 22:57:19,297 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=46, Invalid=86, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:57:19,299 INFO L413 NwaCegarLoop]: 53 mSDtfsCounter, 259 mSDsluCounter, 168 mSDsCounter, 0 mSdLazyCounter, 262 mSolverCounterSat, 84 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 262 SdHoareTripleChecker+Valid, 221 SdHoareTripleChecker+Invalid, 346 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 84 IncrementalHoareTripleChecker+Valid, 262 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:19,299 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [262 Valid, 221 Invalid, 346 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [84 Valid, 262 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:57:19,301 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 475 states. [2023-11-06 22:57:19,356 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 475 to 458. [2023-11-06 22:57:19,357 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 458 states, 346 states have (on average 1.2196531791907514) internal successors, (422), 373 states have internal predecessors, (422), 50 states have call successors, (50), 42 states have call predecessors, (50), 61 states have return successors, (113), 57 states have call predecessors, (113), 50 states have call successors, (113) [2023-11-06 22:57:19,361 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 458 states to 458 states and 585 transitions. [2023-11-06 22:57:19,361 INFO L78 Accepts]: Start accepts. Automaton has 458 states and 585 transitions. Word has length 55 [2023-11-06 22:57:19,363 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:19,363 INFO L495 AbstractCegarLoop]: Abstraction has 458 states and 585 transitions. [2023-11-06 22:57:19,363 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:57:19,364 INFO L276 IsEmpty]: Start isEmpty. Operand 458 states and 585 transitions. [2023-11-06 22:57:19,368 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2023-11-06 22:57:19,368 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:19,368 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:19,368 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2023-11-06 22:57:19,369 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:19,369 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:19,369 INFO L85 PathProgramCache]: Analyzing trace with hash -438470018, now seen corresponding path program 1 times [2023-11-06 22:57:19,369 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:19,369 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1891887534] [2023-11-06 22:57:19,370 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:19,370 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:19,390 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,548 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2023-11-06 22:57:19,557 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,665 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:57:19,671 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,696 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:19,700 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,712 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:19,714 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,718 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2023-11-06 22:57:19,719 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,721 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2023-11-06 22:57:19,723 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,726 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2023-11-06 22:57:19,729 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,734 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:19,735 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,737 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:19,738 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,740 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 16 proven. 4 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:57:19,740 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:19,741 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1891887534] [2023-11-06 22:57:19,741 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1891887534] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:57:19,741 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1895015785] [2023-11-06 22:57:19,741 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:19,742 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:19,742 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:57:19,746 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:57:19,767 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-06 22:57:19,885 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:19,888 INFO L262 TraceCheckSpWp]: Trace formula consists of 339 conjuncts, 4 conjunts are in the unsatisfiable core [2023-11-06 22:57:19,900 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:57:20,131 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 28 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:20,131 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:57:20,131 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1895015785] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:20,132 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:57:20,132 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [9] total 12 [2023-11-06 22:57:20,132 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1514182310] [2023-11-06 22:57:20,132 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:20,133 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:57:20,133 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:20,133 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:57:20,134 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=34, Invalid=98, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:57:20,134 INFO L87 Difference]: Start difference. First operand 458 states and 585 transitions. Second operand has 6 states, 6 states have (on average 13.666666666666666) internal successors, (82), 6 states have internal predecessors, (82), 5 states have call successors, (10), 4 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 5 states have call successors, (9) [2023-11-06 22:57:20,552 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:20,552 INFO L93 Difference]: Finished difference Result 859 states and 1148 transitions. [2023-11-06 22:57:20,553 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:57:20,553 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 13.666666666666666) internal successors, (82), 6 states have internal predecessors, (82), 5 states have call successors, (10), 4 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 5 states have call successors, (9) Word has length 101 [2023-11-06 22:57:20,554 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:20,557 INFO L225 Difference]: With dead ends: 859 [2023-11-06 22:57:20,557 INFO L226 Difference]: Without dead ends: 408 [2023-11-06 22:57:20,559 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 127 GetRequests, 115 SyntacticMatches, 1 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 28 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=38, Invalid=118, Unknown=0, NotChecked=0, Total=156 [2023-11-06 22:57:20,562 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 200 mSDsluCounter, 157 mSDsCounter, 0 mSdLazyCounter, 381 mSolverCounterSat, 66 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 213 SdHoareTripleChecker+Valid, 243 SdHoareTripleChecker+Invalid, 447 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 66 IncrementalHoareTripleChecker+Valid, 381 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:20,563 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [213 Valid, 243 Invalid, 447 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [66 Valid, 381 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:57:20,564 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 408 states. [2023-11-06 22:57:20,618 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 408 to 404. [2023-11-06 22:57:20,619 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 404 states, 307 states have (on average 1.228013029315961) internal successors, (377), 327 states have internal predecessors, (377), 49 states have call successors, (49), 42 states have call predecessors, (49), 47 states have return successors, (93), 47 states have call predecessors, (93), 49 states have call successors, (93) [2023-11-06 22:57:20,622 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 404 states to 404 states and 519 transitions. [2023-11-06 22:57:20,624 INFO L78 Accepts]: Start accepts. Automaton has 404 states and 519 transitions. Word has length 101 [2023-11-06 22:57:20,624 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:20,624 INFO L495 AbstractCegarLoop]: Abstraction has 404 states and 519 transitions. [2023-11-06 22:57:20,624 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 13.666666666666666) internal successors, (82), 6 states have internal predecessors, (82), 5 states have call successors, (10), 4 states have call predecessors, (10), 3 states have return successors, (9), 3 states have call predecessors, (9), 5 states have call successors, (9) [2023-11-06 22:57:20,625 INFO L276 IsEmpty]: Start isEmpty. Operand 404 states and 519 transitions. [2023-11-06 22:57:20,630 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2023-11-06 22:57:20,630 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:20,630 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:20,641 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2023-11-06 22:57:20,836 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:20,837 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:20,837 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:20,837 INFO L85 PathProgramCache]: Analyzing trace with hash -493181504, now seen corresponding path program 1 times [2023-11-06 22:57:20,837 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:20,838 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1078574744] [2023-11-06 22:57:20,838 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:20,838 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:20,870 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,086 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:21,087 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,104 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:57:21,109 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,127 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:57:21,131 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,140 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:21,143 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,153 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:21,155 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,158 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2023-11-06 22:57:21,183 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,187 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2023-11-06 22:57:21,194 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,198 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:21,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,201 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:21,201 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,202 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 11 proven. 9 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:57:21,203 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:21,203 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1078574744] [2023-11-06 22:57:21,203 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1078574744] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:57:21,203 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [741053066] [2023-11-06 22:57:21,203 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:21,203 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:21,204 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:57:21,205 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:57:21,227 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-06 22:57:21,321 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:21,323 INFO L262 TraceCheckSpWp]: Trace formula consists of 341 conjuncts, 8 conjunts are in the unsatisfiable core [2023-11-06 22:57:21,328 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:57:21,458 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 16 proven. 12 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:57:21,458 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-06 22:57:21,634 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 12 proven. 8 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:57:21,634 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [741053066] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-06 22:57:21,634 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-06 22:57:21,635 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 11 [2023-11-06 22:57:21,635 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [743547449] [2023-11-06 22:57:21,635 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-06 22:57:21,636 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 11 states [2023-11-06 22:57:21,636 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:21,637 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 11 interpolants. [2023-11-06 22:57:21,637 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=86, Unknown=0, NotChecked=0, Total=110 [2023-11-06 22:57:21,637 INFO L87 Difference]: Start difference. First operand 404 states and 519 transitions. Second operand has 11 states, 11 states have (on average 9.272727272727273) internal successors, (102), 8 states have internal predecessors, (102), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:57:22,632 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:22,632 INFO L93 Difference]: Finished difference Result 959 states and 1282 transitions. [2023-11-06 22:57:22,632 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2023-11-06 22:57:22,633 INFO L78 Accepts]: Start accepts. Automaton has has 11 states, 11 states have (on average 9.272727272727273) internal successors, (102), 8 states have internal predecessors, (102), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 101 [2023-11-06 22:57:22,633 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:22,638 INFO L225 Difference]: With dead ends: 959 [2023-11-06 22:57:22,638 INFO L226 Difference]: Without dead ends: 605 [2023-11-06 22:57:22,678 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 257 GetRequests, 217 SyntacticMatches, 8 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 301 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=279, Invalid=843, Unknown=0, NotChecked=0, Total=1122 [2023-11-06 22:57:22,678 INFO L413 NwaCegarLoop]: 78 mSDtfsCounter, 442 mSDsluCounter, 501 mSDsCounter, 0 mSdLazyCounter, 744 mSolverCounterSat, 152 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 448 SdHoareTripleChecker+Valid, 579 SdHoareTripleChecker+Invalid, 896 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 152 IncrementalHoareTripleChecker+Valid, 744 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:22,679 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [448 Valid, 579 Invalid, 896 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [152 Valid, 744 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2023-11-06 22:57:22,680 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 605 states. [2023-11-06 22:57:22,749 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 605 to 563. [2023-11-06 22:57:22,750 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 563 states, 426 states have (on average 1.2253521126760563) internal successors, (522), 453 states have internal predecessors, (522), 70 states have call successors, (70), 61 states have call predecessors, (70), 66 states have return successors, (139), 64 states have call predecessors, (139), 70 states have call successors, (139) [2023-11-06 22:57:22,755 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 563 states to 563 states and 731 transitions. [2023-11-06 22:57:22,755 INFO L78 Accepts]: Start accepts. Automaton has 563 states and 731 transitions. Word has length 101 [2023-11-06 22:57:22,757 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:22,757 INFO L495 AbstractCegarLoop]: Abstraction has 563 states and 731 transitions. [2023-11-06 22:57:22,757 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 11 states, 11 states have (on average 9.272727272727273) internal successors, (102), 8 states have internal predecessors, (102), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:57:22,757 INFO L276 IsEmpty]: Start isEmpty. Operand 563 states and 731 transitions. [2023-11-06 22:57:22,764 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2023-11-06 22:57:22,764 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:22,765 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:22,780 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-06 22:57:22,972 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:22,972 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:22,973 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:22,973 INFO L85 PathProgramCache]: Analyzing trace with hash -879070667, now seen corresponding path program 2 times [2023-11-06 22:57:22,974 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:22,974 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1835739605] [2023-11-06 22:57:22,974 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:22,976 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:23,013 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,265 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:23,266 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,275 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:57:23,280 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,298 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:57:23,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,313 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:23,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,327 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:23,329 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,332 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-06 22:57:23,339 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,421 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:57:23,423 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,426 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:57:23,430 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,539 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:23,541 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,544 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:23,545 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,546 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2023-11-06 22:57:23,548 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,550 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2023-11-06 22:57:23,553 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,556 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:23,557 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,559 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:23,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:23,562 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 49 proven. 23 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2023-11-06 22:57:23,562 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:23,562 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1835739605] [2023-11-06 22:57:23,562 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1835739605] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:57:23,563 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [980948784] [2023-11-06 22:57:23,563 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2023-11-06 22:57:23,563 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:23,563 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:57:23,565 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:57:23,572 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2023-11-06 22:57:23,763 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2023-11-06 22:57:23,763 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2023-11-06 22:57:23,766 INFO L262 TraceCheckSpWp]: Trace formula consists of 455 conjuncts, 10 conjunts are in the unsatisfiable core [2023-11-06 22:57:23,772 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:57:23,893 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 84 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2023-11-06 22:57:23,894 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:57:23,894 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [980948784] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:23,894 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:57:23,894 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 12 [2023-11-06 22:57:23,895 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1647816615] [2023-11-06 22:57:23,895 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:23,895 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:57:23,895 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:23,896 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:57:23,896 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:57:23,897 INFO L87 Difference]: Start difference. First operand 563 states and 731 transitions. Second operand has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:57:24,334 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:24,335 INFO L93 Difference]: Finished difference Result 1451 states and 1937 transitions. [2023-11-06 22:57:24,335 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2023-11-06 22:57:24,336 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 147 [2023-11-06 22:57:24,336 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:24,344 INFO L225 Difference]: With dead ends: 1451 [2023-11-06 22:57:24,345 INFO L226 Difference]: Without dead ends: 937 [2023-11-06 22:57:24,349 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 192 GetRequests, 174 SyntacticMatches, 3 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=57, Invalid=215, Unknown=0, NotChecked=0, Total=272 [2023-11-06 22:57:24,349 INFO L413 NwaCegarLoop]: 176 mSDtfsCounter, 155 mSDsluCounter, 527 mSDsCounter, 0 mSdLazyCounter, 156 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 157 SdHoareTripleChecker+Valid, 703 SdHoareTripleChecker+Invalid, 165 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 156 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:24,350 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [157 Valid, 703 Invalid, 165 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 156 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:57:24,352 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 937 states. [2023-11-06 22:57:24,466 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 937 to 826. [2023-11-06 22:57:24,468 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 826 states, 621 states have (on average 1.2077294685990339) internal successors, (750), 654 states have internal predecessors, (750), 96 states have call successors, (96), 90 states have call predecessors, (96), 108 states have return successors, (196), 101 states have call predecessors, (196), 96 states have call successors, (196) [2023-11-06 22:57:24,474 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 826 states to 826 states and 1042 transitions. [2023-11-06 22:57:24,475 INFO L78 Accepts]: Start accepts. Automaton has 826 states and 1042 transitions. Word has length 147 [2023-11-06 22:57:24,475 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:24,476 INFO L495 AbstractCegarLoop]: Abstraction has 826 states and 1042 transitions. [2023-11-06 22:57:24,476 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:57:24,476 INFO L276 IsEmpty]: Start isEmpty. Operand 826 states and 1042 transitions. [2023-11-06 22:57:24,481 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2023-11-06 22:57:24,481 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:57:24,481 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:24,491 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2023-11-06 22:57:24,688 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2023-11-06 22:57:24,689 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:57:24,689 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:57:24,689 INFO L85 PathProgramCache]: Analyzing trace with hash -2095224393, now seen corresponding path program 1 times [2023-11-06 22:57:24,689 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:57:24,690 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1708163] [2023-11-06 22:57:24,690 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:24,690 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:57:24,718 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,827 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:57:24,828 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,835 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:57:24,839 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,848 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:57:24,851 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:24,858 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,862 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:57:24,864 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,866 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-06 22:57:24,872 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,891 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:57:24,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,894 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:57:24,898 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,929 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:24,931 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,932 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:24,933 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,935 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2023-11-06 22:57:24,936 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,938 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2023-11-06 22:57:24,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,946 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:57:24,948 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:57:24,951 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:24,953 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 53 trivial. 0 not checked. [2023-11-06 22:57:24,953 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:57:24,954 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1708163] [2023-11-06 22:57:24,954 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1708163] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:57:24,954 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [58290814] [2023-11-06 22:57:24,954 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:57:24,955 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:57:24,955 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:57:24,956 INFO L229 MonitoredProcess]: Starting monitored process 5 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:57:24,975 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Waiting until timeout for monitored process [2023-11-06 22:57:25,099 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:57:25,102 INFO L262 TraceCheckSpWp]: Trace formula consists of 456 conjuncts, 5 conjunts are in the unsatisfiable core [2023-11-06 22:57:25,111 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:57:25,133 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 70 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2023-11-06 22:57:25,133 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:57:25,133 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [58290814] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:57:25,133 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:57:25,133 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [8] total 8 [2023-11-06 22:57:25,136 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [403521637] [2023-11-06 22:57:25,136 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:57:25,136 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:57:25,136 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:57:25,137 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:57:25,137 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:57:25,138 INFO L87 Difference]: Start difference. First operand 826 states and 1042 transitions. Second operand has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:57:25,222 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:57:25,222 INFO L93 Difference]: Finished difference Result 1128 states and 1412 transitions. [2023-11-06 22:57:25,223 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:57:25,223 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) Word has length 147 [2023-11-06 22:57:25,223 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:57:25,224 INFO L225 Difference]: With dead ends: 1128 [2023-11-06 22:57:25,224 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:57:25,228 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 184 GetRequests, 176 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=23, Invalid=67, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:57:25,229 INFO L413 NwaCegarLoop]: 107 mSDtfsCounter, 6 mSDsluCounter, 305 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 6 SdHoareTripleChecker+Valid, 412 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:57:25,229 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [6 Valid, 412 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:57:25,230 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:57:25,231 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:57:25,231 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:57:25,231 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:57:25,232 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 147 [2023-11-06 22:57:25,232 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:57:25,232 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:57:25,232 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:57:25,232 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:57:25,233 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:57:25,235 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:57:25,248 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (5)] Forceful destruction successful, exit code 0 [2023-11-06 22:57:25,448 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 5 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable11 [2023-11-06 22:57:25,450 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:57:28,238 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 245 252) no Hoare annotation was computed. [2023-11-06 22:57:28,239 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 245 252) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0))) [2023-11-06 22:57:28,239 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 245 252) no Hoare annotation was computed. [2023-11-06 22:57:28,239 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 135 141) no Hoare annotation was computed. [2023-11-06 22:57:28,239 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 135 141) the Hoare annotation is: true [2023-11-06 22:57:28,239 INFO L899 garLoopResultBuilder]: For program point L447-1(lines 443 454) no Hoare annotation was computed. [2023-11-06 22:57:28,240 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 443 454) the Hoare annotation is: true [2023-11-06 22:57:28,240 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 443 454) no Hoare annotation was computed. [2023-11-06 22:57:28,240 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 913 942) no Hoare annotation was computed. [2023-11-06 22:57:28,240 INFO L899 garLoopResultBuilder]: For program point L927(lines 927 931) no Hoare annotation was computed. [2023-11-06 22:57:28,240 INFO L902 garLoopResultBuilder]: At program point L927-1(lines 927 931) the Hoare annotation is: true [2023-11-06 22:57:28,240 INFO L899 garLoopResultBuilder]: For program point L924(line 924) no Hoare annotation was computed. [2023-11-06 22:57:28,240 INFO L902 garLoopResultBuilder]: At program point L923-2(lines 923 937) the Hoare annotation is: true [2023-11-06 22:57:28,240 INFO L902 garLoopResultBuilder]: At program point L919(line 919) the Hoare annotation is: true [2023-11-06 22:57:28,241 INFO L899 garLoopResultBuilder]: For program point L919-1(line 919) no Hoare annotation was computed. [2023-11-06 22:57:28,241 INFO L902 garLoopResultBuilder]: At program point L938(lines 913 942) the Hoare annotation is: true [2023-11-06 22:57:28,241 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 913 942) the Hoare annotation is: true [2023-11-06 22:57:28,241 INFO L899 garLoopResultBuilder]: For program point L934(line 934) no Hoare annotation was computed. [2023-11-06 22:57:28,241 INFO L899 garLoopResultBuilder]: For program point L122-1(lines 122 128) no Hoare annotation was computed. [2023-11-06 22:57:28,241 INFO L895 garLoopResultBuilder]: At program point L209(line 209) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| ~systemActive~0))) (or .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse2))) [2023-11-06 22:57:28,242 INFO L895 garLoopResultBuilder]: At program point L205(line 205) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| ~systemActive~0))) (or .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse2))) [2023-11-06 22:57:28,242 INFO L895 garLoopResultBuilder]: At program point L201(line 201) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| ~systemActive~0))) (or .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse2))) [2023-11-06 22:57:28,242 INFO L899 garLoopResultBuilder]: For program point L201-1(line 201) no Hoare annotation was computed. [2023-11-06 22:57:28,242 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 111 134) no Hoare annotation was computed. [2023-11-06 22:57:28,242 INFO L895 garLoopResultBuilder]: At program point L214(line 214) the Hoare annotation is: (let ((.cse1 (= |old(~pumpRunning~0)| 0)) (.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (< |old(~waterLevel~0)| 2) .cse1) (or (not .cse1) (< |old(~waterLevel~0)| 1) (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse0))) [2023-11-06 22:57:28,243 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 487 495) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse3 (<= 2 ~waterLevel~0)) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (<= 1 |timeShift_getWaterLevel_#res#1|))) (and (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0 (and .cse1 (= |old(~waterLevel~0)| 1) .cse2 (= ~waterLevel~0 1)) (and .cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse4 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 (and .cse3 .cse2 .cse4) (< |old(~waterLevel~0)| 2) (and .cse1 (<= 1 ~waterLevel~0) .cse2 .cse4))))) [2023-11-06 22:57:28,243 INFO L895 garLoopResultBuilder]: At program point L214-1(lines 195 219) the Hoare annotation is: (let ((.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse4 (< |old(~waterLevel~0)| 1)) (.cse2 (not (= 1 ~systemActive~0)))) (and (let ((.cse0 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or (and (<= 2 ~waterLevel~0) .cse0) (and .cse1 (<= 1 ~waterLevel~0) .cse0) .cse2 (< |old(~waterLevel~0)| 2))) (or .cse3 .cse4 .cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (or (< 1 |old(~waterLevel~0)|) .cse3 .cse1 .cse4 .cse2))) [2023-11-06 22:57:28,243 INFO L899 garLoopResultBuilder]: For program point L532(lines 532 538) no Hoare annotation was computed. [2023-11-06 22:57:28,243 INFO L899 garLoopResultBuilder]: For program point L115-1(lines 114 133) no Hoare annotation was computed. [2023-11-06 22:57:28,243 INFO L899 garLoopResultBuilder]: For program point L528(lines 528 541) no Hoare annotation was computed. [2023-11-06 22:57:28,244 INFO L895 garLoopResultBuilder]: At program point L528-1(lines 520 544) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (= ~pumpRunning~0 0)) (.cse5 (< |old(~waterLevel~0)| 2)) (.cse3 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~7#1|)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|))) (and (or (< 1 |old(~waterLevel~0)|) .cse0 (< |old(~waterLevel~0)| 1) .cse1 (and .cse2 .cse3 .cse4 (= ~waterLevel~0 1))) (or .cse0 .cse1 .cse5 (= |old(~waterLevel~0)| ~waterLevel~0)) (let ((.cse6 (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse1 (and .cse2 .cse3 (<= 1 ~waterLevel~0) .cse4 .cse6) .cse5 (and (<= 2 ~waterLevel~0) .cse3 .cse4 .cse6))))) [2023-11-06 22:57:28,244 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2023-11-06 22:57:28,244 INFO L899 garLoopResultBuilder]: For program point L203(lines 203 211) no Hoare annotation was computed. [2023-11-06 22:57:28,244 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 50 57) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (< |old(~waterLevel~0)| 2)) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (= |old(~waterLevel~0)| ~systemActive~0))))) [2023-11-06 22:57:28,244 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 111 134) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse1)) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) (and (= ~pumpRunning~0 0) .cse1) .cse0))) [2023-11-06 22:57:28,244 INFO L899 garLoopResultBuilder]: For program point L199(lines 199 216) no Hoare annotation was computed. [2023-11-06 22:57:28,244 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 111 134) no Hoare annotation was computed. [2023-11-06 22:57:28,245 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 264 272) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0)))) (and (or .cse0 (< |old(~waterLevel~0)| 2)) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (not (= |old(~waterLevel~0)| ~systemActive~0))))) [2023-11-06 22:57:28,245 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2023-11-06 22:57:28,245 INFO L899 garLoopResultBuilder]: For program point L423(lines 423 427) no Hoare annotation was computed. [2023-11-06 22:57:28,245 INFO L895 garLoopResultBuilder]: At program point L423-2(lines 419 430) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (< |old(~waterLevel~0)| 2))) (and (or .cse0 .cse1 (not (= |old(~waterLevel~0)| ~systemActive~0))) (or .cse1 .cse2 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0) (<= ~waterLevel~0 |old(~waterLevel~0)|))) (or .cse0 .cse1 .cse2))) [2023-11-06 22:57:28,245 INFO L895 garLoopResultBuilder]: At program point L407(lines 360 408) the Hoare annotation is: false [2023-11-06 22:57:28,245 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 974 983) the Hoare annotation is: true [2023-11-06 22:57:28,246 INFO L899 garLoopResultBuilder]: For program point L362(lines 361 406) no Hoare annotation was computed. [2023-11-06 22:57:28,246 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 73 79) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:57:28,246 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 984 1006) the Hoare annotation is: true [2023-11-06 22:57:28,246 INFO L899 garLoopResultBuilder]: For program point L391(lines 391 402) no Hoare annotation was computed. [2023-11-06 22:57:28,246 INFO L899 garLoopResultBuilder]: For program point L994(lines 994 1001) no Hoare annotation was computed. [2023-11-06 22:57:28,246 INFO L899 garLoopResultBuilder]: For program point L994-2(lines 994 1001) no Hoare annotation was computed. [2023-11-06 22:57:28,246 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:57:28,246 INFO L895 garLoopResultBuilder]: At program point L383(line 383) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2023-11-06 22:57:28,247 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:57:28,247 INFO L895 garLoopResultBuilder]: At program point L404(lines 361 406) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2023-11-06 22:57:28,251 INFO L899 garLoopResultBuilder]: For program point L371(lines 371 377) no Hoare annotation was computed. [2023-11-06 22:57:28,252 INFO L899 garLoopResultBuilder]: For program point L371-1(lines 371 377) no Hoare annotation was computed. [2023-11-06 22:57:28,252 INFO L899 garLoopResultBuilder]: For program point L363(lines 363 367) no Hoare annotation was computed. [2023-11-06 22:57:28,252 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 967 973) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:57:28,252 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:57:28,252 INFO L899 garLoopResultBuilder]: For program point L397(lines 397 401) no Hoare annotation was computed. [2023-11-06 22:57:28,253 INFO L895 garLoopResultBuilder]: At program point L397-2(lines 391 402) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2023-11-06 22:57:28,253 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:57:28,253 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 80 86) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:57:28,253 INFO L899 garLoopResultBuilder]: For program point L381(lines 381 387) no Hoare annotation was computed. [2023-11-06 22:57:28,254 INFO L899 garLoopResultBuilder]: For program point L381-1(lines 381 387) no Hoare annotation was computed. [2023-11-06 22:57:28,254 INFO L902 garLoopResultBuilder]: At program point L410(lines 351 414) the Hoare annotation is: true [2023-11-06 22:57:28,254 INFO L895 garLoopResultBuilder]: At program point L373(line 373) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (<= 2 ~waterLevel~0) .cse0 .cse1) (and (= ~pumpRunning~0 0) .cse0 .cse1 (<= 1 ~waterLevel~0)))) [2023-11-06 22:57:28,254 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 87 95) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:57:28,255 INFO L899 garLoopResultBuilder]: For program point L318(lines 318 322) no Hoare annotation was computed. [2023-11-06 22:57:28,256 INFO L895 garLoopResultBuilder]: At program point L157(line 157) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) (.cse0 (= |old(~pumpRunning~0)| 0))) (or (not .cse0) (and .cse1 (<= 2 ~waterLevel~0) .cse2 .cse0) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1 .cse2 .cse0))) [2023-11-06 22:57:28,257 INFO L899 garLoopResultBuilder]: For program point L318-2(lines 318 322) no Hoare annotation was computed. [2023-11-06 22:57:28,258 INFO L899 garLoopResultBuilder]: For program point L151(lines 151 159) no Hoare annotation was computed. [2023-11-06 22:57:28,258 INFO L899 garLoopResultBuilder]: For program point L500(lines 500 506) no Hoare annotation was computed. [2023-11-06 22:57:28,258 INFO L899 garLoopResultBuilder]: For program point L147(lines 147 164) no Hoare annotation was computed. [2023-11-06 22:57:28,259 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 143 167) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0))) [2023-11-06 22:57:28,259 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 496 509) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (not (= 1 ~systemActive~0))) (.cse1 (= ~pumpRunning~0 0))) (and (or .cse0 .cse1 .cse2 (< ~waterLevel~0 2)) (or .cse0 .cse2 (not (= ~waterLevel~0 ~systemActive~0)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse1)))) [2023-11-06 22:57:28,259 INFO L895 garLoopResultBuilder]: At program point L162(line 162) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0))) [2023-11-06 22:57:28,259 INFO L899 garLoopResultBuilder]: For program point L162-1(lines 143 167) no Hoare annotation was computed. [2023-11-06 22:57:28,259 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 309 327) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0)) (and .cse0 (<= 2 ~waterLevel~0)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0 (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~4#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0)))) [2023-11-06 22:57:28,260 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 143 167) no Hoare annotation was computed. [2023-11-06 22:57:28,260 INFO L899 garLoopResultBuilder]: For program point L235(lines 235 241) no Hoare annotation was computed. [2023-11-06 22:57:28,260 INFO L895 garLoopResultBuilder]: At program point L233(line 233) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 (< ~waterLevel~0 1) .cse1 (< 1 ~waterLevel~0)) (or .cse0 (= ~pumpRunning~0 0) .cse1 (< ~waterLevel~0 2)))) [2023-11-06 22:57:28,261 INFO L895 garLoopResultBuilder]: At program point L235-2(lines 228 244) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0)) (< 1 ~waterLevel~0)) [2023-11-06 22:57:28,261 INFO L899 garLoopResultBuilder]: For program point L233-1(line 233) no Hoare annotation was computed. [2023-11-06 22:57:28,261 INFO L895 garLoopResultBuilder]: At program point activatePump__wrappee__lowWaterSensor_returnLabel#1(lines 220 227) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0)) (< 1 ~waterLevel~0)) [2023-11-06 22:57:28,261 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 431 442) no Hoare annotation was computed. [2023-11-06 22:57:28,261 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 431 442) the Hoare annotation is: (let ((.cse0 (not (= 1 ~systemActive~0))) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (< |old(~waterLevel~0)| 2) .cse1) (or (< |old(~waterLevel~0)| 1) (not (= ~pumpRunning~0 0)) .cse0 .cse1))) [2023-11-06 22:57:28,262 INFO L899 garLoopResultBuilder]: For program point L435-1(lines 431 442) no Hoare annotation was computed. [2023-11-06 22:57:28,262 INFO L895 garLoopResultBuilder]: At program point L188(line 188) the Hoare annotation is: (or (< ~waterLevel~0 1) (not (= 1 ~systemActive~0)) (and (= ~pumpRunning~0 0) (= |old(~pumpRunning~0)| 0))) [2023-11-06 22:57:28,262 INFO L899 garLoopResultBuilder]: For program point L188-1(lines 169 193) no Hoare annotation was computed. [2023-11-06 22:57:28,263 INFO L899 garLoopResultBuilder]: For program point L337(lines 337 341) no Hoare annotation was computed. [2023-11-06 22:57:28,263 INFO L899 garLoopResultBuilder]: For program point L337-2(lines 337 341) no Hoare annotation was computed. [2023-11-06 22:57:28,263 INFO L895 garLoopResultBuilder]: At program point isLowWaterSensorDry_returnLabel#1(lines 510 518) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0))))) [2023-11-06 22:57:28,263 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 169 193) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (not (= 1 ~systemActive~0))) [2023-11-06 22:57:28,264 INFO L895 garLoopResultBuilder]: At program point isLowWaterLevel_returnLabel#1(lines 328 346) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp~5#1| 0) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp___0~1#1|))))) [2023-11-06 22:57:28,264 INFO L895 garLoopResultBuilder]: At program point L183(line 183) the Hoare annotation is: (or (< ~waterLevel~0 1) (not (= 1 ~systemActive~0))) [2023-11-06 22:57:28,264 INFO L895 garLoopResultBuilder]: At program point L179(line 179) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (not (= 1 ~systemActive~0)))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__methaneQuery_~tmp~1#1|))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2023-11-06 22:57:28,264 INFO L899 garLoopResultBuilder]: For program point L177(lines 177 185) no Hoare annotation was computed. [2023-11-06 22:57:28,265 INFO L899 garLoopResultBuilder]: For program point L173(lines 173 190) no Hoare annotation was computed. [2023-11-06 22:57:28,265 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 169 193) no Hoare annotation was computed. [2023-11-06 22:57:28,265 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCritical_returnLabel#1(lines 455 463) the Hoare annotation is: true [2023-11-06 22:57:28,265 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 253 263) no Hoare annotation was computed. [2023-11-06 22:57:28,265 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 253 263) the Hoare annotation is: true [2023-11-06 22:57:28,266 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 253 263) no Hoare annotation was computed. [2023-11-06 22:57:28,268 INFO L445 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:57:28,270 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:57:28,328 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:57:28 BoogieIcfgContainer [2023-11-06 22:57:28,330 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:57:28,331 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:57:28,331 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:57:28,332 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:57:28,332 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:57:14" (3/4) ... [2023-11-06 22:57:28,335 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:57:28,339 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-06 22:57:28,340 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:57:28,340 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:57:28,340 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:57:28,340 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:57:28,341 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:57:28,341 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:57:28,341 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:57:28,341 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2023-11-06 22:57:28,361 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 18 nodes and edges [2023-11-06 22:57:28,362 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:57:28,363 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:57:28,364 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:57:28,365 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:57:28,400 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive))) && ((!((1 == systemActive)) || (\old(waterLevel) < 2)) || (((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel))))) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2))) [2023-11-06 22:57:28,401 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((2 <= waterLevel) && (waterLevel <= \old(waterLevel))) || (((pumpRunning == 0) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel)))) || !((1 == systemActive))) || (\old(waterLevel) < 2)) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || (\old(waterLevel) == waterLevel))) && (((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (pumpRunning == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive)))) [2023-11-06 22:57:28,403 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (\old(waterLevel) == 1)) && (1 <= \result)) && (waterLevel == 1))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((2 <= waterLevel) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) [2023-11-06 22:57:28,405 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (waterLevel == 1))) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((((pumpRunning == 0) && (1 <= tmp)) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((2 <= waterLevel) && (1 <= tmp)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) [2023-11-06 22:57:28,405 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || ((pumpRunning == \old(pumpRunning)) && (\result == 0)))) [2023-11-06 22:57:28,406 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || !((1 == systemActive))) || (waterLevel < 2)) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((waterLevel == systemActive))) || ((1 <= \result) && (pumpRunning == 0)))) [2023-11-06 22:57:28,406 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) [2023-11-06 22:57:28,406 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) [2023-11-06 22:57:28,407 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) [2023-11-06 22:57:28,410 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || (((((pumpRunning == \old(pumpRunning)) && (tmp == 0)) && (1 <= \result)) && (\result == 0)) && (1 <= tmp___0)))) [2023-11-06 22:57:28,411 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (((((1 <= \result) && (pumpRunning == 0)) && (1 <= tmp)) && (\result == 0)) && (tmp___0 == 0))) [2023-11-06 22:57:28,411 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) [2023-11-06 22:57:28,477 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive))) && ((!((1 == systemActive)) || (\old(waterLevel) < 2)) || (((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel))))) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2))) [2023-11-06 22:57:28,478 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((2 <= waterLevel) && (waterLevel <= \old(waterLevel))) || (((pumpRunning == 0) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel)))) || !((1 == systemActive))) || (\old(waterLevel) < 2)) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || (\old(waterLevel) == waterLevel))) && (((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (pumpRunning == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive)))) [2023-11-06 22:57:28,479 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (\old(waterLevel) == 1)) && (1 <= \result)) && (waterLevel == 1))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((2 <= waterLevel) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) [2023-11-06 22:57:28,479 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (waterLevel == 1))) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((((pumpRunning == 0) && (1 <= tmp)) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((2 <= waterLevel) && (1 <= tmp)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) [2023-11-06 22:57:28,479 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || ((pumpRunning == \old(pumpRunning)) && (\result == 0)))) [2023-11-06 22:57:28,480 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || !((1 == systemActive))) || (waterLevel < 2)) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((waterLevel == systemActive))) || ((1 <= \result) && (pumpRunning == 0)))) [2023-11-06 22:57:28,480 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) [2023-11-06 22:57:28,480 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) [2023-11-06 22:57:28,481 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) [2023-11-06 22:57:28,481 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || (((((pumpRunning == \old(pumpRunning)) && (tmp == 0)) && (1 <= \result)) && (\result == 0)) && (1 <= tmp___0)))) [2023-11-06 22:57:28,483 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (((((1 <= \result) && (pumpRunning == 0)) && (1 <= tmp)) && (\result == 0)) && (tmp___0 == 0))) [2023-11-06 22:57:28,483 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) [2023-11-06 22:57:28,527 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:57:28,527 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:57:28,527 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:57:28,528 INFO L158 Benchmark]: Toolchain (without parser) took 15617.91ms. Allocated memory was 167.8MB in the beginning and 293.6MB in the end (delta: 125.8MB). Free memory was 134.9MB in the beginning and 259.9MB in the end (delta: -125.0MB). Peak memory consumption was 172.8MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,529 INFO L158 Benchmark]: CDTParser took 0.35ms. Allocated memory is still 167.8MB. Free memory is still 126.4MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:57:28,529 INFO L158 Benchmark]: CACSL2BoogieTranslator took 503.00ms. Allocated memory is still 167.8MB. Free memory was 134.6MB in the beginning and 115.1MB in the end (delta: 19.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,529 INFO L158 Benchmark]: Boogie Procedure Inliner took 62.85ms. Allocated memory is still 167.8MB. Free memory was 115.1MB in the beginning and 112.6MB in the end (delta: 2.5MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,530 INFO L158 Benchmark]: Boogie Preprocessor took 36.12ms. Allocated memory is still 167.8MB. Free memory was 112.6MB in the beginning and 111.1MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:57:28,530 INFO L158 Benchmark]: RCFGBuilder took 637.30ms. Allocated memory is still 167.8MB. Free memory was 111.1MB in the beginning and 93.1MB in the end (delta: 18.0MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,530 INFO L158 Benchmark]: TraceAbstraction took 14172.37ms. Allocated memory was 167.8MB in the beginning and 293.6MB in the end (delta: 125.8MB). Free memory was 92.5MB in the beginning and 99.7MB in the end (delta: -7.2MB). Peak memory consumption was 129.7MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,531 INFO L158 Benchmark]: Witness Printer took 196.47ms. Allocated memory is still 293.6MB. Free memory was 99.7MB in the beginning and 259.9MB in the end (delta: -160.3MB). Peak memory consumption was 9.6MB. Max. memory is 16.1GB. [2023-11-06 22:57:28,533 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.35ms. Allocated memory is still 167.8MB. Free memory is still 126.4MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 503.00ms. Allocated memory is still 167.8MB. Free memory was 134.6MB in the beginning and 115.1MB in the end (delta: 19.4MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 62.85ms. Allocated memory is still 167.8MB. Free memory was 115.1MB in the beginning and 112.6MB in the end (delta: 2.5MB). Peak memory consumption was 4.2MB. Max. memory is 16.1GB. * Boogie Preprocessor took 36.12ms. Allocated memory is still 167.8MB. Free memory was 112.6MB in the beginning and 111.1MB in the end (delta: 1.5MB). There was no memory consumed. Max. memory is 16.1GB. * RCFGBuilder took 637.30ms. Allocated memory is still 167.8MB. Free memory was 111.1MB in the beginning and 93.1MB in the end (delta: 18.0MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * TraceAbstraction took 14172.37ms. Allocated memory was 167.8MB in the beginning and 293.6MB in the end (delta: 125.8MB). Free memory was 92.5MB in the beginning and 99.7MB in the end (delta: -7.2MB). Peak memory consumption was 129.7MB. Max. memory is 16.1GB. * Witness Printer took 196.47ms. Allocated memory is still 293.6MB. Free memory was 99.7MB in the beginning and 259.9MB in the end (delta: -160.3MB). Peak memory consumption was 9.6MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] - GenericResultAtLocation [Line: 58]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [58] - GenericResultAtLocation [Line: 96]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [96] - GenericResultAtLocation [Line: 347]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [347] - GenericResultAtLocation [Line: 415]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [415] - GenericResultAtLocation [Line: 519]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [519] - GenericResultAtLocation [Line: 545]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [545] - GenericResultAtLocation [Line: 911]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [911] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 103 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 14.0s, OverallIterations: 12, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 4.9s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2093 SdHoareTripleChecker+Valid, 2.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2054 mSDsluCounter, 3865 SdHoareTripleChecker+Invalid, 2.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2734 mSDsCounter, 594 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2624 IncrementalHoareTripleChecker+Invalid, 3218 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 594 mSolverCounterUnsat, 1131 mSDtfsCounter, 2624 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 880 GetRequests, 740 SyntacticMatches, 12 SemanticMatches, 128 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 532 ImplicationChecksByTransitivity, 1.2s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=826occurred in iteration=11, InterpolantAutomatonStates: 121, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.7s AutomataMinimizationTime, 12 MinimizatonAttempts, 269 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 48 LocationsWithAnnotation, 1939 PreInvPairs, 2059 NumberOfFragments, 1007 HoareAnnotationTreeSize, 1939 FomulaSimplifications, 6760 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 48 FomulaSimplificationsInter, 5103 FormulaSimplificationTreeSizeReductionInter, 2.5s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.5s SatisfiabilityAnalysisTime, 3.4s InterpolantComputationTime, 1296 NumberOfCodeBlocks, 1296 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 1380 ConstructedInterpolants, 0 QuantifiedInterpolants, 2496 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1591 ConjunctsInSsa, 27 ConjunctsInUnsatCore, 17 InterpolantComputations, 11 PerfectInterpolantSequences, 486/548 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 195]: Loop Invariant Derived loop invariant: (((((((2 <= waterLevel) && (waterLevel <= \old(waterLevel))) || (((pumpRunning == 0) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel)))) || !((1 == systemActive))) || (\old(waterLevel) < 2)) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || (\old(waterLevel) == waterLevel))) && (((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (pumpRunning == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive)))) - InvariantResult [Line: 455]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 967]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 220]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) - InvariantResult [Line: 913]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 419]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive))) && ((!((1 == systemActive)) || (\old(waterLevel) < 2)) || (((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel)) && (waterLevel <= \old(waterLevel))))) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2))) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) - InvariantResult [Line: 73]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 487]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (\old(waterLevel) == 1)) && (1 <= \result)) && (waterLevel == 1))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((2 <= waterLevel) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) - InvariantResult [Line: 87]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 80]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 328]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || (((((pumpRunning == \old(pumpRunning)) && (tmp == 0)) && (1 <= \result)) && (\result == 0)) && (1 <= tmp___0)))) - InvariantResult [Line: 520]: Loop Invariant Derived loop invariant: (((((((1 < \old(waterLevel)) || !((\old(pumpRunning) == 0))) || (\old(waterLevel) < 1)) || !((1 == systemActive))) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (waterLevel == 1))) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel))) && (((!((1 == systemActive)) || (((((pumpRunning == 0) && (1 <= tmp)) && (1 <= waterLevel)) && (1 <= \result)) && (waterLevel <= \old(waterLevel)))) || (\old(waterLevel) < 2)) || ((((2 <= waterLevel) && (1 <= tmp)) && (1 <= \result)) && (waterLevel <= \old(waterLevel))))) - InvariantResult [Line: 510]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) && (((waterLevel < 1) || !((1 == systemActive))) || ((pumpRunning == \old(pumpRunning)) && (\result == 0)))) - InvariantResult [Line: 984]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 264]: Loop Invariant Derived loop invariant: ((!((1 == systemActive)) || (\old(waterLevel) < 2)) && ((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((\old(waterLevel) == systemActive)))) - InvariantResult [Line: 360]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 496]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || !((1 == systemActive))) || (waterLevel < 2)) && (((!((\old(pumpRunning) == 0)) || !((1 == systemActive))) || !((waterLevel == systemActive))) || ((1 <= \result) && (pumpRunning == 0)))) - InvariantResult [Line: 351]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 228]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || (1 < waterLevel)) - InvariantResult [Line: 309]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || !((1 == systemActive))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (((((1 <= \result) && (pumpRunning == 0)) && (1 <= tmp)) && (\result == 0)) && (tmp___0 == 0))) - InvariantResult [Line: 361]: Loop Invariant Derived loop invariant: ((((2 <= waterLevel) && (1 == systemActive)) && (splverifierCounter == 0)) || ((((pumpRunning == 0) && (1 == systemActive)) && (splverifierCounter == 0)) && (1 <= waterLevel))) - InvariantResult [Line: 974]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 923]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:57:28,594 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ca94d381-ab88-456b-95e4-30a04968cbcb/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE