./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 894b9126919d6af09c0902d1c20b8183acfd3589fe20590a119ca487cf6e7a3f --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:41:24,393 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:41:24,473 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:41:24,479 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:41:24,480 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:41:24,506 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:41:24,507 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:41:24,508 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:41:24,509 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:41:24,509 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:41:24,510 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:41:24,511 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:41:24,511 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:41:24,512 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:41:24,513 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:41:24,513 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:41:24,514 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:41:24,515 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:41:24,515 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:41:24,516 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:41:24,517 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:41:24,517 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:41:24,518 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:41:24,518 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:41:24,519 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:41:24,520 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:41:24,520 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:41:24,521 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:41:24,521 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:41:24,522 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:41:24,522 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:41:24,523 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:41:24,523 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:41:24,524 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:41:24,524 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:41:24,524 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:41:24,525 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:41:24,525 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:41:24,525 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:41:24,526 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 894b9126919d6af09c0902d1c20b8183acfd3589fe20590a119ca487cf6e7a3f [2023-11-06 22:41:24,770 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:41:24,802 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:41:24,805 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:41:24,807 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:41:24,807 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:41:24,809 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c [2023-11-06 22:41:27,912 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:41:28,249 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:41:28,249 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c [2023-11-06 22:41:28,265 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/data/412f06ba3/f9a0318958b241ccb1e187f441b83336/FLAG23be57985 [2023-11-06 22:41:28,281 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/data/412f06ba3/f9a0318958b241ccb1e187f441b83336 [2023-11-06 22:41:28,284 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:41:28,286 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:41:28,287 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:41:28,287 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:41:28,293 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:41:28,294 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,295 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@31b595b3 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28, skipping insertion in model container [2023-11-06 22:41:28,295 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,399 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:41:28,605 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c[1605,1618] [2023-11-06 22:41:28,778 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:41:28,791 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:41:28,801 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] [2023-11-06 22:41:28,802 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [58] [2023-11-06 22:41:28,802 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [130] [2023-11-06 22:41:28,803 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [388] [2023-11-06 22:41:28,803 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [415] [2023-11-06 22:41:28,803 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [453] [2023-11-06 22:41:28,803 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [549] [2023-11-06 22:41:28,804 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [915] [2023-11-06 22:41:28,808 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/sv-benchmarks/c/product-lines/minepump_spec4_product62.cil.c[1605,1618] [2023-11-06 22:41:28,871 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:41:28,902 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:41:28,902 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28 WrapperNode [2023-11-06 22:41:28,902 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:41:28,903 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:41:28,904 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:41:28,904 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:41:28,911 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,924 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,957 INFO L138 Inliner]: procedures = 58, calls = 105, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 239 [2023-11-06 22:41:28,958 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:41:28,959 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:41:28,959 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:41:28,959 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:41:28,972 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,978 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,982 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,982 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:28,994 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:29,000 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:29,002 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:29,004 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:29,007 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:41:29,008 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:41:29,008 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:41:29,008 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:41:29,010 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (1/1) ... [2023-11-06 22:41:29,017 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:41:29,042 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:41:29,071 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:41:29,088 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:41:29,118 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:41:29,118 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:41:29,118 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:41:29,119 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:41:29,121 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:41:29,121 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:41:29,122 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:41:29,122 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:41:29,122 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:41:29,122 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:41:29,122 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:41:29,123 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:41:29,123 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:41:29,123 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2023-11-06 22:41:29,123 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2023-11-06 22:41:29,124 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-06 22:41:29,124 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-06 22:41:29,124 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:41:29,124 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:41:29,125 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:41:29,125 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:41:29,125 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:41:29,259 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:41:29,263 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:41:29,606 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:41:29,614 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:41:29,615 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:41:29,617 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:41:29 BoogieIcfgContainer [2023-11-06 22:41:29,617 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:41:29,620 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:41:29,621 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:41:29,624 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:41:29,625 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:41:28" (1/3) ... [2023-11-06 22:41:29,625 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7c246bad and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:41:29, skipping insertion in model container [2023-11-06 22:41:29,626 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:41:28" (2/3) ... [2023-11-06 22:41:29,626 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@7c246bad and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:41:29, skipping insertion in model container [2023-11-06 22:41:29,626 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:41:29" (3/3) ... [2023-11-06 22:41:29,628 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product62.cil.c [2023-11-06 22:41:29,649 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:41:29,650 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:41:29,706 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:41:29,713 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4cd2f5bd, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:41:29,714 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:41:29,718 INFO L276 IsEmpty]: Start isEmpty. Operand has 104 states, 77 states have (on average 1.3766233766233766) internal successors, (106), 87 states have internal predecessors, (106), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2023-11-06 22:41:29,729 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2023-11-06 22:41:29,729 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:29,730 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:29,730 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:29,751 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:29,751 INFO L85 PathProgramCache]: Analyzing trace with hash 1971423540, now seen corresponding path program 1 times [2023-11-06 22:41:29,758 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:29,759 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1481431452] [2023-11-06 22:41:29,759 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:29,759 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:29,884 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:29,960 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:29,960 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:29,961 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1481431452] [2023-11-06 22:41:29,961 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1481431452] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:29,962 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:29,962 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:41:29,964 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1740159872] [2023-11-06 22:41:29,965 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:29,971 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:41:29,973 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:30,016 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:41:30,019 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:41:30,023 INFO L87 Difference]: Start difference. First operand has 104 states, 77 states have (on average 1.3766233766233766) internal successors, (106), 87 states have internal predecessors, (106), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,100 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:30,100 INFO L93 Difference]: Finished difference Result 200 states and 271 transitions. [2023-11-06 22:41:30,101 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:41:30,104 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2023-11-06 22:41:30,104 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:30,113 INFO L225 Difference]: With dead ends: 200 [2023-11-06 22:41:30,113 INFO L226 Difference]: Without dead ends: 95 [2023-11-06 22:41:30,117 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:41:30,121 INFO L413 NwaCegarLoop]: 132 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 132 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:30,122 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 132 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:41:30,138 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 95 states. [2023-11-06 22:41:30,165 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 95 to 95. [2023-11-06 22:41:30,167 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 95 states, 70 states have (on average 1.3142857142857143) internal successors, (92), 79 states have internal predecessors, (92), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2023-11-06 22:41:30,170 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 95 states to 95 states and 123 transitions. [2023-11-06 22:41:30,171 INFO L78 Accepts]: Start accepts. Automaton has 95 states and 123 transitions. Word has length 19 [2023-11-06 22:41:30,172 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:30,172 INFO L495 AbstractCegarLoop]: Abstraction has 95 states and 123 transitions. [2023-11-06 22:41:30,172 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,172 INFO L276 IsEmpty]: Start isEmpty. Operand 95 states and 123 transitions. [2023-11-06 22:41:30,174 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2023-11-06 22:41:30,175 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:30,175 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:30,175 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:41:30,176 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:30,176 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:30,177 INFO L85 PathProgramCache]: Analyzing trace with hash -856589602, now seen corresponding path program 1 times [2023-11-06 22:41:30,177 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:30,177 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [166148762] [2023-11-06 22:41:30,177 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:30,178 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:30,203 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:30,340 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:30,341 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:30,341 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [166148762] [2023-11-06 22:41:30,342 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [166148762] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:30,342 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:30,342 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:41:30,342 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1290043002] [2023-11-06 22:41:30,343 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:30,344 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:41:30,345 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:30,346 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:41:30,346 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:41:30,346 INFO L87 Difference]: Start difference. First operand 95 states and 123 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,371 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:30,371 INFO L93 Difference]: Finished difference Result 155 states and 201 transitions. [2023-11-06 22:41:30,372 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:41:30,372 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2023-11-06 22:41:30,373 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:30,375 INFO L225 Difference]: With dead ends: 155 [2023-11-06 22:41:30,375 INFO L226 Difference]: Without dead ends: 86 [2023-11-06 22:41:30,377 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:41:30,379 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 13 mSDsluCounter, 93 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 16 SdHoareTripleChecker+Valid, 203 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:30,380 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [16 Valid, 203 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:41:30,381 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 86 states. [2023-11-06 22:41:30,394 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 86 to 86. [2023-11-06 22:41:30,395 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 64 states have (on average 1.328125) internal successors, (85), 73 states have internal predecessors, (85), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-06 22:41:30,398 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 111 transitions. [2023-11-06 22:41:30,398 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 111 transitions. Word has length 20 [2023-11-06 22:41:30,399 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:30,399 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 111 transitions. [2023-11-06 22:41:30,399 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,400 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 111 transitions. [2023-11-06 22:41:30,401 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2023-11-06 22:41:30,401 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:30,402 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:30,402 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:41:30,402 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:30,403 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:30,403 INFO L85 PathProgramCache]: Analyzing trace with hash 2135542647, now seen corresponding path program 1 times [2023-11-06 22:41:30,404 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:30,404 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2004681461] [2023-11-06 22:41:30,404 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:30,405 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:30,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:30,672 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:30,680 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:30,680 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2004681461] [2023-11-06 22:41:30,681 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2004681461] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:30,681 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:30,681 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:41:30,681 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1368251148] [2023-11-06 22:41:30,682 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:30,682 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:41:30,683 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:30,683 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:41:30,683 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:41:30,684 INFO L87 Difference]: Start difference. First operand 86 states and 111 transitions. Second operand has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,791 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:30,791 INFO L93 Difference]: Finished difference Result 165 states and 216 transitions. [2023-11-06 22:41:30,792 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:41:30,792 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 25 [2023-11-06 22:41:30,797 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:30,799 INFO L225 Difference]: With dead ends: 165 [2023-11-06 22:41:30,803 INFO L226 Difference]: Without dead ends: 86 [2023-11-06 22:41:30,805 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:41:30,809 INFO L413 NwaCegarLoop]: 104 mSDtfsCounter, 136 mSDsluCounter, 176 mSDsCounter, 0 mSdLazyCounter, 9 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 136 SdHoareTripleChecker+Valid, 280 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 9 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:30,810 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [136 Valid, 280 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 9 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:41:30,812 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 86 states. [2023-11-06 22:41:30,827 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 86 to 86. [2023-11-06 22:41:30,827 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 86 states, 64 states have (on average 1.3125) internal successors, (84), 73 states have internal predecessors, (84), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 8 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-06 22:41:30,829 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 86 states to 86 states and 110 transitions. [2023-11-06 22:41:30,830 INFO L78 Accepts]: Start accepts. Automaton has 86 states and 110 transitions. Word has length 25 [2023-11-06 22:41:30,830 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:30,830 INFO L495 AbstractCegarLoop]: Abstraction has 86 states and 110 transitions. [2023-11-06 22:41:30,831 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 4.8) internal successors, (24), 5 states have internal predecessors, (24), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:30,831 INFO L276 IsEmpty]: Start isEmpty. Operand 86 states and 110 transitions. [2023-11-06 22:41:30,833 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2023-11-06 22:41:30,833 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:30,834 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:30,834 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:41:30,834 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:30,835 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:30,835 INFO L85 PathProgramCache]: Analyzing trace with hash -181443690, now seen corresponding path program 1 times [2023-11-06 22:41:30,836 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:30,836 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2091516435] [2023-11-06 22:41:30,836 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:30,837 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:30,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:30,898 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:30,902 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:30,911 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 27 [2023-11-06 22:41:30,913 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:30,918 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:30,918 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:30,918 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2091516435] [2023-11-06 22:41:30,919 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2091516435] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:30,920 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:30,920 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-06 22:41:30,920 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [282612998] [2023-11-06 22:41:30,920 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:30,922 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2023-11-06 22:41:30,922 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:30,923 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2023-11-06 22:41:30,923 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2023-11-06 22:41:30,925 INFO L87 Difference]: Start difference. First operand 86 states and 110 transitions. Second operand has 4 states, 4 states have (on average 8.25) internal successors, (33), 3 states have internal predecessors, (33), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:41:31,126 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:31,126 INFO L93 Difference]: Finished difference Result 241 states and 309 transitions. [2023-11-06 22:41:31,127 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:41:31,127 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 8.25) internal successors, (33), 3 states have internal predecessors, (33), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 38 [2023-11-06 22:41:31,127 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:31,130 INFO L225 Difference]: With dead ends: 241 [2023-11-06 22:41:31,130 INFO L226 Difference]: Without dead ends: 162 [2023-11-06 22:41:31,131 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:41:31,137 INFO L413 NwaCegarLoop]: 80 mSDtfsCounter, 169 mSDsluCounter, 108 mSDsCounter, 0 mSdLazyCounter, 77 mSolverCounterSat, 41 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 173 SdHoareTripleChecker+Valid, 188 SdHoareTripleChecker+Invalid, 118 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 41 IncrementalHoareTripleChecker+Valid, 77 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:31,138 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [173 Valid, 188 Invalid, 118 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [41 Valid, 77 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:41:31,139 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 162 states. [2023-11-06 22:41:31,191 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 162 to 156. [2023-11-06 22:41:31,192 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 156 states, 119 states have (on average 1.26890756302521) internal successors, (151), 128 states have internal predecessors, (151), 16 states have call successors, (16), 15 states have call predecessors, (16), 20 states have return successors, (27), 18 states have call predecessors, (27), 16 states have call successors, (27) [2023-11-06 22:41:31,193 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 156 states to 156 states and 194 transitions. [2023-11-06 22:41:31,194 INFO L78 Accepts]: Start accepts. Automaton has 156 states and 194 transitions. Word has length 38 [2023-11-06 22:41:31,194 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:31,194 INFO L495 AbstractCegarLoop]: Abstraction has 156 states and 194 transitions. [2023-11-06 22:41:31,194 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 8.25) internal successors, (33), 3 states have internal predecessors, (33), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:41:31,195 INFO L276 IsEmpty]: Start isEmpty. Operand 156 states and 194 transitions. [2023-11-06 22:41:31,203 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 47 [2023-11-06 22:41:31,203 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:31,203 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:31,203 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:41:31,203 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:31,204 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:31,204 INFO L85 PathProgramCache]: Analyzing trace with hash -91120732, now seen corresponding path program 1 times [2023-11-06 22:41:31,204 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:31,205 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2030133499] [2023-11-06 22:41:31,205 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:31,205 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:31,254 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:31,428 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:31,433 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:31,440 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:31,443 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:31,448 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:31,449 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:31,451 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:31,451 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:31,451 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2030133499] [2023-11-06 22:41:31,451 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2030133499] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:31,452 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:31,452 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2023-11-06 22:41:31,452 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [748797286] [2023-11-06 22:41:31,452 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:31,453 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2023-11-06 22:41:31,453 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:31,453 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2023-11-06 22:41:31,454 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=56, Unknown=0, NotChecked=0, Total=72 [2023-11-06 22:41:31,454 INFO L87 Difference]: Start difference. First operand 156 states and 194 transitions. Second operand has 9 states, 9 states have (on average 4.333333333333333) internal successors, (39), 8 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:41:32,035 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:32,035 INFO L93 Difference]: Finished difference Result 536 states and 718 transitions. [2023-11-06 22:41:32,036 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 19 states. [2023-11-06 22:41:32,036 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 4.333333333333333) internal successors, (39), 8 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 46 [2023-11-06 22:41:32,037 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:32,046 INFO L225 Difference]: With dead ends: 536 [2023-11-06 22:41:32,047 INFO L226 Difference]: Without dead ends: 387 [2023-11-06 22:41:32,049 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 77 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=113, Invalid=349, Unknown=0, NotChecked=0, Total=462 [2023-11-06 22:41:32,058 INFO L413 NwaCegarLoop]: 97 mSDtfsCounter, 330 mSDsluCounter, 543 mSDsCounter, 0 mSdLazyCounter, 386 mSolverCounterSat, 88 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 335 SdHoareTripleChecker+Valid, 640 SdHoareTripleChecker+Invalid, 474 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 88 IncrementalHoareTripleChecker+Valid, 386 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:32,059 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [335 Valid, 640 Invalid, 474 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [88 Valid, 386 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-06 22:41:32,063 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 387 states. [2023-11-06 22:41:32,152 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 387 to 377. [2023-11-06 22:41:32,153 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 377 states, 286 states have (on average 1.2377622377622377) internal successors, (354), 306 states have internal predecessors, (354), 40 states have call successors, (40), 38 states have call predecessors, (40), 50 states have return successors, (90), 46 states have call predecessors, (90), 40 states have call successors, (90) [2023-11-06 22:41:32,160 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 377 states to 377 states and 484 transitions. [2023-11-06 22:41:32,160 INFO L78 Accepts]: Start accepts. Automaton has 377 states and 484 transitions. Word has length 46 [2023-11-06 22:41:32,161 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:32,161 INFO L495 AbstractCegarLoop]: Abstraction has 377 states and 484 transitions. [2023-11-06 22:41:32,162 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 4.333333333333333) internal successors, (39), 8 states have internal predecessors, (39), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:41:32,162 INFO L276 IsEmpty]: Start isEmpty. Operand 377 states and 484 transitions. [2023-11-06 22:41:32,172 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2023-11-06 22:41:32,173 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:32,173 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:32,173 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:41:32,174 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:32,174 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:32,174 INFO L85 PathProgramCache]: Analyzing trace with hash 1034406580, now seen corresponding path program 1 times [2023-11-06 22:41:32,174 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:32,175 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1746291969] [2023-11-06 22:41:32,175 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:32,175 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:32,197 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,273 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:41:32,274 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,283 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:32,290 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,320 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:41:32,340 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,359 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:32,364 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,426 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:32,429 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,431 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 71 [2023-11-06 22:41:32,434 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,438 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2023-11-06 22:41:32,440 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:32,443 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:41:32,443 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:32,443 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1746291969] [2023-11-06 22:41:32,443 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1746291969] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:32,443 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:32,444 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2023-11-06 22:41:32,444 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2045232517] [2023-11-06 22:41:32,444 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:32,445 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-06 22:41:32,445 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:32,446 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-06 22:41:32,446 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:41:32,446 INFO L87 Difference]: Start difference. First operand 377 states and 484 transitions. Second operand has 8 states, 8 states have (on average 8.5) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) [2023-11-06 22:41:32,882 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:32,882 INFO L93 Difference]: Finished difference Result 840 states and 1145 transitions. [2023-11-06 22:41:32,883 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-06 22:41:32,883 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 8.5) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) Word has length 89 [2023-11-06 22:41:32,885 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:32,889 INFO L225 Difference]: With dead ends: 840 [2023-11-06 22:41:32,889 INFO L226 Difference]: Without dead ends: 470 [2023-11-06 22:41:32,892 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 26 GetRequests, 16 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=43, Invalid=89, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:41:32,894 INFO L413 NwaCegarLoop]: 63 mSDtfsCounter, 108 mSDsluCounter, 301 mSDsCounter, 0 mSdLazyCounter, 365 mSolverCounterSat, 34 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 112 SdHoareTripleChecker+Valid, 364 SdHoareTripleChecker+Invalid, 399 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 34 IncrementalHoareTripleChecker+Valid, 365 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:32,894 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [112 Valid, 364 Invalid, 399 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [34 Valid, 365 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:41:32,897 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 470 states. [2023-11-06 22:41:32,963 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 470 to 431. [2023-11-06 22:41:32,964 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 431 states, 330 states have (on average 1.2242424242424241) internal successors, (404), 355 states have internal predecessors, (404), 44 states have call successors, (44), 38 states have call predecessors, (44), 56 states have return successors, (104), 51 states have call predecessors, (104), 44 states have call successors, (104) [2023-11-06 22:41:32,969 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 431 states to 431 states and 552 transitions. [2023-11-06 22:41:32,970 INFO L78 Accepts]: Start accepts. Automaton has 431 states and 552 transitions. Word has length 89 [2023-11-06 22:41:32,970 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:32,971 INFO L495 AbstractCegarLoop]: Abstraction has 431 states and 552 transitions. [2023-11-06 22:41:32,971 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 8.5) internal successors, (68), 5 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) [2023-11-06 22:41:32,971 INFO L276 IsEmpty]: Start isEmpty. Operand 431 states and 552 transitions. [2023-11-06 22:41:32,974 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2023-11-06 22:41:32,974 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:32,974 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:32,975 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:41:32,975 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:32,976 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:32,976 INFO L85 PathProgramCache]: Analyzing trace with hash -1999643466, now seen corresponding path program 1 times [2023-11-06 22:41:32,976 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:32,976 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [26709844] [2023-11-06 22:41:32,976 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:32,977 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:33,010 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,110 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:41:33,112 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,122 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:33,130 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,172 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:41:33,179 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,208 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:33,212 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,249 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:33,250 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,252 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 71 [2023-11-06 22:41:33,254 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,256 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2023-11-06 22:41:33,257 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,258 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:41:33,259 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:33,259 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [26709844] [2023-11-06 22:41:33,259 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [26709844] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:33,259 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:41:33,260 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2023-11-06 22:41:33,260 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1026329591] [2023-11-06 22:41:33,260 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:33,260 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2023-11-06 22:41:33,261 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:33,261 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2023-11-06 22:41:33,262 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=55, Unknown=0, NotChecked=0, Total=72 [2023-11-06 22:41:33,262 INFO L87 Difference]: Start difference. First operand 431 states and 552 transitions. Second operand has 9 states, 9 states have (on average 7.555555555555555) internal successors, (68), 6 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) [2023-11-06 22:41:33,734 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:33,734 INFO L93 Difference]: Finished difference Result 807 states and 1067 transitions. [2023-11-06 22:41:33,734 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2023-11-06 22:41:33,735 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 7.555555555555555) internal successors, (68), 6 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) Word has length 89 [2023-11-06 22:41:33,735 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:33,738 INFO L225 Difference]: With dead ends: 807 [2023-11-06 22:41:33,738 INFO L226 Difference]: Without dead ends: 383 [2023-11-06 22:41:33,741 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 18 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 11 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=42, Invalid=114, Unknown=0, NotChecked=0, Total=156 [2023-11-06 22:41:33,742 INFO L413 NwaCegarLoop]: 61 mSDtfsCounter, 265 mSDsluCounter, 267 mSDsCounter, 0 mSdLazyCounter, 413 mSolverCounterSat, 82 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 270 SdHoareTripleChecker+Valid, 328 SdHoareTripleChecker+Invalid, 495 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 82 IncrementalHoareTripleChecker+Valid, 413 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:33,742 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [270 Valid, 328 Invalid, 495 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [82 Valid, 413 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:41:33,743 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 383 states. [2023-11-06 22:41:33,794 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 383 to 368. [2023-11-06 22:41:33,795 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 368 states, 280 states have (on average 1.2142857142857142) internal successors, (340), 301 states have internal predecessors, (340), 40 states have call successors, (40), 33 states have call predecessors, (40), 47 states have return successors, (86), 44 states have call predecessors, (86), 40 states have call successors, (86) [2023-11-06 22:41:33,798 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 368 states to 368 states and 466 transitions. [2023-11-06 22:41:33,799 INFO L78 Accepts]: Start accepts. Automaton has 368 states and 466 transitions. Word has length 89 [2023-11-06 22:41:33,799 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:33,799 INFO L495 AbstractCegarLoop]: Abstraction has 368 states and 466 transitions. [2023-11-06 22:41:33,800 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 7.555555555555555) internal successors, (68), 6 states have internal predecessors, (68), 2 states have call successors, (8), 5 states have call predecessors, (8), 2 states have return successors, (7), 2 states have call predecessors, (7), 2 states have call successors, (7) [2023-11-06 22:41:33,800 INFO L276 IsEmpty]: Start isEmpty. Operand 368 states and 466 transitions. [2023-11-06 22:41:33,802 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 90 [2023-11-06 22:41:33,802 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:33,803 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:33,803 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:41:33,803 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:33,803 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:33,804 INFO L85 PathProgramCache]: Analyzing trace with hash -1438943688, now seen corresponding path program 1 times [2023-11-06 22:41:33,804 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:33,804 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [215763685] [2023-11-06 22:41:33,804 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:33,805 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:33,823 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:41:33,896 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,906 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:33,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,930 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:41:33,933 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,937 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:33,940 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,944 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:33,946 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,948 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 71 [2023-11-06 22:41:33,949 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,951 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2023-11-06 22:41:33,953 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:33,957 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 4 proven. 1 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2023-11-06 22:41:33,957 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:33,957 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [215763685] [2023-11-06 22:41:33,957 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [215763685] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:41:33,957 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1697733765] [2023-11-06 22:41:33,958 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:33,958 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:41:33,958 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:41:33,964 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:41:33,992 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-06 22:41:34,094 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:34,113 INFO L262 TraceCheckSpWp]: Trace formula consists of 311 conjuncts, 8 conjunts are in the unsatisfiable core [2023-11-06 22:41:34,121 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:41:34,364 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 8 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:41:34,364 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-06 22:41:34,622 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 13 proven. 4 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2023-11-06 22:41:34,622 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1697733765] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-06 22:41:34,622 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-06 22:41:34,623 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 6, 6] total 12 [2023-11-06 22:41:34,623 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2014424636] [2023-11-06 22:41:34,623 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-06 22:41:34,625 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 12 states [2023-11-06 22:41:34,625 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:34,626 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 12 interpolants. [2023-11-06 22:41:34,627 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=24, Invalid=108, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:41:34,627 INFO L87 Difference]: Start difference. First operand 368 states and 466 transitions. Second operand has 12 states, 12 states have (on average 9.666666666666666) internal successors, (116), 9 states have internal predecessors, (116), 3 states have call successors, (18), 6 states have call predecessors, (18), 4 states have return successors, (16), 4 states have call predecessors, (16), 3 states have call successors, (16) [2023-11-06 22:41:36,216 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:36,216 INFO L93 Difference]: Finished difference Result 813 states and 1099 transitions. [2023-11-06 22:41:36,217 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 48 states. [2023-11-06 22:41:36,217 INFO L78 Accepts]: Start accepts. Automaton has has 12 states, 12 states have (on average 9.666666666666666) internal successors, (116), 9 states have internal predecessors, (116), 3 states have call successors, (18), 6 states have call predecessors, (18), 4 states have return successors, (16), 4 states have call predecessors, (16), 3 states have call successors, (16) Word has length 89 [2023-11-06 22:41:36,217 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:36,221 INFO L225 Difference]: With dead ends: 813 [2023-11-06 22:41:36,222 INFO L226 Difference]: Without dead ends: 500 [2023-11-06 22:41:36,225 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 254 GetRequests, 198 SyntacticMatches, 5 SemanticMatches, 51 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 842 ImplicationChecksByTransitivity, 0.7s TimeCoverageRelationStatistics Valid=481, Invalid=2275, Unknown=0, NotChecked=0, Total=2756 [2023-11-06 22:41:36,226 INFO L413 NwaCegarLoop]: 77 mSDtfsCounter, 638 mSDsluCounter, 566 mSDsCounter, 0 mSdLazyCounter, 910 mSolverCounterSat, 207 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 645 SdHoareTripleChecker+Valid, 643 SdHoareTripleChecker+Invalid, 1117 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 207 IncrementalHoareTripleChecker+Valid, 910 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.8s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:36,226 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [645 Valid, 643 Invalid, 1117 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [207 Valid, 910 Invalid, 0 Unknown, 0 Unchecked, 0.8s Time] [2023-11-06 22:41:36,228 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 500 states. [2023-11-06 22:41:36,310 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 500 to 434. [2023-11-06 22:41:36,311 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 434 states, 328 states have (on average 1.2103658536585367) internal successors, (397), 352 states have internal predecessors, (397), 51 states have call successors, (51), 44 states have call predecessors, (51), 54 states have return successors, (111), 50 states have call predecessors, (111), 51 states have call successors, (111) [2023-11-06 22:41:36,315 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 434 states to 434 states and 559 transitions. [2023-11-06 22:41:36,316 INFO L78 Accepts]: Start accepts. Automaton has 434 states and 559 transitions. Word has length 89 [2023-11-06 22:41:36,316 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:36,316 INFO L495 AbstractCegarLoop]: Abstraction has 434 states and 559 transitions. [2023-11-06 22:41:36,317 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 12 states, 12 states have (on average 9.666666666666666) internal successors, (116), 9 states have internal predecessors, (116), 3 states have call successors, (18), 6 states have call predecessors, (18), 4 states have return successors, (16), 4 states have call predecessors, (16), 3 states have call successors, (16) [2023-11-06 22:41:36,317 INFO L276 IsEmpty]: Start isEmpty. Operand 434 states and 559 transitions. [2023-11-06 22:41:36,320 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 151 [2023-11-06 22:41:36,320 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:36,320 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:36,333 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-06 22:41:36,527 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:41:36,528 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:36,528 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:36,528 INFO L85 PathProgramCache]: Analyzing trace with hash 1270234994, now seen corresponding path program 1 times [2023-11-06 22:41:36,528 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:36,528 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [77253732] [2023-11-06 22:41:36,529 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:36,529 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:36,566 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,745 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:41:36,746 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,753 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:36,759 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,775 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:41:36,779 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,788 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:36,791 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:36,804 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,806 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2023-11-06 22:41:36,812 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,930 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:41:36,932 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:36,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:41:36,940 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,019 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:41:37,021 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,024 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:37,024 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,026 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 118 [2023-11-06 22:41:37,027 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,029 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 125 [2023-11-06 22:41:37,034 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,039 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:41:37,041 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,045 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:37,045 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,047 INFO L134 CoverageAnalysis]: Checked inductivity of 105 backedges. 52 proven. 23 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2023-11-06 22:41:37,047 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:37,047 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [77253732] [2023-11-06 22:41:37,048 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [77253732] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:41:37,048 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1168453580] [2023-11-06 22:41:37,048 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:37,048 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:41:37,048 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:41:37,050 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:41:37,078 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-06 22:41:37,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:37,214 INFO L262 TraceCheckSpWp]: Trace formula consists of 464 conjuncts, 11 conjunts are in the unsatisfiable core [2023-11-06 22:41:37,222 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:41:37,494 INFO L134 CoverageAnalysis]: Checked inductivity of 105 backedges. 88 proven. 15 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-06 22:41:37,494 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-06 22:41:37,802 INFO L134 CoverageAnalysis]: Checked inductivity of 105 backedges. 53 proven. 23 refuted. 0 times theorem prover too weak. 29 trivial. 0 not checked. [2023-11-06 22:41:37,802 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1168453580] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-06 22:41:37,802 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-06 22:41:37,803 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [11, 9, 9] total 17 [2023-11-06 22:41:37,803 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1953485494] [2023-11-06 22:41:37,803 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-06 22:41:37,804 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 17 states [2023-11-06 22:41:37,804 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:37,805 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 17 interpolants. [2023-11-06 22:41:37,805 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=61, Invalid=211, Unknown=0, NotChecked=0, Total=272 [2023-11-06 22:41:37,806 INFO L87 Difference]: Start difference. First operand 434 states and 559 transitions. Second operand has 17 states, 17 states have (on average 8.941176470588236) internal successors, (152), 15 states have internal predecessors, (152), 6 states have call successors, (33), 9 states have call predecessors, (33), 6 states have return successors, (24), 8 states have call predecessors, (24), 6 states have call successors, (24) [2023-11-06 22:41:39,312 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:39,312 INFO L93 Difference]: Finished difference Result 1193 states and 1627 transitions. [2023-11-06 22:41:39,313 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2023-11-06 22:41:39,313 INFO L78 Accepts]: Start accepts. Automaton has has 17 states, 17 states have (on average 8.941176470588236) internal successors, (152), 15 states have internal predecessors, (152), 6 states have call successors, (33), 9 states have call predecessors, (33), 6 states have return successors, (24), 8 states have call predecessors, (24), 6 states have call successors, (24) Word has length 150 [2023-11-06 22:41:39,314 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:39,320 INFO L225 Difference]: With dead ends: 1193 [2023-11-06 22:41:39,320 INFO L226 Difference]: Without dead ends: 813 [2023-11-06 22:41:39,324 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 372 GetRequests, 330 SyntacticMatches, 5 SemanticMatches, 37 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 327 ImplicationChecksByTransitivity, 0.5s TimeCoverageRelationStatistics Valid=380, Invalid=1102, Unknown=0, NotChecked=0, Total=1482 [2023-11-06 22:41:39,324 INFO L413 NwaCegarLoop]: 136 mSDtfsCounter, 642 mSDsluCounter, 660 mSDsCounter, 0 mSdLazyCounter, 1073 mSolverCounterSat, 276 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 646 SdHoareTripleChecker+Valid, 796 SdHoareTripleChecker+Invalid, 1349 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 276 IncrementalHoareTripleChecker+Valid, 1073 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:39,325 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [646 Valid, 796 Invalid, 1349 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [276 Valid, 1073 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2023-11-06 22:41:39,326 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 813 states. [2023-11-06 22:41:39,422 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 813 to 710. [2023-11-06 22:41:39,423 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 710 states, 533 states have (on average 1.2026266416510318) internal successors, (641), 565 states have internal predecessors, (641), 83 states have call successors, (83), 76 states have call predecessors, (83), 93 states have return successors, (177), 85 states have call predecessors, (177), 83 states have call successors, (177) [2023-11-06 22:41:39,429 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 710 states to 710 states and 901 transitions. [2023-11-06 22:41:39,430 INFO L78 Accepts]: Start accepts. Automaton has 710 states and 901 transitions. Word has length 150 [2023-11-06 22:41:39,430 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:39,431 INFO L495 AbstractCegarLoop]: Abstraction has 710 states and 901 transitions. [2023-11-06 22:41:39,431 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 17 states, 17 states have (on average 8.941176470588236) internal successors, (152), 15 states have internal predecessors, (152), 6 states have call successors, (33), 9 states have call predecessors, (33), 6 states have return successors, (24), 8 states have call predecessors, (24), 6 states have call successors, (24) [2023-11-06 22:41:39,431 INFO L276 IsEmpty]: Start isEmpty. Operand 710 states and 901 transitions. [2023-11-06 22:41:39,435 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 151 [2023-11-06 22:41:39,435 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:41:39,435 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:39,442 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-06 22:41:39,642 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:41:39,642 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:41:39,643 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:41:39,643 INFO L85 PathProgramCache]: Analyzing trace with hash -2070792144, now seen corresponding path program 1 times [2023-11-06 22:41:39,643 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:41:39,643 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [433921123] [2023-11-06 22:41:39,643 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:39,644 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:41:39,671 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,787 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:41:39,788 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,795 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-06 22:41:39,799 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,809 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:41:39,812 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,816 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:39,819 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,823 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:41:39,824 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,826 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 65 [2023-11-06 22:41:39,833 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,853 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:41:39,855 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,857 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:41:39,860 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,892 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:41:39,893 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,895 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:39,895 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,896 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 118 [2023-11-06 22:41:39,898 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,899 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 125 [2023-11-06 22:41:39,903 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,906 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:41:39,907 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,909 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:41:39,910 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:39,912 INFO L134 CoverageAnalysis]: Checked inductivity of 105 backedges. 45 proven. 6 refuted. 0 times theorem prover too weak. 54 trivial. 0 not checked. [2023-11-06 22:41:39,912 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:41:39,912 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [433921123] [2023-11-06 22:41:39,912 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [433921123] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:41:39,912 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1466301135] [2023-11-06 22:41:39,912 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:41:39,913 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:41:39,913 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:41:39,914 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:41:39,936 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2023-11-06 22:41:40,075 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:41:40,078 INFO L262 TraceCheckSpWp]: Trace formula consists of 465 conjuncts, 5 conjunts are in the unsatisfiable core [2023-11-06 22:41:40,090 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:41:40,110 INFO L134 CoverageAnalysis]: Checked inductivity of 105 backedges. 72 proven. 0 refuted. 0 times theorem prover too weak. 33 trivial. 0 not checked. [2023-11-06 22:41:40,111 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:41:40,111 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1466301135] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:41:40,111 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:41:40,111 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [8] total 8 [2023-11-06 22:41:40,111 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [27706798] [2023-11-06 22:41:40,112 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:41:40,112 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:41:40,112 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:41:40,113 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:41:40,113 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=15, Invalid=41, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:41:40,113 INFO L87 Difference]: Start difference. First operand 710 states and 901 transitions. Second operand has 5 states, 5 states have (on average 20.0) internal successors, (100), 5 states have internal predecessors, (100), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:41:40,189 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:41:40,189 INFO L93 Difference]: Finished difference Result 942 states and 1183 transitions. [2023-11-06 22:41:40,190 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:41:40,190 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 20.0) internal successors, (100), 5 states have internal predecessors, (100), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) Word has length 150 [2023-11-06 22:41:40,191 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:41:40,191 INFO L225 Difference]: With dead ends: 942 [2023-11-06 22:41:40,192 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:41:40,195 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 187 GetRequests, 179 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=23, Invalid=67, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:41:40,195 INFO L413 NwaCegarLoop]: 108 mSDtfsCounter, 6 mSDsluCounter, 308 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 6 SdHoareTripleChecker+Valid, 416 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:41:40,196 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [6 Valid, 416 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:41:40,197 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:41:40,197 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:41:40,197 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:41:40,197 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:41:40,198 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 150 [2023-11-06 22:41:40,198 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:41:40,198 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:41:40,198 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 20.0) internal successors, (100), 5 states have internal predecessors, (100), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:41:40,198 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:41:40,198 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:41:40,201 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:41:40,211 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2023-11-06 22:41:40,407 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2023-11-06 22:41:40,409 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:41:43,010 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 278 285) no Hoare annotation was computed. [2023-11-06 22:41:43,010 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 278 285) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,010 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 278 285) no Hoare annotation was computed. [2023-11-06 22:41:43,010 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 168 174) no Hoare annotation was computed. [2023-11-06 22:41:43,010 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 168 174) the Hoare annotation is: true [2023-11-06 22:41:43,010 INFO L899 garLoopResultBuilder]: For program point L946-1(lines 942 953) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 942 953) the Hoare annotation is: true [2023-11-06 22:41:43,011 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 942 953) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L902 garLoopResultBuilder]: At program point L480(lines 455 484) the Hoare annotation is: true [2023-11-06 22:41:43,011 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 455 484) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L899 garLoopResultBuilder]: For program point L476(line 476) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L899 garLoopResultBuilder]: For program point L469(lines 469 473) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L902 garLoopResultBuilder]: At program point L469-1(lines 469 473) the Hoare annotation is: true [2023-11-06 22:41:43,011 INFO L899 garLoopResultBuilder]: For program point L466(line 466) no Hoare annotation was computed. [2023-11-06 22:41:43,011 INFO L902 garLoopResultBuilder]: At program point L465-2(lines 465 479) the Hoare annotation is: true [2023-11-06 22:41:43,011 INFO L902 garLoopResultBuilder]: At program point L461(line 461) the Hoare annotation is: true [2023-11-06 22:41:43,012 INFO L899 garLoopResultBuilder]: For program point L461-1(line 461) no Hoare annotation was computed. [2023-11-06 22:41:43,012 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 455 484) the Hoare annotation is: true [2023-11-06 22:41:43,012 INFO L899 garLoopResultBuilder]: For program point L155-1(lines 155 161) no Hoare annotation was computed. [2023-11-06 22:41:43,012 INFO L895 garLoopResultBuilder]: At program point L242(line 242) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,012 INFO L895 garLoopResultBuilder]: At program point L238(line 238) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,012 INFO L895 garLoopResultBuilder]: At program point L234(line 234) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,012 INFO L899 garLoopResultBuilder]: For program point L234-1(line 234) no Hoare annotation was computed. [2023-11-06 22:41:43,013 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 144 167) no Hoare annotation was computed. [2023-11-06 22:41:43,013 INFO L895 garLoopResultBuilder]: At program point L247(line 247) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (= |old(~pumpRunning~0)| 0)) (.cse3 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 .cse2) (or (and .cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse0 .cse2) (or (not .cse1) (not (= |old(~waterLevel~0)| 1)) (and .cse3 (= ~waterLevel~0 1)) .cse2))) [2023-11-06 22:41:43,013 INFO L895 garLoopResultBuilder]: At program point L247-1(lines 228 252) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= |old(~waterLevel~0)| ~waterLevel~0) .cse1 (<= |old(~waterLevel~0)| 1)) (let ((.cse3 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse2 .cse3) (< |old(~waterLevel~0)| 2) (and (<= 2 ~waterLevel~0) .cse3) .cse1)) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse2 (= ~waterLevel~0 1)) .cse1))) [2023-11-06 22:41:43,013 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 986 994) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (< |old(~waterLevel~0)| 2)) (.cse3 (= ~pumpRunning~0 0)) (.cse4 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (= |old(~waterLevel~0)| ~waterLevel~0) .cse2) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse3 .cse4 (= ~waterLevel~0 1)) .cse2) (let ((.cse5 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or .cse1 (and (<= 2 ~waterLevel~0) .cse5 .cse4) (and .cse3 .cse5 .cse4) .cse2)))) [2023-11-06 22:41:43,013 INFO L899 garLoopResultBuilder]: For program point L148-1(lines 147 166) no Hoare annotation was computed. [2023-11-06 22:41:43,014 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2023-11-06 22:41:43,014 INFO L899 garLoopResultBuilder]: For program point L236(lines 236 244) no Hoare annotation was computed. [2023-11-06 22:41:43,014 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 50 57) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,014 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 144 167) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) (not (= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1)) .cse0))) [2023-11-06 22:41:43,014 INFO L899 garLoopResultBuilder]: For program point L232(lines 232 249) no Hoare annotation was computed. [2023-11-06 22:41:43,014 INFO L899 garLoopResultBuilder]: For program point L922(lines 922 926) no Hoare annotation was computed. [2023-11-06 22:41:43,014 INFO L895 garLoopResultBuilder]: At program point L922-2(lines 918 929) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,014 INFO L899 garLoopResultBuilder]: For program point L402(lines 402 408) no Hoare annotation was computed. [2023-11-06 22:41:43,015 INFO L899 garLoopResultBuilder]: For program point L398(lines 398 411) no Hoare annotation was computed. [2023-11-06 22:41:43,015 INFO L895 garLoopResultBuilder]: At program point L398-1(lines 390 414) the Hoare annotation is: (let ((.cse4 (<= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse1 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~7#1|)) (.cse2 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse5 (= 0 ~systemActive~0))) (and (let ((.cse3 (= |old(~waterLevel~0)| ~waterLevel~0))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) (and .cse0 .cse1 .cse2 .cse3) (and .cse4 .cse3) .cse5)) (let ((.cse6 (<= |old(~waterLevel~0)| (+ ~waterLevel~0 1)))) (or (and .cse4 .cse1 .cse6 .cse2) (< |old(~waterLevel~0)| 2) (and .cse0 .cse1 .cse6 .cse2) .cse5)))) [2023-11-06 22:41:43,015 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 144 167) no Hoare annotation was computed. [2023-11-06 22:41:43,015 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 297 305) the Hoare annotation is: (let ((.cse0 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) .cse0))) [2023-11-06 22:41:43,015 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2023-11-06 22:41:43,015 INFO L895 garLoopResultBuilder]: At program point startSystem_returnLabel#1(lines 380 387) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3))) [2023-11-06 22:41:43,016 INFO L895 garLoopResultBuilder]: At program point L122(lines 73 123) the Hoare annotation is: false [2023-11-06 22:41:43,016 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 516 525) the Hoare annotation is: true [2023-11-06 22:41:43,016 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 430 436) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:41:43,022 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 526 548) the Hoare annotation is: true [2023-11-06 22:41:43,022 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:41:43,022 INFO L899 garLoopResultBuilder]: For program point L94(lines 94 100) no Hoare annotation was computed. [2023-11-06 22:41:43,023 INFO L899 garLoopResultBuilder]: For program point L94-1(lines 94 100) no Hoare annotation was computed. [2023-11-06 22:41:43,023 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:41:43,023 INFO L899 garLoopResultBuilder]: For program point L536(lines 536 543) no Hoare annotation was computed. [2023-11-06 22:41:43,023 INFO L895 garLoopResultBuilder]: At program point L119(lines 74 121) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3))) [2023-11-06 22:41:43,023 INFO L895 garLoopResultBuilder]: At program point L86(line 86) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3))) [2023-11-06 22:41:43,024 INFO L899 garLoopResultBuilder]: For program point L536-2(lines 536 543) no Hoare annotation was computed. [2023-11-06 22:41:43,024 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 509 515) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:41:43,024 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:41:43,024 INFO L899 garLoopResultBuilder]: For program point L112(lines 112 116) no Hoare annotation was computed. [2023-11-06 22:41:43,024 INFO L895 garLoopResultBuilder]: At program point L112-2(lines 104 117) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3))) [2023-11-06 22:41:43,024 INFO L899 garLoopResultBuilder]: For program point L75(lines 74 121) no Hoare annotation was computed. [2023-11-06 22:41:43,025 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:41:43,025 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 437 443) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:41:43,025 INFO L899 garLoopResultBuilder]: For program point L104(lines 104 117) no Hoare annotation was computed. [2023-11-06 22:41:43,025 INFO L895 garLoopResultBuilder]: At program point L96(line 96) the Hoare annotation is: (let ((.cse0 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse1 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse2 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse0 (<= 2 ~waterLevel~0) .cse1 .cse2 .cse3) (and (= ~pumpRunning~0 0) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3))) [2023-11-06 22:41:43,026 INFO L902 garLoopResultBuilder]: At program point L125(lines 64 129) the Hoare annotation is: true [2023-11-06 22:41:43,026 INFO L899 garLoopResultBuilder]: For program point L84(lines 84 90) no Hoare annotation was computed. [2023-11-06 22:41:43,026 INFO L899 garLoopResultBuilder]: For program point L84-1(lines 84 90) no Hoare annotation was computed. [2023-11-06 22:41:43,026 INFO L899 garLoopResultBuilder]: For program point L76(lines 76 80) no Hoare annotation was computed. [2023-11-06 22:41:43,027 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 444 452) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:41:43,028 INFO L899 garLoopResultBuilder]: For program point L351(lines 351 355) no Hoare annotation was computed. [2023-11-06 22:41:43,028 INFO L895 garLoopResultBuilder]: At program point L190(line 190) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~1#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) .cse1) (and .cse0 (<= 2 ~waterLevel~0) .cse1) (= 0 ~systemActive~0))) [2023-11-06 22:41:43,028 INFO L899 garLoopResultBuilder]: For program point L351-2(lines 351 355) no Hoare annotation was computed. [2023-11-06 22:41:43,028 INFO L899 garLoopResultBuilder]: For program point L184(lines 184 192) no Hoare annotation was computed. [2023-11-06 22:41:43,029 INFO L899 garLoopResultBuilder]: For program point L180(lines 180 197) no Hoare annotation was computed. [2023-11-06 22:41:43,029 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 176 200) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,029 INFO L895 garLoopResultBuilder]: At program point L195(line 195) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,029 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 995 1008) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0))) (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (and .cse0 (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0))) (and .cse0 (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0))) [2023-11-06 22:41:43,029 INFO L899 garLoopResultBuilder]: For program point L195-1(lines 176 200) no Hoare annotation was computed. [2023-11-06 22:41:43,030 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 342 360) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (<= ~waterLevel~0 1) .cse2) (or (not (= ~waterLevel~0 1)) .cse0 (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~5#1| 0)) (not (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse2))) [2023-11-06 22:41:43,030 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 176 200) no Hoare annotation was computed. [2023-11-06 22:41:43,030 INFO L899 garLoopResultBuilder]: For program point L268(lines 268 274) no Hoare annotation was computed. [2023-11-06 22:41:43,030 INFO L895 garLoopResultBuilder]: At program point L266(line 266) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (and (= ~pumpRunning~0 0) (<= 2 ~waterLevel~0)) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,030 INFO L895 garLoopResultBuilder]: At program point L268-2(lines 261 277) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (<= 2 ~waterLevel~0) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,030 INFO L899 garLoopResultBuilder]: For program point L266-1(line 266) no Hoare annotation was computed. [2023-11-06 22:41:43,031 INFO L899 garLoopResultBuilder]: For program point L999(lines 999 1005) no Hoare annotation was computed. [2023-11-06 22:41:43,031 INFO L895 garLoopResultBuilder]: At program point activatePump__wrappee__lowWaterSensor_returnLabel#1(lines 253 260) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (<= 2 ~waterLevel~0) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,031 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 930 941) no Hoare annotation was computed. [2023-11-06 22:41:43,031 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 930 941) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 .cse1) (or (< |old(~waterLevel~0)| 1) (not (= ~pumpRunning~0 0)) .cse0 .cse1))) [2023-11-06 22:41:43,031 INFO L899 garLoopResultBuilder]: For program point L934-1(lines 930 941) no Hoare annotation was computed. [2023-11-06 22:41:43,032 INFO L895 garLoopResultBuilder]: At program point L221(line 221) the Hoare annotation is: (or (< ~waterLevel~0 1) (= 0 ~systemActive~0) (and (= ~pumpRunning~0 0) (= |old(~pumpRunning~0)| 0))) [2023-11-06 22:41:43,032 INFO L899 garLoopResultBuilder]: For program point L221-1(lines 202 226) no Hoare annotation was computed. [2023-11-06 22:41:43,032 INFO L899 garLoopResultBuilder]: For program point L370(lines 370 374) no Hoare annotation was computed. [2023-11-06 22:41:43,032 INFO L899 garLoopResultBuilder]: For program point L370-2(lines 370 374) no Hoare annotation was computed. [2023-11-06 22:41:43,033 INFO L895 garLoopResultBuilder]: At program point isLowWaterSensorDry_returnLabel#1(lines 1009 1017) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0)) .cse1))) [2023-11-06 22:41:43,033 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 202 226) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,033 INFO L895 garLoopResultBuilder]: At program point isLowWaterLevel_returnLabel#1(lines 361 379) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (= |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp~6#1| 0)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2023-11-06 22:41:43,034 INFO L895 garLoopResultBuilder]: At program point L216(line 216) the Hoare annotation is: (or (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:41:43,034 INFO L895 garLoopResultBuilder]: At program point L212(line 212) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (<= 1 |processEnvironment__wrappee__methaneQuery_~tmp~2#1|)) .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2023-11-06 22:41:43,034 INFO L899 garLoopResultBuilder]: For program point L210(lines 210 218) no Hoare annotation was computed. [2023-11-06 22:41:43,034 INFO L899 garLoopResultBuilder]: For program point L206(lines 206 223) no Hoare annotation was computed. [2023-11-06 22:41:43,034 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 202 226) no Hoare annotation was computed. [2023-11-06 22:41:43,034 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCritical_returnLabel#1(lines 954 962) the Hoare annotation is: true [2023-11-06 22:41:43,035 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 286 296) no Hoare annotation was computed. [2023-11-06 22:41:43,035 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 286 296) the Hoare annotation is: true [2023-11-06 22:41:43,036 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 286 296) no Hoare annotation was computed. [2023-11-06 22:41:43,038 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:41:43,040 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:41:43,085 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:41:43 BoogieIcfgContainer [2023-11-06 22:41:43,085 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:41:43,086 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:41:43,086 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:41:43,086 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:41:43,087 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:41:29" (3/4) ... [2023-11-06 22:41:43,095 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:41:43,099 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-06 22:41:43,099 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:41:43,099 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:41:43,099 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:41:43,099 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:41:43,100 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:41:43,100 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:41:43,100 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:41:43,100 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2023-11-06 22:41:43,113 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 18 nodes and edges [2023-11-06 22:41:43,113 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:41:43,114 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:41:43,115 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:41:43,116 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:41:43,143 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:41:43,143 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:41:43,143 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) [2023-11-06 22:41:43,145 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) || ((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) <= (waterLevel + 1)))) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,145 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) || (\old(waterLevel) <= 1)) && (((((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) || (\old(waterLevel) < 2)) || ((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (waterLevel == 1))) || (0 == systemActive))) [2023-11-06 22:41:43,146 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (1 <= \result)) && (waterLevel == 1))) || (0 == systemActive))) && ((((\old(waterLevel) < 2) || (((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) [2023-11-06 22:41:43,146 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) [2023-11-06 22:41:43,147 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && (((((((2 <= waterLevel) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result)) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) [2023-11-06 22:41:43,147 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:41:43,148 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) [2023-11-06 22:41:43,148 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,148 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:41:43,148 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:41:43,149 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,149 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel <= 1)) || (0 == systemActive)) && (((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (((((pumpRunning == 0) && (tmp___0 == 0)) && !((tmp == 0))) && !((\result == 0))) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:41:43,149 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,189 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:41:43,189 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:41:43,189 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) [2023-11-06 22:41:43,190 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) || ((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) <= (waterLevel + 1)))) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,190 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) || (\old(waterLevel) <= 1)) && (((((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) || (\old(waterLevel) < 2)) || ((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (waterLevel == 1))) || (0 == systemActive))) [2023-11-06 22:41:43,191 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (1 <= \result)) && (waterLevel == 1))) || (0 == systemActive))) && ((((\old(waterLevel) < 2) || (((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) [2023-11-06 22:41:43,191 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) [2023-11-06 22:41:43,191 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && (((((((2 <= waterLevel) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result)) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) [2023-11-06 22:41:43,191 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel <= 1)) || (0 == systemActive)) && (((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (((((pumpRunning == 0) && (tmp___0 == 0)) && !((tmp == 0))) && !((\result == 0))) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:41:43,192 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) [2023-11-06 22:41:43,213 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:41:43,214 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:41:43,214 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:41:43,215 INFO L158 Benchmark]: Toolchain (without parser) took 14929.04ms. Allocated memory was 142.6MB in the beginning and 237.0MB in the end (delta: 94.4MB). Free memory was 109.5MB in the beginning and 73.9MB in the end (delta: 35.7MB). Peak memory consumption was 132.1MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,215 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 142.6MB. Free memory is still 87.1MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:41:43,216 INFO L158 Benchmark]: CACSL2BoogieTranslator took 615.52ms. Allocated memory is still 142.6MB. Free memory was 109.5MB in the beginning and 89.8MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,219 INFO L158 Benchmark]: Boogie Procedure Inliner took 54.70ms. Allocated memory is still 142.6MB. Free memory was 89.4MB in the beginning and 87.2MB in the end (delta: 2.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,219 INFO L158 Benchmark]: Boogie Preprocessor took 48.60ms. Allocated memory is still 142.6MB. Free memory was 87.2MB in the beginning and 85.6MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,220 INFO L158 Benchmark]: RCFGBuilder took 609.32ms. Allocated memory is still 142.6MB. Free memory was 85.6MB in the beginning and 67.6MB in the end (delta: 18.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,221 INFO L158 Benchmark]: TraceAbstraction took 13464.89ms. Allocated memory was 142.6MB in the beginning and 237.0MB in the end (delta: 94.4MB). Free memory was 67.1MB in the beginning and 82.3MB in the end (delta: -15.1MB). Peak memory consumption was 96.5MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,221 INFO L158 Benchmark]: Witness Printer took 128.37ms. Allocated memory is still 237.0MB. Free memory was 81.2MB in the beginning and 73.9MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2023-11-06 22:41:43,224 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 142.6MB. Free memory is still 87.1MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 615.52ms. Allocated memory is still 142.6MB. Free memory was 109.5MB in the beginning and 89.8MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 54.70ms. Allocated memory is still 142.6MB. Free memory was 89.4MB in the beginning and 87.2MB in the end (delta: 2.2MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 48.60ms. Allocated memory is still 142.6MB. Free memory was 87.2MB in the beginning and 85.6MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 609.32ms. Allocated memory is still 142.6MB. Free memory was 85.6MB in the beginning and 67.6MB in the end (delta: 18.0MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 13464.89ms. Allocated memory was 142.6MB in the beginning and 237.0MB in the end (delta: 94.4MB). Free memory was 67.1MB in the beginning and 82.3MB in the end (delta: -15.1MB). Peak memory consumption was 96.5MB. Max. memory is 16.1GB. * Witness Printer took 128.37ms. Allocated memory is still 237.0MB. Free memory was 81.2MB in the beginning and 73.9MB in the end (delta: 7.3MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] - GenericResultAtLocation [Line: 58]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [58] - GenericResultAtLocation [Line: 130]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [130] - GenericResultAtLocation [Line: 388]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [388] - GenericResultAtLocation [Line: 415]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [415] - GenericResultAtLocation [Line: 453]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [453] - GenericResultAtLocation [Line: 549]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [549] - GenericResultAtLocation [Line: 915]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [915] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 104 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 13.4s, OverallIterations: 10, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 5.3s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 2.6s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2339 SdHoareTripleChecker+Valid, 3.0s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2307 mSDsluCounter, 3990 SdHoareTripleChecker+Invalid, 2.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3022 mSDsCounter, 739 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 3251 IncrementalHoareTripleChecker+Invalid, 3990 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 739 mSolverCounterUnsat, 968 mSDtfsCounter, 3251 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 920 GetRequests, 764 SyntacticMatches, 10 SemanticMatches, 146 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1279 ImplicationChecksByTransitivity, 1.6s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=710occurred in iteration=9, InterpolantAutomatonStates: 137, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.5s AutomataMinimizationTime, 10 MinimizatonAttempts, 239 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 49 LocationsWithAnnotation, 1422 PreInvPairs, 1536 NumberOfFragments, 1013 HoareAnnotationTreeSize, 1422 FomulaSimplifications, 5691 FormulaSimplificationTreeSizeReduction, 0.2s HoareSimplificationTime, 49 FomulaSimplificationsInter, 4242 FormulaSimplificationTreeSizeReductionInter, 2.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 3.2s InterpolantComputationTime, 1104 NumberOfCodeBlocks, 1104 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 1328 ConstructedInterpolants, 0 QuantifiedInterpolants, 2252 SizeOfPredicates, 10 NumberOfNonLiveVariables, 1240 ConjunctsInSsa, 24 ConjunctsInUnsatCore, 15 InterpolantComputations, 8 PerfectInterpolantSequences, 550/630 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 509]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 253]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) - InvariantResult [Line: 430]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 228]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) || (\old(waterLevel) <= 1)) && (((((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) || (\old(waterLevel) < 2)) || ((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1)))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((pumpRunning == 0) && (waterLevel == 1))) || (0 == systemActive))) - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: ((((\old(waterLevel) < 2) || (0 == systemActive)) || ((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) <= (waterLevel + 1)))) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) - InvariantResult [Line: 390]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || ((((pumpRunning == 0) && (1 <= tmp)) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || ((2 <= waterLevel) && (\old(waterLevel) == waterLevel))) || (0 == systemActive)) && (((((((2 <= waterLevel) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result)) || (\old(waterLevel) < 2)) || ((((pumpRunning == 0) && (1 <= tmp)) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) - InvariantResult [Line: 1009]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) - InvariantResult [Line: 297]: Loop Invariant Derived loop invariant: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) - InvariantResult [Line: 995]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || ((pumpRunning == 0) && !((\result == 0)))) || ((pumpRunning == 0) && (2 <= waterLevel))) || (0 == systemActive)) - InvariantResult [Line: 261]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) - InvariantResult [Line: 342]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel <= 1)) || (0 == systemActive)) && (((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (((((pumpRunning == 0) && (tmp___0 == 0)) && !((tmp == 0))) && !((\result == 0))) && (\result == 0))) || (0 == systemActive))) - InvariantResult [Line: 73]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 516]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 455]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 954]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 74]: Loop Invariant Derived loop invariant: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 64]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 380]: Loop Invariant Derived loop invariant: ((((((\result == 1) && (2 <= waterLevel)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && !((0 == systemActive)))) - InvariantResult [Line: 50]: Loop Invariant Derived loop invariant: (((\old(waterLevel) < 2) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (0 == systemActive))) - InvariantResult [Line: 986]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (\old(waterLevel) == waterLevel)) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (1 <= \result)) && (waterLevel == 1))) || (0 == systemActive))) && ((((\old(waterLevel) < 2) || (((2 <= waterLevel) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (((pumpRunning == 0) && (\old(waterLevel) <= (waterLevel + 1))) && (1 <= \result))) || (0 == systemActive))) - InvariantResult [Line: 444]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 437]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 465]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 361]: Loop Invariant Derived loop invariant: ((((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive))) - InvariantResult [Line: 526]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:41:43,283 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_e44556a2-ce77-4d1a-a2c5-1d60582a4bef/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE