./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 7c7779f94f1738e754b88f9a8a8e36de7065a4e94578f4135106bd0ff9ddb13d --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:32:20,991 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:32:21,070 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:32:21,076 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:32:21,077 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:32:21,105 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:32:21,106 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:32:21,107 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:32:21,108 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:32:21,108 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:32:21,109 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:32:21,110 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:32:21,110 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:32:21,111 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:32:21,111 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:32:21,112 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:32:21,112 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:32:21,113 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:32:21,114 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:32:21,114 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:32:21,115 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:32:21,116 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:32:21,116 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:32:21,117 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:32:21,117 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:32:21,118 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:32:21,118 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:32:21,119 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:32:21,120 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:32:21,120 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:32:21,121 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:32:21,121 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:32:21,122 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:32:21,122 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:32:21,123 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:32:21,123 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:32:21,124 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:32:21,124 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:32:21,124 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:32:21,125 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 7c7779f94f1738e754b88f9a8a8e36de7065a4e94578f4135106bd0ff9ddb13d [2023-11-06 22:32:21,434 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:32:21,491 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:32:21,494 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:32:21,496 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:32:21,497 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:32:21,498 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c [2023-11-06 22:32:24,597 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:32:24,851 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:32:24,852 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c [2023-11-06 22:32:24,875 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/data/3c2beb802/3f299ea033c14b34a266090131e210b2/FLAG068ff7714 [2023-11-06 22:32:24,890 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/data/3c2beb802/3f299ea033c14b34a266090131e210b2 [2023-11-06 22:32:24,892 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:32:24,894 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:32:24,895 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:32:24,896 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:32:24,901 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:32:24,904 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:32:24" (1/1) ... [2023-11-06 22:32:24,905 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@130a36f6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:24, skipping insertion in model container [2023-11-06 22:32:24,906 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:32:24" (1/1) ... [2023-11-06 22:32:24,953 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:32:25,272 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c[15018,15031] [2023-11-06 22:32:25,294 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:32:25,307 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:32:25,317 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [49] [2023-11-06 22:32:25,319 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [415] [2023-11-06 22:32:25,319 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [519] [2023-11-06 22:32:25,320 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [554] [2023-11-06 22:32:25,320 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [583] [2023-11-06 22:32:25,320 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [691] [2023-11-06 22:32:25,320 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [700] [2023-11-06 22:32:25,321 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [958] [2023-11-06 22:32:25,405 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/sv-benchmarks/c/product-lines/minepump_spec4_product63.cil.c[15018,15031] [2023-11-06 22:32:25,418 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:32:25,450 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:32:25,450 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25 WrapperNode [2023-11-06 22:32:25,450 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:32:25,452 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:32:25,452 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:32:25,452 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:32:25,460 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,489 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,520 INFO L138 Inliner]: procedures = 58, calls = 106, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 241 [2023-11-06 22:32:25,520 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:32:25,521 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:32:25,521 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:32:25,522 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:32:25,530 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,531 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,533 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,534 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,541 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,545 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,548 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,549 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,553 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:32:25,554 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:32:25,554 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:32:25,554 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:32:25,555 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (1/1) ... [2023-11-06 22:32:25,562 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:32:25,578 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:32:25,591 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:32:25,612 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:32:25,630 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:32:25,630 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:32:25,630 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:32:25,631 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:32:25,631 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:32:25,631 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:32:25,631 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:32:25,631 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:32:25,632 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:32:25,632 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:32:25,632 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:32:25,632 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:32:25,632 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:32:25,633 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2023-11-06 22:32:25,633 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2023-11-06 22:32:25,633 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-06 22:32:25,633 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-06 22:32:25,634 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:32:25,634 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:32:25,634 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:32:25,634 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:32:25,634 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:32:25,716 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:32:25,718 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:32:26,039 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:32:26,047 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:32:26,048 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:32:26,066 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:32:26 BoogieIcfgContainer [2023-11-06 22:32:26,066 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:32:26,069 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:32:26,070 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:32:26,073 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:32:26,074 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:32:24" (1/3) ... [2023-11-06 22:32:26,074 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3d29f011 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:32:26, skipping insertion in model container [2023-11-06 22:32:26,074 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:32:25" (2/3) ... [2023-11-06 22:32:26,075 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@3d29f011 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:32:26, skipping insertion in model container [2023-11-06 22:32:26,075 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:32:26" (3/3) ... [2023-11-06 22:32:26,076 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec4_product63.cil.c [2023-11-06 22:32:26,103 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:32:26,103 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:32:26,184 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:32:26,192 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@77e34b68, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:32:26,193 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:32:26,197 INFO L276 IsEmpty]: Start isEmpty. Operand has 107 states, 79 states have (on average 1.379746835443038) internal successors, (109), 90 states have internal predecessors, (109), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2023-11-06 22:32:26,206 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 20 [2023-11-06 22:32:26,206 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:26,207 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:26,207 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:26,212 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:26,213 INFO L85 PathProgramCache]: Analyzing trace with hash 1070951928, now seen corresponding path program 1 times [2023-11-06 22:32:26,222 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:26,223 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1596942811] [2023-11-06 22:32:26,223 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:26,224 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:26,397 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:26,519 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:26,520 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:26,520 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1596942811] [2023-11-06 22:32:26,521 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1596942811] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:26,521 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:26,521 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:32:26,523 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1306203365] [2023-11-06 22:32:26,524 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:26,531 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:32:26,532 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:26,580 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:32:26,582 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:32:26,586 INFO L87 Difference]: Start difference. First operand has 107 states, 79 states have (on average 1.379746835443038) internal successors, (109), 90 states have internal predecessors, (109), 17 states have call successors, (17), 9 states have call predecessors, (17), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) Second operand has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:26,674 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:26,675 INFO L93 Difference]: Finished difference Result 206 states and 281 transitions. [2023-11-06 22:32:26,676 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:32:26,677 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 19 [2023-11-06 22:32:26,678 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:26,693 INFO L225 Difference]: With dead ends: 206 [2023-11-06 22:32:26,693 INFO L226 Difference]: Without dead ends: 98 [2023-11-06 22:32:26,700 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:32:26,705 INFO L413 NwaCegarLoop]: 137 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 137 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:26,706 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 137 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:32:26,751 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 98 states. [2023-11-06 22:32:26,778 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 98 to 98. [2023-11-06 22:32:26,780 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 98 states, 72 states have (on average 1.3194444444444444) internal successors, (95), 82 states have internal predecessors, (95), 17 states have call successors, (17), 9 states have call predecessors, (17), 8 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2023-11-06 22:32:26,783 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 98 states to 98 states and 128 transitions. [2023-11-06 22:32:26,784 INFO L78 Accepts]: Start accepts. Automaton has 98 states and 128 transitions. Word has length 19 [2023-11-06 22:32:26,785 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:26,785 INFO L495 AbstractCegarLoop]: Abstraction has 98 states and 128 transitions. [2023-11-06 22:32:26,786 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 8.5) internal successors, (17), 2 states have internal predecessors, (17), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:26,786 INFO L276 IsEmpty]: Start isEmpty. Operand 98 states and 128 transitions. [2023-11-06 22:32:26,788 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2023-11-06 22:32:26,789 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:26,789 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:26,789 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:32:26,789 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:26,790 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:26,791 INFO L85 PathProgramCache]: Analyzing trace with hash -630554312, now seen corresponding path program 1 times [2023-11-06 22:32:26,791 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:26,791 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1948208610] [2023-11-06 22:32:26,791 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:26,792 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:26,814 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:26,899 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:26,899 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:26,899 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1948208610] [2023-11-06 22:32:26,900 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1948208610] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:26,900 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:26,900 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:32:26,900 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [635227781] [2023-11-06 22:32:26,900 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:26,902 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:32:26,902 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:26,903 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:32:26,903 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:32:26,903 INFO L87 Difference]: Start difference. First operand 98 states and 128 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:26,932 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:26,934 INFO L93 Difference]: Finished difference Result 158 states and 206 transitions. [2023-11-06 22:32:26,935 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:32:26,936 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 20 [2023-11-06 22:32:26,936 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:26,940 INFO L225 Difference]: With dead ends: 158 [2023-11-06 22:32:26,941 INFO L226 Difference]: Without dead ends: 89 [2023-11-06 22:32:26,944 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:32:26,948 INFO L413 NwaCegarLoop]: 115 mSDtfsCounter, 16 mSDsluCounter, 94 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 20 SdHoareTripleChecker+Valid, 209 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:26,949 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [20 Valid, 209 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:32:26,952 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2023-11-06 22:32:26,969 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 89. [2023-11-06 22:32:26,971 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 89 states, 66 states have (on average 1.3333333333333333) internal successors, (88), 76 states have internal predecessors, (88), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 9 states have call predecessors, (14), 14 states have call successors, (14) [2023-11-06 22:32:26,979 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 89 states to 89 states and 116 transitions. [2023-11-06 22:32:26,979 INFO L78 Accepts]: Start accepts. Automaton has 89 states and 116 transitions. Word has length 20 [2023-11-06 22:32:26,980 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:26,980 INFO L495 AbstractCegarLoop]: Abstraction has 89 states and 116 transitions. [2023-11-06 22:32:26,980 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 1 states have call successors, (2), 1 states have call predecessors, (2), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:26,981 INFO L276 IsEmpty]: Start isEmpty. Operand 89 states and 116 transitions. [2023-11-06 22:32:26,983 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2023-11-06 22:32:26,983 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:26,984 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:26,984 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:32:26,985 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:26,986 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:26,987 INFO L85 PathProgramCache]: Analyzing trace with hash 735150912, now seen corresponding path program 1 times [2023-11-06 22:32:26,987 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:26,988 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [698563269] [2023-11-06 22:32:26,988 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:26,988 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:27,052 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:27,320 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:27,320 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:27,321 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [698563269] [2023-11-06 22:32:27,321 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [698563269] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:27,321 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:27,321 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:32:27,322 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [505690550] [2023-11-06 22:32:27,322 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:27,323 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:32:27,323 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:27,324 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:32:27,325 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=10, Invalid=20, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:32:27,326 INFO L87 Difference]: Start difference. First operand 89 states and 116 transitions. Second operand has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:27,657 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:27,658 INFO L93 Difference]: Finished difference Result 290 states and 385 transitions. [2023-11-06 22:32:27,658 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2023-11-06 22:32:27,659 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 24 [2023-11-06 22:32:27,659 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:27,662 INFO L225 Difference]: With dead ends: 290 [2023-11-06 22:32:27,663 INFO L226 Difference]: Without dead ends: 208 [2023-11-06 22:32:27,664 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 1 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:32:27,665 INFO L413 NwaCegarLoop]: 122 mSDtfsCounter, 307 mSDsluCounter, 342 mSDsCounter, 0 mSdLazyCounter, 111 mSolverCounterSat, 38 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 307 SdHoareTripleChecker+Valid, 464 SdHoareTripleChecker+Invalid, 149 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 38 IncrementalHoareTripleChecker+Valid, 111 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:27,666 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [307 Valid, 464 Invalid, 149 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [38 Valid, 111 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:32:27,668 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 208 states. [2023-11-06 22:32:27,702 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 208 to 202. [2023-11-06 22:32:27,702 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 202 states, 149 states have (on average 1.3624161073825503) internal successors, (203), 171 states have internal predecessors, (203), 32 states have call successors, (32), 20 states have call predecessors, (32), 20 states have return successors, (33), 20 states have call predecessors, (33), 32 states have call successors, (33) [2023-11-06 22:32:27,705 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 202 states to 202 states and 268 transitions. [2023-11-06 22:32:27,705 INFO L78 Accepts]: Start accepts. Automaton has 202 states and 268 transitions. Word has length 24 [2023-11-06 22:32:27,706 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:27,706 INFO L495 AbstractCegarLoop]: Abstraction has 202 states and 268 transitions. [2023-11-06 22:32:27,706 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 3.8333333333333335) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:27,706 INFO L276 IsEmpty]: Start isEmpty. Operand 202 states and 268 transitions. [2023-11-06 22:32:27,708 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2023-11-06 22:32:27,709 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:27,709 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:27,709 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:32:27,709 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:27,710 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:27,710 INFO L85 PathProgramCache]: Analyzing trace with hash 769011574, now seen corresponding path program 1 times [2023-11-06 22:32:27,710 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:27,711 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2107973265] [2023-11-06 22:32:27,711 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:27,711 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:27,728 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:27,849 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:27,849 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:27,849 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2107973265] [2023-11-06 22:32:27,850 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2107973265] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:27,851 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:27,851 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-06 22:32:27,852 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [458082301] [2023-11-06 22:32:27,852 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:27,853 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:32:27,853 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:27,854 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:32:27,854 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:32:27,855 INFO L87 Difference]: Start difference. First operand 202 states and 268 transitions. Second operand has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:27,958 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:27,959 INFO L93 Difference]: Finished difference Result 575 states and 793 transitions. [2023-11-06 22:32:27,959 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:32:27,959 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 28 [2023-11-06 22:32:27,960 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:27,964 INFO L225 Difference]: With dead ends: 575 [2023-11-06 22:32:27,965 INFO L226 Difference]: Without dead ends: 380 [2023-11-06 22:32:27,966 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:32:27,968 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 85 mSDsluCounter, 318 mSDsCounter, 0 mSdLazyCounter, 30 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 85 SdHoareTripleChecker+Valid, 427 SdHoareTripleChecker+Invalid, 34 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 30 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:27,968 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [85 Valid, 427 Invalid, 34 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 30 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:32:27,972 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 380 states. [2023-11-06 22:32:28,076 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 380 to 380. [2023-11-06 22:32:28,077 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 380 states, 278 states have (on average 1.3381294964028776) internal successors, (372), 318 states have internal predecessors, (372), 64 states have call successors, (64), 40 states have call predecessors, (64), 37 states have return successors, (70), 37 states have call predecessors, (70), 64 states have call successors, (70) [2023-11-06 22:32:28,081 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 380 states to 380 states and 506 transitions. [2023-11-06 22:32:28,082 INFO L78 Accepts]: Start accepts. Automaton has 380 states and 506 transitions. Word has length 28 [2023-11-06 22:32:28,082 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:28,083 INFO L495 AbstractCegarLoop]: Abstraction has 380 states and 506 transitions. [2023-11-06 22:32:28,083 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.4) internal successors, (27), 4 states have internal predecessors, (27), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:28,083 INFO L276 IsEmpty]: Start isEmpty. Operand 380 states and 506 transitions. [2023-11-06 22:32:28,087 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 31 [2023-11-06 22:32:28,087 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:28,088 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:28,088 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:32:28,088 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:28,089 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:28,089 INFO L85 PathProgramCache]: Analyzing trace with hash 1555028603, now seen corresponding path program 1 times [2023-11-06 22:32:28,089 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:28,089 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [281691163] [2023-11-06 22:32:28,090 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:28,090 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:28,106 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:28,152 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:28,153 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:28,153 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [281691163] [2023-11-06 22:32:28,153 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [281691163] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:28,154 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:28,154 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:32:28,154 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1154603577] [2023-11-06 22:32:28,154 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:28,155 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:32:28,155 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:28,155 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:32:28,156 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:32:28,156 INFO L87 Difference]: Start difference. First operand 380 states and 506 transitions. Second operand has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:28,231 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:28,231 INFO L93 Difference]: Finished difference Result 870 states and 1181 transitions. [2023-11-06 22:32:28,232 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:32:28,232 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) Word has length 30 [2023-11-06 22:32:28,233 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:28,237 INFO L225 Difference]: With dead ends: 870 [2023-11-06 22:32:28,237 INFO L226 Difference]: Without dead ends: 497 [2023-11-06 22:32:28,239 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:32:28,241 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 67 mSDsluCounter, 72 mSDsCounter, 0 mSdLazyCounter, 13 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 183 SdHoareTripleChecker+Invalid, 23 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 13 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:28,242 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 183 Invalid, 23 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 13 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:32:28,243 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 497 states. [2023-11-06 22:32:28,290 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 497 to 486. [2023-11-06 22:32:28,292 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 486 states, 368 states have (on average 1.2771739130434783) internal successors, (470), 397 states have internal predecessors, (470), 61 states have call successors, (61), 57 states have call predecessors, (61), 56 states have return successors, (89), 55 states have call predecessors, (89), 61 states have call successors, (89) [2023-11-06 22:32:28,296 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 486 states to 486 states and 620 transitions. [2023-11-06 22:32:28,296 INFO L78 Accepts]: Start accepts. Automaton has 486 states and 620 transitions. Word has length 30 [2023-11-06 22:32:28,297 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:28,297 INFO L495 AbstractCegarLoop]: Abstraction has 486 states and 620 transitions. [2023-11-06 22:32:28,297 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 9.666666666666666) internal successors, (29), 2 states have internal predecessors, (29), 1 states have call successors, (1), 1 states have call predecessors, (1), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:28,298 INFO L276 IsEmpty]: Start isEmpty. Operand 486 states and 620 transitions. [2023-11-06 22:32:28,299 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2023-11-06 22:32:28,299 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:28,299 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:28,299 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:32:28,300 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:28,300 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:28,300 INFO L85 PathProgramCache]: Analyzing trace with hash -129157540, now seen corresponding path program 1 times [2023-11-06 22:32:28,301 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:28,301 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [163402572] [2023-11-06 22:32:28,301 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:28,301 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:28,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:28,409 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:28,412 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:28,415 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:28,415 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:28,416 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [163402572] [2023-11-06 22:32:28,416 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [163402572] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:28,416 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:28,416 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:32:28,417 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1044781296] [2023-11-06 22:32:28,417 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:28,417 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:32:28,418 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:28,419 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:32:28,419 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:32:28,419 INFO L87 Difference]: Start difference. First operand 486 states and 620 transitions. Second operand has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:32:28,878 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:28,878 INFO L93 Difference]: Finished difference Result 573 states and 734 transitions. [2023-11-06 22:32:28,878 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2023-11-06 22:32:28,879 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 32 [2023-11-06 22:32:28,879 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:28,886 INFO L225 Difference]: With dead ends: 573 [2023-11-06 22:32:28,887 INFO L226 Difference]: Without dead ends: 571 [2023-11-06 22:32:28,888 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 14 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:32:28,890 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 156 mSDsluCounter, 209 mSDsCounter, 0 mSdLazyCounter, 275 mSolverCounterSat, 43 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 164 SdHoareTripleChecker+Valid, 277 SdHoareTripleChecker+Invalid, 318 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 43 IncrementalHoareTripleChecker+Valid, 275 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:28,893 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [164 Valid, 277 Invalid, 318 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [43 Valid, 275 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:32:28,896 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 571 states. [2023-11-06 22:32:28,988 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 571 to 550. [2023-11-06 22:32:28,990 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 550 states, 415 states have (on average 1.2626506024096384) internal successors, (524), 455 states have internal predecessors, (524), 69 states have call successors, (69), 57 states have call predecessors, (69), 65 states have return successors, (110), 61 states have call predecessors, (110), 69 states have call successors, (110) [2023-11-06 22:32:28,996 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 550 states to 550 states and 703 transitions. [2023-11-06 22:32:28,996 INFO L78 Accepts]: Start accepts. Automaton has 550 states and 703 transitions. Word has length 32 [2023-11-06 22:32:28,998 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:28,998 INFO L495 AbstractCegarLoop]: Abstraction has 550 states and 703 transitions. [2023-11-06 22:32:28,998 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.833333333333333) internal successors, (29), 5 states have internal predecessors, (29), 1 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2023-11-06 22:32:28,998 INFO L276 IsEmpty]: Start isEmpty. Operand 550 states and 703 transitions. [2023-11-06 22:32:29,003 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:32:29,003 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:29,003 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:29,003 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:32:29,004 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:29,004 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:29,004 INFO L85 PathProgramCache]: Analyzing trace with hash -1897123065, now seen corresponding path program 1 times [2023-11-06 22:32:29,005 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:29,005 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1094801433] [2023-11-06 22:32:29,005 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:29,005 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:29,037 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,113 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:29,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,122 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:32:29,134 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,166 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:29,170 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,207 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:29,210 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,213 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:29,213 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:29,213 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1094801433] [2023-11-06 22:32:29,214 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1094801433] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:29,214 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:29,214 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:32:29,214 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [657079461] [2023-11-06 22:32:29,215 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:29,215 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:32:29,215 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:29,216 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:32:29,216 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:32:29,217 INFO L87 Difference]: Start difference. First operand 550 states and 703 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:29,705 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:29,706 INFO L93 Difference]: Finished difference Result 1023 states and 1352 transitions. [2023-11-06 22:32:29,706 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-06 22:32:29,706 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2023-11-06 22:32:29,707 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:29,711 INFO L225 Difference]: With dead ends: 1023 [2023-11-06 22:32:29,712 INFO L226 Difference]: Without dead ends: 680 [2023-11-06 22:32:29,714 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 6 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=40, Invalid=70, Unknown=0, NotChecked=0, Total=110 [2023-11-06 22:32:29,717 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 160 mSDsluCounter, 185 mSDsCounter, 0 mSdLazyCounter, 307 mSolverCounterSat, 51 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 161 SdHoareTripleChecker+Valid, 249 SdHoareTripleChecker+Invalid, 358 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 51 IncrementalHoareTripleChecker+Valid, 307 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:29,718 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [161 Valid, 249 Invalid, 358 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [51 Valid, 307 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:32:29,720 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 680 states. [2023-11-06 22:32:29,822 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 680 to 602. [2023-11-06 22:32:29,824 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 602 states, 457 states have (on average 1.2516411378555798) internal successors, (572), 497 states have internal predecessors, (572), 69 states have call successors, (69), 57 states have call predecessors, (69), 75 states have return successors, (124), 69 states have call predecessors, (124), 69 states have call successors, (124) [2023-11-06 22:32:29,829 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 602 states to 602 states and 765 transitions. [2023-11-06 22:32:29,830 INFO L78 Accepts]: Start accepts. Automaton has 602 states and 765 transitions. Word has length 55 [2023-11-06 22:32:29,831 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:29,831 INFO L495 AbstractCegarLoop]: Abstraction has 602 states and 765 transitions. [2023-11-06 22:32:29,831 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:29,831 INFO L276 IsEmpty]: Start isEmpty. Operand 602 states and 765 transitions. [2023-11-06 22:32:29,834 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:32:29,834 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:29,834 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:29,834 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:32:29,835 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:29,835 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:29,835 INFO L85 PathProgramCache]: Analyzing trace with hash -2031136571, now seen corresponding path program 1 times [2023-11-06 22:32:29,835 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:29,836 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1297765261] [2023-11-06 22:32:29,836 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:29,836 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:29,854 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:29,952 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,961 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:32:29,966 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,978 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:29,982 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:29,996 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:29,998 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:30,001 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:30,002 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:30,002 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1297765261] [2023-11-06 22:32:30,002 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1297765261] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:30,002 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:30,002 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:32:30,002 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1664018550] [2023-11-06 22:32:30,003 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:30,003 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:32:30,003 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:30,004 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:32:30,004 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:32:30,004 INFO L87 Difference]: Start difference. First operand 602 states and 765 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:30,789 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:30,789 INFO L93 Difference]: Finished difference Result 1268 states and 1714 transitions. [2023-11-06 22:32:30,790 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2023-11-06 22:32:30,790 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2023-11-06 22:32:30,790 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:30,797 INFO L225 Difference]: With dead ends: 1268 [2023-11-06 22:32:30,797 INFO L226 Difference]: Without dead ends: 873 [2023-11-06 22:32:30,801 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 29 GetRequests, 10 SyntacticMatches, 2 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 56 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=106, Invalid=236, Unknown=0, NotChecked=0, Total=342 [2023-11-06 22:32:30,804 INFO L413 NwaCegarLoop]: 93 mSDtfsCounter, 217 mSDsluCounter, 330 mSDsCounter, 0 mSdLazyCounter, 532 mSolverCounterSat, 66 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 220 SdHoareTripleChecker+Valid, 423 SdHoareTripleChecker+Invalid, 598 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 66 IncrementalHoareTripleChecker+Valid, 532 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:30,804 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [220 Valid, 423 Invalid, 598 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [66 Valid, 532 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2023-11-06 22:32:30,807 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 873 states. [2023-11-06 22:32:30,925 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 873 to 824. [2023-11-06 22:32:30,927 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 824 states, 628 states have (on average 1.2356687898089171) internal successors, (776), 676 states have internal predecessors, (776), 93 states have call successors, (93), 81 states have call predecessors, (93), 102 states have return successors, (208), 101 states have call predecessors, (208), 93 states have call successors, (208) [2023-11-06 22:32:30,933 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 824 states to 824 states and 1077 transitions. [2023-11-06 22:32:30,934 INFO L78 Accepts]: Start accepts. Automaton has 824 states and 1077 transitions. Word has length 55 [2023-11-06 22:32:30,934 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:30,934 INFO L495 AbstractCegarLoop]: Abstraction has 824 states and 1077 transitions. [2023-11-06 22:32:30,934 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:30,935 INFO L276 IsEmpty]: Start isEmpty. Operand 824 states and 1077 transitions. [2023-11-06 22:32:30,937 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:32:30,937 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:30,937 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:30,937 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2023-11-06 22:32:30,937 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:30,938 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:30,938 INFO L85 PathProgramCache]: Analyzing trace with hash -1959162679, now seen corresponding path program 1 times [2023-11-06 22:32:30,938 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:30,938 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [544087600] [2023-11-06 22:32:30,938 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:30,939 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:30,958 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,001 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:31,003 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,008 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:32:31,013 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,029 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:31,033 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,072 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:31,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,076 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:31,076 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:31,076 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [544087600] [2023-11-06 22:32:31,076 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [544087600] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:31,076 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:31,076 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-06 22:32:31,076 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1779768210] [2023-11-06 22:32:31,077 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:31,077 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-06 22:32:31,077 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:31,078 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-06 22:32:31,078 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=31, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:32:31,078 INFO L87 Difference]: Start difference. First operand 824 states and 1077 transitions. Second operand has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:31,572 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:31,572 INFO L93 Difference]: Finished difference Result 1719 states and 2316 transitions. [2023-11-06 22:32:31,572 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-06 22:32:31,572 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2023-11-06 22:32:31,573 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:31,580 INFO L225 Difference]: With dead ends: 1719 [2023-11-06 22:32:31,580 INFO L226 Difference]: Without dead ends: 902 [2023-11-06 22:32:31,584 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 21 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=43, Invalid=89, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:32:31,584 INFO L413 NwaCegarLoop]: 64 mSDtfsCounter, 162 mSDsluCounter, 244 mSDsCounter, 0 mSdLazyCounter, 338 mSolverCounterSat, 60 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 163 SdHoareTripleChecker+Valid, 308 SdHoareTripleChecker+Invalid, 398 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 60 IncrementalHoareTripleChecker+Valid, 338 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:31,585 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [163 Valid, 308 Invalid, 398 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [60 Valid, 338 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-06 22:32:31,586 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 902 states. [2023-11-06 22:32:31,679 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 902 to 836. [2023-11-06 22:32:31,682 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 836 states, 640 states have (on average 1.23125) internal successors, (788), 688 states have internal predecessors, (788), 93 states have call successors, (93), 81 states have call predecessors, (93), 102 states have return successors, (208), 101 states have call predecessors, (208), 93 states have call successors, (208) [2023-11-06 22:32:31,688 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 836 states to 836 states and 1089 transitions. [2023-11-06 22:32:31,689 INFO L78 Accepts]: Start accepts. Automaton has 836 states and 1089 transitions. Word has length 55 [2023-11-06 22:32:31,689 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:31,689 INFO L495 AbstractCegarLoop]: Abstraction has 836 states and 1089 transitions. [2023-11-06 22:32:31,689 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 6.571428571428571) internal successors, (46), 5 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:31,689 INFO L276 IsEmpty]: Start isEmpty. Operand 836 states and 1089 transitions. [2023-11-06 22:32:31,691 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:32:31,692 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:31,692 INFO L195 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:31,692 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2023-11-06 22:32:31,692 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:31,693 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:31,693 INFO L85 PathProgramCache]: Analyzing trace with hash -2093176185, now seen corresponding path program 1 times [2023-11-06 22:32:31,693 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:31,693 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1562458500] [2023-11-06 22:32:31,693 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:31,693 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:31,706 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,783 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:31,785 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,790 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:32:31,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,808 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:31,812 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,836 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:31,837 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:31,839 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:31,839 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:31,840 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1562458500] [2023-11-06 22:32:31,840 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1562458500] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:31,840 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:32:31,840 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:32:31,840 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [869450186] [2023-11-06 22:32:31,840 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:31,841 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:32:31,841 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:31,841 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:32:31,841 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:32:31,842 INFO L87 Difference]: Start difference. First operand 836 states and 1089 transitions. Second operand has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:32,223 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:32,224 INFO L93 Difference]: Finished difference Result 1546 states and 2060 transitions. [2023-11-06 22:32:32,224 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:32:32,225 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 55 [2023-11-06 22:32:32,226 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:32,231 INFO L225 Difference]: With dead ends: 1546 [2023-11-06 22:32:32,232 INFO L226 Difference]: Without dead ends: 717 [2023-11-06 22:32:32,237 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 18 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=27, Invalid=45, Unknown=0, NotChecked=0, Total=72 [2023-11-06 22:32:32,237 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 163 mSDsluCounter, 189 mSDsCounter, 0 mSdLazyCounter, 261 mSolverCounterSat, 55 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 164 SdHoareTripleChecker+Valid, 251 SdHoareTripleChecker+Invalid, 316 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 55 IncrementalHoareTripleChecker+Valid, 261 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:32,239 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [164 Valid, 251 Invalid, 316 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [55 Valid, 261 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:32:32,240 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 717 states. [2023-11-06 22:32:32,318 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 717 to 697. [2023-11-06 22:32:32,320 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 697 states, 531 states have (on average 1.2241054613935969) internal successors, (650), 570 states have internal predecessors, (650), 82 states have call successors, (82), 70 states have call predecessors, (82), 83 states have return successors, (163), 84 states have call predecessors, (163), 82 states have call successors, (163) [2023-11-06 22:32:32,325 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 697 states to 697 states and 895 transitions. [2023-11-06 22:32:32,325 INFO L78 Accepts]: Start accepts. Automaton has 697 states and 895 transitions. Word has length 55 [2023-11-06 22:32:32,325 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:32,326 INFO L495 AbstractCegarLoop]: Abstraction has 697 states and 895 transitions. [2023-11-06 22:32:32,326 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.666666666666667) internal successors, (46), 4 states have internal predecessors, (46), 2 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2023-11-06 22:32:32,326 INFO L276 IsEmpty]: Start isEmpty. Operand 697 states and 895 transitions. [2023-11-06 22:32:32,331 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2023-11-06 22:32:32,331 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:32,332 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:32,332 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2023-11-06 22:32:32,332 INFO L420 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:32,333 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:32,333 INFO L85 PathProgramCache]: Analyzing trace with hash 1124052112, now seen corresponding path program 1 times [2023-11-06 22:32:32,333 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:32,333 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1553242907] [2023-11-06 22:32:32,333 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:32,333 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:32,361 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,541 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:32,542 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,555 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:32:32,560 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,581 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:32:32,585 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,595 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:32,599 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,611 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:32,613 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,618 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2023-11-06 22:32:32,619 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,622 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2023-11-06 22:32:32,625 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,633 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:32:32,634 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,636 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:32,637 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,639 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 11 proven. 9 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:32:32,639 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:32,640 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1553242907] [2023-11-06 22:32:32,640 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1553242907] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:32:32,640 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2010203975] [2023-11-06 22:32:32,640 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:32,640 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:32,641 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:32:32,644 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:32:32,673 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-06 22:32:32,810 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:32,822 INFO L262 TraceCheckSpWp]: Trace formula consists of 341 conjuncts, 8 conjunts are in the unsatisfiable core [2023-11-06 22:32:32,832 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:32:33,079 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 16 proven. 12 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:32:33,079 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-06 22:32:33,286 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 12 proven. 8 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2023-11-06 22:32:33,286 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2010203975] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-06 22:32:33,287 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-06 22:32:33,287 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [9, 6, 6] total 9 [2023-11-06 22:32:33,287 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1568006668] [2023-11-06 22:32:33,287 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-06 22:32:33,288 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2023-11-06 22:32:33,288 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:33,289 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2023-11-06 22:32:33,289 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2023-11-06 22:32:33,290 INFO L87 Difference]: Start difference. First operand 697 states and 895 transitions. Second operand has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:32:34,274 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:34,274 INFO L93 Difference]: Finished difference Result 1672 states and 2265 transitions. [2023-11-06 22:32:34,274 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 27 states. [2023-11-06 22:32:34,275 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 101 [2023-11-06 22:32:34,275 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:34,284 INFO L225 Difference]: With dead ends: 1672 [2023-11-06 22:32:34,285 INFO L226 Difference]: Without dead ends: 1099 [2023-11-06 22:32:34,288 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 254 GetRequests, 219 SyntacticMatches, 8 SemanticMatches, 27 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 203 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=227, Invalid=585, Unknown=0, NotChecked=0, Total=812 [2023-11-06 22:32:34,289 INFO L413 NwaCegarLoop]: 85 mSDtfsCounter, 274 mSDsluCounter, 442 mSDsCounter, 0 mSdLazyCounter, 590 mSolverCounterSat, 86 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 282 SdHoareTripleChecker+Valid, 527 SdHoareTripleChecker+Invalid, 676 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 86 IncrementalHoareTripleChecker+Valid, 590 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:34,290 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [282 Valid, 527 Invalid, 676 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [86 Valid, 590 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2023-11-06 22:32:34,292 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1099 states. [2023-11-06 22:32:34,416 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1099 to 964. [2023-11-06 22:32:34,418 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 964 states, 726 states have (on average 1.2314049586776858) internal successors, (894), 783 states have internal predecessors, (894), 119 states have call successors, (119), 101 states have call predecessors, (119), 118 states have return successors, (250), 113 states have call predecessors, (250), 119 states have call successors, (250) [2023-11-06 22:32:34,425 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 964 states to 964 states and 1263 transitions. [2023-11-06 22:32:34,425 INFO L78 Accepts]: Start accepts. Automaton has 964 states and 1263 transitions. Word has length 101 [2023-11-06 22:32:34,425 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:34,426 INFO L495 AbstractCegarLoop]: Abstraction has 964 states and 1263 transitions. [2023-11-06 22:32:34,426 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 9 states have (on average 11.0) internal successors, (99), 6 states have internal predecessors, (99), 3 states have call successors, (21), 6 states have call predecessors, (21), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:32:34,426 INFO L276 IsEmpty]: Start isEmpty. Operand 964 states and 1263 transitions. [2023-11-06 22:32:34,430 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2023-11-06 22:32:34,431 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:34,431 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:34,443 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-06 22:32:34,637 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:34,638 INFO L420 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:34,638 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:34,638 INFO L85 PathProgramCache]: Analyzing trace with hash -159048421, now seen corresponding path program 2 times [2023-11-06 22:32:34,639 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:34,639 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1471421163] [2023-11-06 22:32:34,639 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:34,639 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:34,667 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,846 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:34,847 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,855 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:32:34,859 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,876 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:32:34,879 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,889 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:34,892 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,902 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:34,903 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:34,906 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-06 22:32:34,912 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,004 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:32:35,006 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,008 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:32:35,011 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,100 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:32:35,102 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,104 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:35,104 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,105 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2023-11-06 22:32:35,107 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,108 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2023-11-06 22:32:35,111 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,114 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:32:35,115 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,117 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:35,117 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:35,119 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 49 proven. 23 refuted. 0 times theorem prover too weak. 30 trivial. 0 not checked. [2023-11-06 22:32:35,119 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:35,119 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1471421163] [2023-11-06 22:32:35,119 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1471421163] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:32:35,119 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [168636428] [2023-11-06 22:32:35,120 INFO L93 rtionOrderModulation]: Changing assertion order to OUTSIDE_LOOP_FIRST1 [2023-11-06 22:32:35,120 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:35,120 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:32:35,121 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:32:35,140 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-06 22:32:35,266 INFO L228 tOrderPrioritization]: Assert order OUTSIDE_LOOP_FIRST1 issued 2 check-sat command(s) [2023-11-06 22:32:35,267 INFO L229 tOrderPrioritization]: Conjunction of SSA is unsat [2023-11-06 22:32:35,269 INFO L262 TraceCheckSpWp]: Trace formula consists of 455 conjuncts, 10 conjunts are in the unsatisfiable core [2023-11-06 22:32:35,284 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:32:35,379 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 84 proven. 0 refuted. 0 times theorem prover too weak. 18 trivial. 0 not checked. [2023-11-06 22:32:35,379 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:32:35,379 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [168636428] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:35,380 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:32:35,380 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [11] total 12 [2023-11-06 22:32:35,380 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1744832103] [2023-11-06 22:32:35,380 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:35,381 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:32:35,381 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:35,382 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:32:35,382 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=26, Invalid=106, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:32:35,382 INFO L87 Difference]: Start difference. First operand 964 states and 1263 transitions. Second operand has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:32:35,839 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:35,839 INFO L93 Difference]: Finished difference Result 2581 states and 3531 transitions. [2023-11-06 22:32:35,840 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2023-11-06 22:32:35,840 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) Word has length 147 [2023-11-06 22:32:35,841 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:35,853 INFO L225 Difference]: With dead ends: 2581 [2023-11-06 22:32:35,854 INFO L226 Difference]: Without dead ends: 1739 [2023-11-06 22:32:35,859 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 192 GetRequests, 174 SyntacticMatches, 3 SemanticMatches, 15 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=57, Invalid=215, Unknown=0, NotChecked=0, Total=272 [2023-11-06 22:32:35,860 INFO L413 NwaCegarLoop]: 192 mSDtfsCounter, 213 mSDsluCounter, 468 mSDsCounter, 0 mSdLazyCounter, 150 mSolverCounterSat, 26 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 215 SdHoareTripleChecker+Valid, 660 SdHoareTripleChecker+Invalid, 176 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 26 IncrementalHoareTripleChecker+Valid, 150 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:35,860 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [215 Valid, 660 Invalid, 176 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [26 Valid, 150 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:32:35,863 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1739 states. [2023-11-06 22:32:36,048 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1739 to 1703. [2023-11-06 22:32:36,052 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1703 states, 1286 states have (on average 1.2301710730948678) internal successors, (1582), 1370 states have internal predecessors, (1582), 202 states have call successors, (202), 180 states have call predecessors, (202), 214 states have return successors, (404), 204 states have call predecessors, (404), 202 states have call successors, (404) [2023-11-06 22:32:36,065 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1703 states to 1703 states and 2188 transitions. [2023-11-06 22:32:36,066 INFO L78 Accepts]: Start accepts. Automaton has 1703 states and 2188 transitions. Word has length 147 [2023-11-06 22:32:36,067 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:36,067 INFO L495 AbstractCegarLoop]: Abstraction has 1703 states and 2188 transitions. [2023-11-06 22:32:36,067 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 17.666666666666668) internal successors, (106), 6 states have internal predecessors, (106), 3 states have call successors, (14), 4 states have call predecessors, (14), 3 states have return successors, (14), 3 states have call predecessors, (14), 3 states have call successors, (14) [2023-11-06 22:32:36,067 INFO L276 IsEmpty]: Start isEmpty. Operand 1703 states and 2188 transitions. [2023-11-06 22:32:36,073 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 148 [2023-11-06 22:32:36,073 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:32:36,074 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:36,084 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-06 22:32:36,279 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:36,280 INFO L420 AbstractCegarLoop]: === Iteration 13 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:32:36,280 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:32:36,280 INFO L85 PathProgramCache]: Analyzing trace with hash -1375202147, now seen corresponding path program 1 times [2023-11-06 22:32:36,280 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:32:36,280 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1220032397] [2023-11-06 22:32:36,280 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:36,281 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:32:36,302 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,431 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-06 22:32:36,432 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,440 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:32:36,443 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,454 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-06 22:32:36,456 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,460 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:36,462 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,465 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-06 22:32:36,466 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,469 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-06 22:32:36,475 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,494 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-06 22:32:36,495 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,496 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:32:36,499 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,532 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:32:36,534 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,535 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:36,536 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,537 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 115 [2023-11-06 22:32:36,538 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,541 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 122 [2023-11-06 22:32:36,546 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,549 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-06 22:32:36,551 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,553 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:32:36,554 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,557 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 43 proven. 6 refuted. 0 times theorem prover too weak. 53 trivial. 0 not checked. [2023-11-06 22:32:36,557 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:32:36,557 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1220032397] [2023-11-06 22:32:36,558 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1220032397] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:32:36,558 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1603855526] [2023-11-06 22:32:36,558 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:32:36,558 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:36,558 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:32:36,559 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:32:36,592 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2023-11-06 22:32:36,706 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:32:36,708 INFO L262 TraceCheckSpWp]: Trace formula consists of 456 conjuncts, 5 conjunts are in the unsatisfiable core [2023-11-06 22:32:36,717 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:32:36,742 INFO L134 CoverageAnalysis]: Checked inductivity of 102 backedges. 70 proven. 0 refuted. 0 times theorem prover too weak. 32 trivial. 0 not checked. [2023-11-06 22:32:36,742 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-06 22:32:36,742 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1603855526] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:32:36,742 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-06 22:32:36,743 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [10] total 10 [2023-11-06 22:32:36,745 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [248714968] [2023-11-06 22:32:36,745 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:32:36,747 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:32:36,747 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:32:36,748 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:32:36,748 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=19, Invalid=71, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:32:36,749 INFO L87 Difference]: Start difference. First operand 1703 states and 2188 transitions. Second operand has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:32:36,876 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:32:36,877 INFO L93 Difference]: Finished difference Result 2351 states and 2994 transitions. [2023-11-06 22:32:36,877 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:32:36,878 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) Word has length 147 [2023-11-06 22:32:36,878 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:32:36,881 INFO L225 Difference]: With dead ends: 2351 [2023-11-06 22:32:36,881 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:32:36,887 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 187 GetRequests, 177 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=27, Invalid=105, Unknown=0, NotChecked=0, Total=132 [2023-11-06 22:32:36,888 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 6 mSDsluCounter, 326 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 6 SdHoareTripleChecker+Valid, 440 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:32:36,889 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [6 Valid, 440 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:32:36,890 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:32:36,890 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:32:36,890 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:32:36,890 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:32:36,891 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 147 [2023-11-06 22:32:36,891 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:32:36,891 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:32:36,891 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 19.6) internal successors, (98), 5 states have internal predecessors, (98), 2 states have call successors, (12), 2 states have call predecessors, (12), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2023-11-06 22:32:36,891 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:32:36,891 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:32:36,894 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:32:36,901 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2023-11-06 22:32:37,100 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable12,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:32:37,102 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:32:41,017 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 841 848) no Hoare annotation was computed. [2023-11-06 22:32:41,018 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 841 848) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,018 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 841 848) no Hoare annotation was computed. [2023-11-06 22:32:41,018 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 731 737) no Hoare annotation was computed. [2023-11-06 22:32:41,018 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 731 737) the Hoare annotation is: true [2023-11-06 22:32:41,018 INFO L899 garLoopResultBuilder]: For program point L619-1(lines 615 626) no Hoare annotation was computed. [2023-11-06 22:32:41,018 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 615 626) the Hoare annotation is: true [2023-11-06 22:32:41,019 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 615 626) no Hoare annotation was computed. [2023-11-06 22:32:41,019 INFO L899 garLoopResultBuilder]: For program point L799(lines 799 807) no Hoare annotation was computed. [2023-11-06 22:32:41,019 INFO L899 garLoopResultBuilder]: For program point L795(lines 795 812) no Hoare annotation was computed. [2023-11-06 22:32:41,019 INFO L899 garLoopResultBuilder]: For program point L696(line 696) no Hoare annotation was computed. [2023-11-06 22:32:41,019 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 707 730) no Hoare annotation was computed. [2023-11-06 22:32:41,019 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 659 667) the Hoare annotation is: (let ((.cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse4 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse2 (= 0 ~systemActive~0))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse6 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse1 (< |old(~waterLevel~0)| 2)) (.cse3 (and .cse7 .cse4 (not .cse2)))) (and (or .cse0 .cse1 .cse2 .cse3) (or (and (<= 2 ~waterLevel~0) .cse4) .cse1 (and .cse5 (<= 1 ~waterLevel~0) .cse6) .cse2) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and .cse5 (= ~waterLevel~0 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse0 (and .cse5 .cse6 .cse7) .cse1 .cse3)))) [2023-11-06 22:32:41,020 INFO L899 garLoopResultBuilder]: For program point L718-1(lines 718 724) no Hoare annotation was computed. [2023-11-06 22:32:41,020 INFO L895 garLoopResultBuilder]: At program point L805(line 805) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,020 INFO L895 garLoopResultBuilder]: At program point L801(line 801) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,020 INFO L895 garLoopResultBuilder]: At program point L797(line 797) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,020 INFO L899 garLoopResultBuilder]: For program point L797-1(line 797) no Hoare annotation was computed. [2023-11-06 22:32:41,021 INFO L899 garLoopResultBuilder]: For program point L570(lines 570 576) no Hoare annotation was computed. [2023-11-06 22:32:41,021 INFO L899 garLoopResultBuilder]: For program point L566(lines 566 579) no Hoare annotation was computed. [2023-11-06 22:32:41,021 INFO L895 garLoopResultBuilder]: At program point L566-1(lines 558 582) the Hoare annotation is: (let ((.cse7 (<= 2 ~waterLevel~0)) (.cse10 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse8 (<= 2 |timeShift_getWaterLevel_#res#1|)) (.cse9 (<= 2 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|)) (.cse3 (= 0 ~systemActive~0))) (let ((.cse2 (< |old(~waterLevel~0)| 2)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (and .cse7 .cse10 .cse8 .cse9 (not .cse3))) (.cse4 (= ~pumpRunning~0 0)) (.cse5 (<= 1 |timeShift_getWaterLevel_#res#1|)) (.cse6 (<= 1 |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1|))) (and (or .cse0 .cse1 .cse2 .cse3) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (and (= |timeShift___utac_acc__Specification4_spec__1_~tmp~4#1| 1) (= |timeShift_getWaterLevel_#res#1| 1))) (or .cse2 (and .cse4 (<= 1 ~waterLevel~0) .cse5 .cse6) (and .cse7 .cse8 .cse9) .cse3) (or .cse0 (< |old(~waterLevel~0)| 1) .cse1 (and .cse4 .cse5 .cse10 .cse6))))) [2023-11-06 22:32:41,021 INFO L899 garLoopResultBuilder]: For program point L595(lines 595 599) no Hoare annotation was computed. [2023-11-06 22:32:41,021 INFO L895 garLoopResultBuilder]: At program point L595-2(lines 591 602) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 ~waterLevel~0)) (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,021 INFO L895 garLoopResultBuilder]: At program point L810(line 810) the Hoare annotation is: (let ((.cse0 (= |old(~pumpRunning~0)| 0)) (.cse1 (= 0 ~systemActive~0))) (and (or (< |old(~waterLevel~0)| 2) .cse0 .cse1) (or (not .cse0) (< |old(~waterLevel~0)| 1) (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0) (not .cse1))))) [2023-11-06 22:32:41,022 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 692 699) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,022 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 707 730) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) (and (= ~pumpRunning~0 0) .cse0)) (or (< |old(~waterLevel~0)| 2) (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) .cse0) (= 0 ~systemActive~0)))) [2023-11-06 22:32:41,022 INFO L895 garLoopResultBuilder]: At program point L810-1(lines 791 815) the Hoare annotation is: (let ((.cse3 (<= 2 ~waterLevel~0)) (.cse4 (= 0 ~systemActive~0)) (.cse0 (= ~pumpRunning~0 0))) (and (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not .cse4))) (or (not (= |old(~pumpRunning~0)| 0)) (< |old(~waterLevel~0)| 1) (and .cse0 .cse1 .cse2) (and .cse3 .cse1 .cse2))) (or .cse3 (< |old(~waterLevel~0)| 2) .cse4 (and .cse0 (<= 1 ~waterLevel~0))))) [2023-11-06 22:32:41,022 INFO L899 garLoopResultBuilder]: For program point L711-1(lines 710 729) no Hoare annotation was computed. [2023-11-06 22:32:41,022 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 707 730) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L895 garLoopResultBuilder]: At program point isPumpRunning_returnLabel#1(lines 860 868) the Hoare annotation is: (let ((.cse0 (< |old(~waterLevel~0)| 2)) (.cse1 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 (= 0 ~systemActive~0)) (or .cse1 .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1))))) [2023-11-06 22:32:41,023 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 696) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 418 447) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L902 garLoopResultBuilder]: At program point L443(lines 418 447) the Hoare annotation is: true [2023-11-06 22:32:41,023 INFO L899 garLoopResultBuilder]: For program point L439(line 439) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L899 garLoopResultBuilder]: For program point L432(lines 432 436) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L902 garLoopResultBuilder]: At program point L432-1(lines 432 436) the Hoare annotation is: true [2023-11-06 22:32:41,023 INFO L899 garLoopResultBuilder]: For program point L429(line 429) no Hoare annotation was computed. [2023-11-06 22:32:41,023 INFO L902 garLoopResultBuilder]: At program point L428-2(lines 428 442) the Hoare annotation is: true [2023-11-06 22:32:41,024 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 418 447) the Hoare annotation is: true [2023-11-06 22:32:41,024 INFO L902 garLoopResultBuilder]: At program point L424(line 424) the Hoare annotation is: true [2023-11-06 22:32:41,024 INFO L899 garLoopResultBuilder]: For program point L424-1(line 424) no Hoare annotation was computed. [2023-11-06 22:32:41,024 INFO L899 garLoopResultBuilder]: For program point L989(lines 989 995) no Hoare annotation was computed. [2023-11-06 22:32:41,024 INFO L899 garLoopResultBuilder]: For program point L989-1(lines 989 995) no Hoare annotation was computed. [2023-11-06 22:32:41,024 INFO L899 garLoopResultBuilder]: For program point L506(lines 506 513) no Hoare annotation was computed. [2023-11-06 22:32:41,024 INFO L899 garLoopResultBuilder]: For program point L506-2(lines 506 513) no Hoare annotation was computed. [2023-11-06 22:32:41,024 INFO L895 garLoopResultBuilder]: At program point L1014(lines 969 1016) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2023-11-06 22:32:41,024 INFO L895 garLoopResultBuilder]: At program point L981(line 981) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2023-11-06 22:32:41,025 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 483 492) the Hoare annotation is: true [2023-11-06 22:32:41,025 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 531 537) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:32:41,025 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 496 518) the Hoare annotation is: true [2023-11-06 22:32:41,025 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:32:41,025 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:32:41,025 INFO L895 garLoopResultBuilder]: At program point L949(line 949) the Hoare annotation is: (and (<= 2 ~waterLevel~0) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2023-11-06 22:32:41,025 INFO L899 garLoopResultBuilder]: For program point L970(lines 969 1016) no Hoare annotation was computed. [2023-11-06 22:32:41,025 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 475 481) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= 1 ~systemActive~0) (= |ULTIMATE.start_main_~tmp~3#1| 1) (= ~waterLevel~0 1)) [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point L999(lines 999 1012) no Hoare annotation was computed. [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:32:41,026 INFO L895 garLoopResultBuilder]: At program point L991(line 991) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2023-11-06 22:32:41,026 INFO L902 garLoopResultBuilder]: At program point L1020(lines 959 1024) the Hoare annotation is: true [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point L979(lines 979 985) no Hoare annotation was computed. [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point L979-1(lines 979 985) no Hoare annotation was computed. [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point L971(lines 971 975) no Hoare annotation was computed. [2023-11-06 22:32:41,026 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:32:41,027 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 538 544) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:32:41,027 INFO L895 garLoopResultBuilder]: At program point L1017(lines 968 1018) the Hoare annotation is: false [2023-11-06 22:32:41,027 INFO L899 garLoopResultBuilder]: For program point L947(lines 947 953) no Hoare annotation was computed. [2023-11-06 22:32:41,027 INFO L899 garLoopResultBuilder]: For program point L947-1(lines 947 953) no Hoare annotation was computed. [2023-11-06 22:32:41,027 INFO L895 garLoopResultBuilder]: At program point stopSystem_returnLabel#1(lines 943 957) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse0 (<= 2 ~waterLevel~0) .cse1))) [2023-11-06 22:32:41,027 INFO L899 garLoopResultBuilder]: For program point L1005(lines 1005 1011) no Hoare annotation was computed. [2023-11-06 22:32:41,027 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 545 553) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= 1 ~systemActive~0) (= ~waterLevel~0 1)) [2023-11-06 22:32:41,028 INFO L895 garLoopResultBuilder]: At program point L1005-2(lines 999 1012) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 (= ~waterLevel~0 1)) (and .cse2 .cse1 (not (= 0 ~systemActive~0))) (and .cse0 .cse2 .cse1))) [2023-11-06 22:32:41,028 INFO L895 garLoopResultBuilder]: At program point L758(line 758) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,028 INFO L899 garLoopResultBuilder]: For program point L758-1(lines 739 763) no Hoare annotation was computed. [2023-11-06 22:32:41,028 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 739 763) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,028 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 668 681) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 0)) (.cse1 (= 0 ~systemActive~0)) (.cse4 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse4)) (.cse2 (and .cse3 (<= 2 ~waterLevel~0) .cse4 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0) (not .cse1)))) (and (or .cse0 (< ~waterLevel~0 2) .cse1 .cse2) (or .cse0 (< ~waterLevel~0 1) .cse1 .cse2 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse3))))) [2023-11-06 22:32:41,028 INFO L899 garLoopResultBuilder]: For program point L672(lines 672 678) no Hoare annotation was computed. [2023-11-06 22:32:41,028 INFO L899 garLoopResultBuilder]: For program point L831(lines 831 837) no Hoare annotation was computed. [2023-11-06 22:32:41,029 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 905 923) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= ~waterLevel~0 1)) .cse0 (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~9#1|) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~1#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0)) .cse1) (or .cse0 (= ~pumpRunning~0 0) (< ~waterLevel~0 1) .cse1))) [2023-11-06 22:32:41,029 INFO L895 garLoopResultBuilder]: At program point L829(line 829) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 0) (< ~waterLevel~0 2) .cse1) (or (not (= ~waterLevel~0 1)) .cse0 .cse1))) [2023-11-06 22:32:41,029 INFO L895 garLoopResultBuilder]: At program point L831-2(lines 824 840) the Hoare annotation is: (or (not (= ~waterLevel~0 1)) (not (= |old(~pumpRunning~0)| 0)) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,029 INFO L899 garLoopResultBuilder]: For program point L829-1(line 829) no Hoare annotation was computed. [2023-11-06 22:32:41,029 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 739 763) no Hoare annotation was computed. [2023-11-06 22:32:41,029 INFO L899 garLoopResultBuilder]: For program point L914(lines 914 918) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L895 garLoopResultBuilder]: At program point L753(line 753) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 0)) (.cse1 (= |processEnvironment__wrappee__highWaterSensor_~tmp~5#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) (and (<= 1 |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1|) .cse0 .cse1) (and .cse0 .cse1 (<= 2 ~waterLevel~0)) (< ~waterLevel~0 1) (= 0 ~systemActive~0))) [2023-11-06 22:32:41,030 INFO L899 garLoopResultBuilder]: For program point L914-2(lines 914 918) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L899 garLoopResultBuilder]: For program point L747(lines 747 755) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L899 garLoopResultBuilder]: For program point L743(lines 743 760) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L895 garLoopResultBuilder]: At program point activatePump__wrappee__lowWaterSensor_returnLabel#1(lines 816 823) the Hoare annotation is: (or (not (= |old(~pumpRunning~0)| 0)) (< ~waterLevel~0 1) (<= 2 ~waterLevel~0) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,030 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 603 614) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L899 garLoopResultBuilder]: For program point L607-1(lines 603 614) no Hoare annotation was computed. [2023-11-06 22:32:41,030 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 603 614) the Hoare annotation is: (let ((.cse0 (not (= ~pumpRunning~0 0))) (.cse1 (< |old(~waterLevel~0)| 2)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 .cse1 .cse2) (or .cse0 (not (= |old(~waterLevel~0)| 1)) (= ~waterLevel~0 1)) (or .cse1 .cse2 (= 0 ~systemActive~0)))) [2023-11-06 22:32:41,031 INFO L895 garLoopResultBuilder]: At program point isLowWaterSensorDry_returnLabel#1(lines 682 690) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0)) .cse1))) [2023-11-06 22:32:41,031 INFO L895 garLoopResultBuilder]: At program point L779(line 779) the Hoare annotation is: (or (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,031 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 765 789) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~waterLevel~0 1) (= 0 ~systemActive~0)) [2023-11-06 22:32:41,031 INFO L895 garLoopResultBuilder]: At program point L775(line 775) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_~tmp~6#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0))) (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1))) [2023-11-06 22:32:41,031 INFO L899 garLoopResultBuilder]: For program point L773(lines 773 781) no Hoare annotation was computed. [2023-11-06 22:32:41,031 INFO L899 garLoopResultBuilder]: For program point L769(lines 769 786) no Hoare annotation was computed. [2023-11-06 22:32:41,032 INFO L895 garLoopResultBuilder]: At program point isLowWaterLevel_returnLabel#1(lines 924 942) the Hoare annotation is: (let ((.cse0 (< ~waterLevel~0 1)) (.cse1 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 .cse1) (or .cse0 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp___0~2#1|) (<= 1 |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_#res#1|) (= |processEnvironment__wrappee__methaneQuery_isLowWaterSensorDry_#res#1| 0) (= |processEnvironment__wrappee__methaneQuery_isLowWaterLevel_~tmp~10#1| 0)) .cse1))) [2023-11-06 22:32:41,032 INFO L895 garLoopResultBuilder]: At program point L784(line 784) the Hoare annotation is: (or (< ~waterLevel~0 1) (= 0 ~systemActive~0) (and (= ~pumpRunning~0 0) (= |old(~pumpRunning~0)| 0))) [2023-11-06 22:32:41,032 INFO L899 garLoopResultBuilder]: For program point L784-1(lines 765 789) no Hoare annotation was computed. [2023-11-06 22:32:41,032 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 765 789) no Hoare annotation was computed. [2023-11-06 22:32:41,032 INFO L899 garLoopResultBuilder]: For program point L933(lines 933 937) no Hoare annotation was computed. [2023-11-06 22:32:41,032 INFO L899 garLoopResultBuilder]: For program point L933-2(lines 933 937) no Hoare annotation was computed. [2023-11-06 22:32:41,032 INFO L902 garLoopResultBuilder]: At program point isMethaneLevelCritical_returnLabel#1(lines 627 635) the Hoare annotation is: true [2023-11-06 22:32:41,032 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 849 859) no Hoare annotation was computed. [2023-11-06 22:32:41,033 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 849 859) the Hoare annotation is: true [2023-11-06 22:32:41,033 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmFINAL(lines 849 859) no Hoare annotation was computed. [2023-11-06 22:32:41,035 INFO L445 BasicCegarLoop]: Path program histogram: [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:32:41,038 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:32:41,069 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:32:41 BoogieIcfgContainer [2023-11-06 22:32:41,069 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:32:41,070 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:32:41,070 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:32:41,070 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:32:41,071 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:32:26" (3/4) ... [2023-11-06 22:32:41,073 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:32:41,078 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-06 22:32:41,078 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:32:41,078 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:32:41,078 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:32:41,078 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:32:41,079 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:32:41,079 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:32:41,079 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2023-11-06 22:32:41,079 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2023-11-06 22:32:41,089 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 19 nodes and edges [2023-11-06 22:32:41,090 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:32:41,090 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:32:41,091 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:32:41,092 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:32:41,121 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (waterLevel == 1)) [2023-11-06 22:32:41,122 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (tmp == 1)) && (waterLevel == 1)) [2023-11-06 22:32:41,123 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((\old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel))) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,123 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) && ((((2 <= waterLevel) || (\old(waterLevel) < 2)) || (0 == systemActive)) || ((pumpRunning == 0) && (1 <= waterLevel)))) [2023-11-06 22:32:41,124 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (0 == systemActive)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive)))) && (((((2 <= waterLevel) && (2 <= \result)) || (\old(waterLevel) < 2)) || (((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result))) || (0 == systemActive))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (waterLevel == 1)) && (\result == 1)))) && (((!((\old(pumpRunning) == 0)) || (((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || (\old(waterLevel) < 2)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive))))) [2023-11-06 22:32:41,125 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || (\old(waterLevel) < 2)) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((tmp == 1) && (\result == 1)))) && ((((\old(waterLevel) < 2) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (1 <= tmp))) || (((2 <= waterLevel) && (2 <= \result)) && (2 <= tmp))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || ((((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel)) && (1 <= tmp)))) [2023-11-06 22:32:41,125 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:32:41,126 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 2)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) && ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) || ((1 <= \result) && (pumpRunning == 0)))) [2023-11-06 22:32:41,126 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,126 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) [2023-11-06 22:32:41,126 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:32:41,127 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive))) [2023-11-06 22:32:41,127 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || ((((1 <= \result) && (1 <= tmp)) && (tmp___0 == 0)) && (\result == 0))) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel < 1)) || (0 == systemActive))) [2023-11-06 22:32:41,127 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (waterLevel == 1)) [2023-11-06 22:32:41,165 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (tmp == 1)) && (waterLevel == 1)) [2023-11-06 22:32:41,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((\old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel))) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,166 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) && ((((2 <= waterLevel) || (\old(waterLevel) < 2)) || (0 == systemActive)) || ((pumpRunning == 0) && (1 <= waterLevel)))) [2023-11-06 22:32:41,167 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (0 == systemActive)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive)))) && (((((2 <= waterLevel) && (2 <= \result)) || (\old(waterLevel) < 2)) || (((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result))) || (0 == systemActive))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (waterLevel == 1)) && (\result == 1)))) && (((!((\old(pumpRunning) == 0)) || (((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || (\old(waterLevel) < 2)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive))))) [2023-11-06 22:32:41,167 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || (\old(waterLevel) < 2)) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((tmp == 1) && (\result == 1)))) && ((((\old(waterLevel) < 2) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (1 <= tmp))) || (((2 <= waterLevel) && (2 <= \result)) && (2 <= tmp))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || ((((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel)) && (1 <= tmp)))) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 2)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) && ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) || ((1 <= \result) && (pumpRunning == 0)))) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) [2023-11-06 22:32:41,168 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive))) [2023-11-06 22:32:41,169 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || ((((1 <= \result) && (1 <= tmp)) && (tmp___0 == 0)) && (\result == 0))) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel < 1)) || (0 == systemActive))) [2023-11-06 22:32:41,169 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) [2023-11-06 22:32:41,187 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:32:41,188 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:32:41,188 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:32:41,189 INFO L158 Benchmark]: Toolchain (without parser) took 16294.75ms. Allocated memory was 174.1MB in the beginning and 331.4MB in the end (delta: 157.3MB). Free memory was 136.1MB in the beginning and 249.1MB in the end (delta: -113.0MB). Peak memory consumption was 45.8MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,189 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 174.1MB. Free memory is still 149.7MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:32:41,189 INFO L158 Benchmark]: CACSL2BoogieTranslator took 555.40ms. Allocated memory is still 174.1MB. Free memory was 135.6MB in the beginning and 115.6MB in the end (delta: 20.0MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,190 INFO L158 Benchmark]: Boogie Procedure Inliner took 68.99ms. Allocated memory is still 174.1MB. Free memory was 115.6MB in the beginning and 113.5MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,190 INFO L158 Benchmark]: Boogie Preprocessor took 31.83ms. Allocated memory is still 174.1MB. Free memory was 113.5MB in the beginning and 111.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,190 INFO L158 Benchmark]: RCFGBuilder took 512.70ms. Allocated memory is still 174.1MB. Free memory was 111.9MB in the beginning and 93.7MB in the end (delta: 18.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,191 INFO L158 Benchmark]: TraceAbstraction took 14999.96ms. Allocated memory was 174.1MB in the beginning and 331.4MB in the end (delta: 157.3MB). Free memory was 93.1MB in the beginning and 257.5MB in the end (delta: -164.5MB). Peak memory consumption was 146.4MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,191 INFO L158 Benchmark]: Witness Printer took 117.95ms. Allocated memory is still 331.4MB. Free memory was 257.5MB in the beginning and 249.1MB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2023-11-06 22:32:41,193 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 174.1MB. Free memory is still 149.7MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 555.40ms. Allocated memory is still 174.1MB. Free memory was 135.6MB in the beginning and 115.6MB in the end (delta: 20.0MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 68.99ms. Allocated memory is still 174.1MB. Free memory was 115.6MB in the beginning and 113.5MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 31.83ms. Allocated memory is still 174.1MB. Free memory was 113.5MB in the beginning and 111.9MB in the end (delta: 1.6MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 512.70ms. Allocated memory is still 174.1MB. Free memory was 111.9MB in the beginning and 93.7MB in the end (delta: 18.3MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 14999.96ms. Allocated memory was 174.1MB in the beginning and 331.4MB in the end (delta: 157.3MB). Free memory was 93.1MB in the beginning and 257.5MB in the end (delta: -164.5MB). Peak memory consumption was 146.4MB. Max. memory is 16.1GB. * Witness Printer took 117.95ms. Allocated memory is still 331.4MB. Free memory was 257.5MB in the beginning and 249.1MB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [49] - GenericResultAtLocation [Line: 415]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [415] - GenericResultAtLocation [Line: 519]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [519] - GenericResultAtLocation [Line: 554]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification4_spec.i","") [554] - GenericResultAtLocation [Line: 583]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [583] - GenericResultAtLocation [Line: 691]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [691] - GenericResultAtLocation [Line: 700]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [700] - GenericResultAtLocation [Line: 958]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [958] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 696]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 107 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 14.9s, OverallIterations: 13, TraceHistogramMax: 3, PathProgramHistogramMax: 2, EmptinessCheckTime: 0.1s, AutomataDifference: 5.1s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 3.9s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1854 SdHoareTripleChecker+Valid, 2.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1826 mSDsluCounter, 4555 SdHoareTripleChecker+Invalid, 2.3s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3219 mSDsCounter, 441 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 2625 IncrementalHoareTripleChecker+Invalid, 3066 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 441 mSolverCounterUnsat, 1336 mSDtfsCounter, 2625 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 757 GetRequests, 626 SyntacticMatches, 13 SemanticMatches, 118 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 322 ImplicationChecksByTransitivity, 1.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1703occurred in iteration=12, InterpolantAutomatonStates: 114, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 1.1s AutomataMinimizationTime, 13 MinimizatonAttempts, 422 StatesRemovedByMinimization, 9 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 50 LocationsWithAnnotation, 3415 PreInvPairs, 3678 NumberOfFragments, 1097 HoareAnnotationTreeSize, 3415 FomulaSimplifications, 10122 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 50 FomulaSimplificationsInter, 8719 FormulaSimplificationTreeSizeReductionInter, 3.2s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 2.9s InterpolantComputationTime, 1163 NumberOfCodeBlocks, 1163 NumberOfCodeBlocksAsserted, 17 NumberOfCheckSat, 1247 ConstructedInterpolants, 0 QuantifiedInterpolants, 2145 SizeOfPredicates, 11 NumberOfNonLiveVariables, 1252 ConjunctsInSsa, 23 ConjunctsInUnsatCore, 17 InterpolantComputations, 12 PerfectInterpolantSequences, 434/492 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 475]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (tmp == 1)) && (waterLevel == 1)) - InvariantResult [Line: 816]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (2 <= waterLevel)) || (0 == systemActive)) - InvariantResult [Line: 558]: Loop Invariant Derived loop invariant: ((((((!((\old(pumpRunning) == 0)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || (\old(waterLevel) < 2)) || (0 == systemActive)) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || ((tmp == 1) && (\result == 1)))) && ((((\old(waterLevel) < 2) || ((((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result)) && (1 <= tmp))) || (((2 <= waterLevel) && (2 <= \result)) && (2 <= tmp))) || (0 == systemActive))) && (((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && (2 <= \result)) && (2 <= tmp)) && !((0 == systemActive)))) || ((((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel)) && (1 <= tmp)))) - InvariantResult [Line: 531]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 418]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 682]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || ((pumpRunning == \old(pumpRunning)) && (\result == 0))) || (0 == systemActive))) - InvariantResult [Line: 428]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 860]: Loop Invariant Derived loop invariant: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) - InvariantResult [Line: 791]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 1)) || (((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) || (((2 <= waterLevel) && (\old(waterLevel) == waterLevel)) && !((0 == systemActive)))) && ((((2 <= waterLevel) || (\old(waterLevel) < 2)) || (0 == systemActive)) || ((pumpRunning == 0) && (1 <= waterLevel)))) - InvariantResult [Line: 668]: Loop Invariant Derived loop invariant: ((((!((\old(pumpRunning) == 0)) || (waterLevel < 2)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) && ((((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) || (((((pumpRunning == 0) && (2 <= waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)) && !((0 == systemActive)))) || ((1 <= \result) && (pumpRunning == 0)))) - InvariantResult [Line: 905]: Loop Invariant Derived loop invariant: ((((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || ((((1 <= \result) && (1 <= tmp)) && (tmp___0 == 0)) && (\result == 0))) || (0 == systemActive)) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (waterLevel < 1)) || (0 == systemActive))) - InvariantResult [Line: 483]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 591]: Loop Invariant Derived loop invariant: (((((\old(waterLevel) < 2) || ((pumpRunning == \old(pumpRunning)) && (1 <= waterLevel))) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) - InvariantResult [Line: 627]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 943]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (splverifierCounter == 0)) && (waterLevel == 1)) || (((pumpRunning == 0) && (2 <= waterLevel)) && (splverifierCounter == 0))) - InvariantResult [Line: 959]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 824]: Loop Invariant Derived loop invariant: ((!((waterLevel == 1)) || !((\old(pumpRunning) == 0))) || (0 == systemActive)) - InvariantResult [Line: 692]: Loop Invariant Derived loop invariant: ((((\old(waterLevel) < 2) || (0 == systemActive)) && (!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2))) && (!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1)))) - InvariantResult [Line: 659]: Loop Invariant Derived loop invariant: ((((((!((\old(pumpRunning) == 0)) || (\old(waterLevel) < 2)) || (0 == systemActive)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive)))) && (((((2 <= waterLevel) && (2 <= \result)) || (\old(waterLevel) < 2)) || (((pumpRunning == 0) && (1 <= waterLevel)) && (1 <= \result))) || (0 == systemActive))) && ((!((\old(pumpRunning) == 0)) || !((\old(waterLevel) == 1))) || (((pumpRunning == 0) && (waterLevel == 1)) && (\result == 1)))) && (((!((\old(pumpRunning) == 0)) || (((pumpRunning == 0) && (1 <= \result)) && (\old(waterLevel) == waterLevel))) || (\old(waterLevel) < 2)) || (((\old(waterLevel) == waterLevel) && (2 <= \result)) && !((0 == systemActive))))) - InvariantResult [Line: 545]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (\result == 1)) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 969]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (splverifierCounter == 0)) && (waterLevel == 1)) || (((2 <= waterLevel) && (splverifierCounter == 0)) && !((0 == systemActive)))) || (((pumpRunning == 0) && (2 <= waterLevel)) && (splverifierCounter == 0))) - InvariantResult [Line: 538]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel == 1)) - InvariantResult [Line: 924]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (waterLevel < 1)) || (0 == systemActive)) && (((waterLevel < 1) || (((((pumpRunning == \old(pumpRunning)) && (1 <= tmp___0)) && (1 <= \result)) && (\result == 0)) && (tmp == 0))) || (0 == systemActive))) - InvariantResult [Line: 496]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 968]: Loop Invariant Derived loop invariant: 0 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:32:41,234 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8f87d10c-f087-4516-b43f-2d393749c679/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE