./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version e7bb482b Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP --witnessprinter.witness.filename witness.graphml --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 31801b0d0a8db366707af3e7371b9dc02f7c34625c63f4c3f856015d4449b4b2 --- Real Ultimate output --- This is Ultimate 0.2.3-dev-e7bb482 [2023-11-06 22:53:30,657 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-06 22:53:30,727 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-06 22:53:30,734 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-06 22:53:30,734 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-06 22:53:30,760 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-06 22:53:30,761 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-06 22:53:30,761 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-06 22:53:30,762 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-06 22:53:30,763 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-06 22:53:30,764 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-06 22:53:30,764 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-06 22:53:30,765 INFO L153 SettingsManager]: * Use SBE=true [2023-11-06 22:53:30,765 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-06 22:53:30,766 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-06 22:53:30,767 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-06 22:53:30,767 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-06 22:53:30,768 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-06 22:53:30,768 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-06 22:53:30,769 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-06 22:53:30,769 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-06 22:53:30,770 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-06 22:53:30,771 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-06 22:53:30,771 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-06 22:53:30,772 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-06 22:53:30,772 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-06 22:53:30,773 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-06 22:53:30,773 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-06 22:53:30,774 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:53:30,774 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-06 22:53:30,775 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-06 22:53:30,775 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopsAndPotentialCycles [2023-11-06 22:53:30,776 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-06 22:53:30,776 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-06 22:53:30,776 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-06 22:53:30,777 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-06 22:53:30,777 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-06 22:53:30,778 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-06 22:53:30,778 INFO L153 SettingsManager]: * Independence relation used for large block encoding in concurrent analysis=SYNTACTIC [2023-11-06 22:53:30,778 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness.graphml Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 31801b0d0a8db366707af3e7371b9dc02f7c34625c63f4c3f856015d4449b4b2 [2023-11-06 22:53:31,114 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-06 22:53:31,144 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-06 22:53:31,147 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-06 22:53:31,149 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-06 22:53:31,149 INFO L274 PluginConnector]: CDTParser initialized [2023-11-06 22:53:31,151 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/../../sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c [2023-11-06 22:53:34,346 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-06 22:53:34,608 INFO L384 CDTParser]: Found 1 translation units. [2023-11-06 22:53:34,609 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c [2023-11-06 22:53:34,631 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/data/b01c20086/7ef22f81f73540e782a2b220bd53c9c9/FLAG45bf242f9 [2023-11-06 22:53:34,649 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/data/b01c20086/7ef22f81f73540e782a2b220bd53c9c9 [2023-11-06 22:53:34,657 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-06 22:53:34,660 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-06 22:53:34,664 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-06 22:53:34,665 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-06 22:53:34,671 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-06 22:53:34,674 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:53:34" (1/1) ... [2023-11-06 22:53:34,675 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@1271af42 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:34, skipping insertion in model container [2023-11-06 22:53:34,676 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 06.11 10:53:34" (1/1) ... [2023-11-06 22:53:34,754 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-06 22:53:35,165 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c[17098,17111] [2023-11-06 22:53:35,183 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:53:35,198 INFO L202 MainTranslator]: Completed pre-run [2023-11-06 22:53:35,211 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [49] [2023-11-06 22:53:35,213 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [266] [2023-11-06 22:53:35,214 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [338] [2023-11-06 22:53:35,214 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [704] [2023-11-06 22:53:35,214 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [755] [2023-11-06 22:53:35,214 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [855] [2023-11-06 22:53:35,215 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [864] [2023-11-06 22:53:35,215 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [899] [2023-11-06 22:53:35,291 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/sv-benchmarks/c/product-lines/minepump_spec5_product40.cil.c[17098,17111] [2023-11-06 22:53:35,296 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-06 22:53:35,316 INFO L206 MainTranslator]: Completed translation [2023-11-06 22:53:35,317 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35 WrapperNode [2023-11-06 22:53:35,317 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-06 22:53:35,318 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-06 22:53:35,319 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-06 22:53:35,319 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-06 22:53:35,327 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,343 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,374 INFO L138 Inliner]: procedures = 57, calls = 103, calls flagged for inlining = 25, calls inlined = 22, statements flattened = 209 [2023-11-06 22:53:35,374 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-06 22:53:35,375 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-06 22:53:35,376 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-06 22:53:35,376 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-06 22:53:35,386 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,386 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,399 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,407 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,412 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,428 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,430 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,431 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,434 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-06 22:53:35,447 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-06 22:53:35,447 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-06 22:53:35,447 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-06 22:53:35,448 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (1/1) ... [2023-11-06 22:53:35,455 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-06 22:53:35,468 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:53:35,484 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-06 22:53:35,514 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-06 22:53:35,533 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-06 22:53:35,533 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-06 22:53:35,534 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-06 22:53:35,534 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-06 22:53:35,536 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-06 22:53:35,536 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-06 22:53:35,537 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-06 22:53:35,537 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:53:35,537 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:53:35,537 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-06 22:53:35,537 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-06 22:53:35,538 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2023-11-06 22:53:35,538 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2023-11-06 22:53:35,538 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-06 22:53:35,538 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-06 22:53:35,539 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2023-11-06 22:53:35,540 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-06 22:53:35,540 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-06 22:53:35,540 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-06 22:53:35,541 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-06 22:53:35,665 INFO L236 CfgBuilder]: Building ICFG [2023-11-06 22:53:35,668 INFO L262 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-06 22:53:35,987 INFO L277 CfgBuilder]: Performing block encoding [2023-11-06 22:53:35,995 INFO L297 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-06 22:53:35,995 INFO L302 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-06 22:53:35,998 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:53:35 BoogieIcfgContainer [2023-11-06 22:53:35,998 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-06 22:53:36,000 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-06 22:53:36,001 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-06 22:53:36,004 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-06 22:53:36,004 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 06.11 10:53:34" (1/3) ... [2023-11-06 22:53:36,005 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@282bed14 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:53:36, skipping insertion in model container [2023-11-06 22:53:36,005 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 06.11 10:53:35" (2/3) ... [2023-11-06 22:53:36,006 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@282bed14 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 06.11 10:53:36, skipping insertion in model container [2023-11-06 22:53:36,006 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:53:35" (3/3) ... [2023-11-06 22:53:36,007 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product40.cil.c [2023-11-06 22:53:36,027 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-06 22:53:36,027 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-06 22:53:36,083 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-06 22:53:36,089 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopsAndPotentialCycles, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4ae24f7f, mLbeIndependenceSettings=[IndependenceType=SYNTACTIC, AbstractionType=NONE, UseConditional=, UseSemiCommutativity=, Solver=, SolverTimeout=] [2023-11-06 22:53:36,090 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-06 22:53:36,094 INFO L276 IsEmpty]: Start isEmpty. Operand has 98 states, 74 states have (on average 1.364864864864865) internal successors, (101), 83 states have internal predecessors, (101), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) [2023-11-06 22:53:36,106 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2023-11-06 22:53:36,106 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:36,107 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:36,107 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:36,113 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:36,113 INFO L85 PathProgramCache]: Analyzing trace with hash 694872208, now seen corresponding path program 1 times [2023-11-06 22:53:36,123 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:36,123 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1626777425] [2023-11-06 22:53:36,123 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:36,124 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:36,243 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,355 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2023-11-06 22:53:36,368 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,380 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 24 [2023-11-06 22:53:36,387 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,398 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:36,400 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:36,401 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1626777425] [2023-11-06 22:53:36,402 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1626777425] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:36,402 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:36,402 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-06 22:53:36,404 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [981725336] [2023-11-06 22:53:36,405 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:36,410 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-06 22:53:36,410 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:36,454 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-06 22:53:36,456 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:53:36,459 INFO L87 Difference]: Start difference. First operand has 98 states, 74 states have (on average 1.364864864864865) internal successors, (101), 83 states have internal predecessors, (101), 14 states have call successors, (14), 8 states have call predecessors, (14), 8 states have return successors, (14), 11 states have call predecessors, (14), 14 states have call successors, (14) Second operand has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:53:36,525 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:36,525 INFO L93 Difference]: Finished difference Result 187 states and 252 transitions. [2023-11-06 22:53:36,526 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-06 22:53:36,528 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 32 [2023-11-06 22:53:36,529 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:36,540 INFO L225 Difference]: With dead ends: 187 [2023-11-06 22:53:36,540 INFO L226 Difference]: Without dead ends: 89 [2023-11-06 22:53:36,546 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-06 22:53:36,550 INFO L413 NwaCegarLoop]: 123 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 0 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 123 SdHoareTripleChecker+Invalid, 0 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 0 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:36,552 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 123 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 0 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:53:36,571 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 89 states. [2023-11-06 22:53:36,606 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 89 to 89. [2023-11-06 22:53:36,608 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 89 states, 67 states have (on average 1.2985074626865671) internal successors, (87), 75 states have internal predecessors, (87), 14 states have call successors, (14), 8 states have call predecessors, (14), 7 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-06 22:53:36,617 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 89 states to 89 states and 114 transitions. [2023-11-06 22:53:36,620 INFO L78 Accepts]: Start accepts. Automaton has 89 states and 114 transitions. Word has length 32 [2023-11-06 22:53:36,620 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:36,621 INFO L495 AbstractCegarLoop]: Abstraction has 89 states and 114 transitions. [2023-11-06 22:53:36,621 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 12.0) internal successors, (24), 2 states have internal predecessors, (24), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:53:36,622 INFO L276 IsEmpty]: Start isEmpty. Operand 89 states and 114 transitions. [2023-11-06 22:53:36,630 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 34 [2023-11-06 22:53:36,631 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:36,631 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:36,631 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-06 22:53:36,632 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:36,633 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:36,633 INFO L85 PathProgramCache]: Analyzing trace with hash -778098819, now seen corresponding path program 1 times [2023-11-06 22:53:36,634 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:36,634 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1815487595] [2023-11-06 22:53:36,635 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:36,635 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:36,674 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,802 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-06 22:53:36,803 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,806 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2023-11-06 22:53:36,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:36,810 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:36,810 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:36,811 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1815487595] [2023-11-06 22:53:36,811 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1815487595] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:36,811 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:36,811 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-06 22:53:36,812 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1136290966] [2023-11-06 22:53:36,812 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:36,813 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-06 22:53:36,813 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:36,814 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-06 22:53:36,815 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:53:36,815 INFO L87 Difference]: Start difference. First operand 89 states and 114 transitions. Second operand has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:53:36,833 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:36,833 INFO L93 Difference]: Finished difference Result 138 states and 176 transitions. [2023-11-06 22:53:36,833 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-06 22:53:36,834 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 33 [2023-11-06 22:53:36,834 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:36,835 INFO L225 Difference]: With dead ends: 138 [2023-11-06 22:53:36,836 INFO L226 Difference]: Without dead ends: 80 [2023-11-06 22:53:36,837 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-06 22:53:36,839 INFO L413 NwaCegarLoop]: 101 mSDtfsCounter, 17 mSDsluCounter, 79 mSDsCounter, 0 mSdLazyCounter, 1 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 21 SdHoareTripleChecker+Valid, 180 SdHoareTripleChecker+Invalid, 1 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 1 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:36,839 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [21 Valid, 180 Invalid, 1 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 1 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-06 22:53:36,841 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 80 states. [2023-11-06 22:53:36,849 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 80 to 80. [2023-11-06 22:53:36,850 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 80 states, 61 states have (on average 1.3114754098360655) internal successors, (80), 69 states have internal predecessors, (80), 11 states have call successors, (11), 7 states have call predecessors, (11), 7 states have return successors, (11), 8 states have call predecessors, (11), 11 states have call successors, (11) [2023-11-06 22:53:36,851 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 80 states to 80 states and 102 transitions. [2023-11-06 22:53:36,851 INFO L78 Accepts]: Start accepts. Automaton has 80 states and 102 transitions. Word has length 33 [2023-11-06 22:53:36,852 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:36,852 INFO L495 AbstractCegarLoop]: Abstraction has 80 states and 102 transitions. [2023-11-06 22:53:36,852 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.333333333333334) internal successors, (25), 3 states have internal predecessors, (25), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-06 22:53:36,852 INFO L276 IsEmpty]: Start isEmpty. Operand 80 states and 102 transitions. [2023-11-06 22:53:36,854 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 39 [2023-11-06 22:53:36,854 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:36,854 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:36,854 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-06 22:53:36,855 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:36,855 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:36,855 INFO L85 PathProgramCache]: Analyzing trace with hash 1811500472, now seen corresponding path program 1 times [2023-11-06 22:53:36,856 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:36,856 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1087950776] [2023-11-06 22:53:36,856 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:36,856 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:36,878 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,066 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:53:37,069 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,072 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-06 22:53:37,074 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,076 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:37,077 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:37,077 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1087950776] [2023-11-06 22:53:37,077 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1087950776] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:37,078 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:37,078 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:53:37,078 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [900096352] [2023-11-06 22:53:37,078 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:37,079 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:53:37,079 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:37,080 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:53:37,080 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:53:37,081 INFO L87 Difference]: Start difference. First operand 80 states and 102 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:53:37,233 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:37,233 INFO L93 Difference]: Finished difference Result 199 states and 258 transitions. [2023-11-06 22:53:37,234 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2023-11-06 22:53:37,234 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 38 [2023-11-06 22:53:37,235 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:37,237 INFO L225 Difference]: With dead ends: 199 [2023-11-06 22:53:37,237 INFO L226 Difference]: Without dead ends: 127 [2023-11-06 22:53:37,239 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 9 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2023-11-06 22:53:37,240 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 163 mSDsluCounter, 233 mSDsCounter, 0 mSdLazyCounter, 12 mSolverCounterSat, 19 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 163 SdHoareTripleChecker+Valid, 343 SdHoareTripleChecker+Invalid, 31 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 19 IncrementalHoareTripleChecker+Valid, 12 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:37,241 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [163 Valid, 343 Invalid, 31 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [19 Valid, 12 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:53:37,243 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 127 states. [2023-11-06 22:53:37,270 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 127 to 124. [2023-11-06 22:53:37,272 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 124 states, 94 states have (on average 1.3297872340425532) internal successors, (125), 105 states have internal predecessors, (125), 17 states have call successors, (17), 12 states have call predecessors, (17), 12 states have return successors, (18), 13 states have call predecessors, (18), 17 states have call successors, (18) [2023-11-06 22:53:37,274 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 124 states to 124 states and 160 transitions. [2023-11-06 22:53:37,275 INFO L78 Accepts]: Start accepts. Automaton has 124 states and 160 transitions. Word has length 38 [2023-11-06 22:53:37,276 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:37,276 INFO L495 AbstractCegarLoop]: Abstraction has 124 states and 160 transitions. [2023-11-06 22:53:37,276 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 5 states have internal predecessors, (31), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:53:37,276 INFO L276 IsEmpty]: Start isEmpty. Operand 124 states and 160 transitions. [2023-11-06 22:53:37,278 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 42 [2023-11-06 22:53:37,278 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:37,278 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:37,278 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-06 22:53:37,286 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:37,287 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:37,287 INFO L85 PathProgramCache]: Analyzing trace with hash -1858694344, now seen corresponding path program 1 times [2023-11-06 22:53:37,287 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:37,288 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1926374177] [2023-11-06 22:53:37,288 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:37,288 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:37,316 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,408 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2023-11-06 22:53:37,410 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,412 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2023-11-06 22:53:37,414 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,428 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 2 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2023-11-06 22:53:37,428 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:37,428 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1926374177] [2023-11-06 22:53:37,429 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1926374177] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:37,429 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:37,429 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:53:37,429 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1509121991] [2023-11-06 22:53:37,430 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:37,430 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:53:37,431 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:37,431 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:53:37,432 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:53:37,432 INFO L87 Difference]: Start difference. First operand 124 states and 160 transitions. Second operand has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 1 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:53:37,660 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:37,660 INFO L93 Difference]: Finished difference Result 282 states and 373 transitions. [2023-11-06 22:53:37,660 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-06 22:53:37,661 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 1 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 41 [2023-11-06 22:53:37,661 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:37,663 INFO L225 Difference]: With dead ends: 282 [2023-11-06 22:53:37,664 INFO L226 Difference]: Without dead ends: 166 [2023-11-06 22:53:37,666 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2023-11-06 22:53:37,667 INFO L413 NwaCegarLoop]: 104 mSDtfsCounter, 72 mSDsluCounter, 337 mSDsCounter, 0 mSdLazyCounter, 70 mSolverCounterSat, 10 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 74 SdHoareTripleChecker+Valid, 441 SdHoareTripleChecker+Invalid, 80 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 10 IncrementalHoareTripleChecker+Valid, 70 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:37,668 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [74 Valid, 441 Invalid, 80 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [10 Valid, 70 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:53:37,669 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 166 states. [2023-11-06 22:53:37,697 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 166 to 162. [2023-11-06 22:53:37,698 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 162 states, 123 states have (on average 1.2682926829268293) internal successors, (156), 133 states have internal predecessors, (156), 21 states have call successors, (21), 17 states have call predecessors, (21), 17 states have return successors, (27), 20 states have call predecessors, (27), 21 states have call successors, (27) [2023-11-06 22:53:37,699 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 162 states to 162 states and 204 transitions. [2023-11-06 22:53:37,699 INFO L78 Accepts]: Start accepts. Automaton has 162 states and 204 transitions. Word has length 41 [2023-11-06 22:53:37,699 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:37,700 INFO L495 AbstractCegarLoop]: Abstraction has 162 states and 204 transitions. [2023-11-06 22:53:37,700 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 6.0) internal successors, (36), 5 states have internal predecessors, (36), 2 states have call successors, (3), 1 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-06 22:53:37,700 INFO L276 IsEmpty]: Start isEmpty. Operand 162 states and 204 transitions. [2023-11-06 22:53:37,702 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-06 22:53:37,702 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:37,702 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:37,703 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-06 22:53:37,703 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:37,703 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:37,703 INFO L85 PathProgramCache]: Analyzing trace with hash -873577577, now seen corresponding path program 1 times [2023-11-06 22:53:37,704 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:37,704 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [316875863] [2023-11-06 22:53:37,704 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:37,704 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:37,722 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,754 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2023-11-06 22:53:37,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,762 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 31 [2023-11-06 22:53:37,766 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,770 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 47 [2023-11-06 22:53:37,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:37,774 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:37,774 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:37,774 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [316875863] [2023-11-06 22:53:37,775 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [316875863] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:37,775 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:37,775 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-06 22:53:37,775 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2022999606] [2023-11-06 22:53:37,776 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:37,776 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2023-11-06 22:53:37,776 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:37,777 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2023-11-06 22:53:37,777 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2023-11-06 22:53:37,777 INFO L87 Difference]: Start difference. First operand 162 states and 204 transitions. Second operand has 4 states, 4 states have (on average 11.5) internal successors, (46), 3 states have internal predecessors, (46), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:37,920 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:37,920 INFO L93 Difference]: Finished difference Result 343 states and 432 transitions. [2023-11-06 22:53:37,921 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:53:37,921 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 11.5) internal successors, (46), 3 states have internal predecessors, (46), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 55 [2023-11-06 22:53:37,921 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:37,924 INFO L225 Difference]: With dead ends: 343 [2023-11-06 22:53:37,924 INFO L226 Difference]: Without dead ends: 189 [2023-11-06 22:53:37,925 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:53:37,926 INFO L413 NwaCegarLoop]: 114 mSDtfsCounter, 90 mSDsluCounter, 144 mSDsCounter, 0 mSdLazyCounter, 75 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 97 SdHoareTripleChecker+Valid, 258 SdHoareTripleChecker+Invalid, 93 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 75 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:37,927 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [97 Valid, 258 Invalid, 93 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 75 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:53:37,928 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 189 states. [2023-11-06 22:53:37,954 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 189 to 185. [2023-11-06 22:53:37,955 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 185 states, 141 states have (on average 1.2553191489361701) internal successors, (177), 151 states have internal predecessors, (177), 23 states have call successors, (23), 17 states have call predecessors, (23), 20 states have return successors, (30), 24 states have call predecessors, (30), 23 states have call successors, (30) [2023-11-06 22:53:37,956 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 185 states to 185 states and 230 transitions. [2023-11-06 22:53:37,957 INFO L78 Accepts]: Start accepts. Automaton has 185 states and 230 transitions. Word has length 55 [2023-11-06 22:53:37,957 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:37,957 INFO L495 AbstractCegarLoop]: Abstraction has 185 states and 230 transitions. [2023-11-06 22:53:37,958 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 11.5) internal successors, (46), 3 states have internal predecessors, (46), 2 states have call successors, (4), 3 states have call predecessors, (4), 1 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:37,958 INFO L276 IsEmpty]: Start isEmpty. Operand 185 states and 230 transitions. [2023-11-06 22:53:37,959 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2023-11-06 22:53:37,959 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:37,959 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:37,959 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-06 22:53:37,960 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:37,960 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:37,960 INFO L85 PathProgramCache]: Analyzing trace with hash 68722199, now seen corresponding path program 1 times [2023-11-06 22:53:37,960 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:37,961 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [574602852] [2023-11-06 22:53:37,961 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:37,961 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:37,977 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,072 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:53:38,075 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,089 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2023-11-06 22:53:38,096 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,149 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2023-11-06 22:53:38,152 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,159 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:38,159 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:38,159 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [574602852] [2023-11-06 22:53:38,159 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [574602852] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:38,159 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:38,160 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:53:38,160 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1514950269] [2023-11-06 22:53:38,160 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:38,160 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:53:38,161 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:38,162 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:53:38,163 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:53:38,163 INFO L87 Difference]: Start difference. First operand 185 states and 230 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:38,452 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:38,452 INFO L93 Difference]: Finished difference Result 514 states and 667 transitions. [2023-11-06 22:53:38,453 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 10 states. [2023-11-06 22:53:38,453 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2023-11-06 22:53:38,453 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:38,457 INFO L225 Difference]: With dead ends: 514 [2023-11-06 22:53:38,457 INFO L226 Difference]: Without dead ends: 337 [2023-11-06 22:53:38,458 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 10 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=35, Invalid=75, Unknown=0, NotChecked=0, Total=110 [2023-11-06 22:53:38,459 INFO L413 NwaCegarLoop]: 98 mSDtfsCounter, 159 mSDsluCounter, 289 mSDsCounter, 0 mSdLazyCounter, 146 mSolverCounterSat, 39 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 165 SdHoareTripleChecker+Valid, 387 SdHoareTripleChecker+Invalid, 185 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 39 IncrementalHoareTripleChecker+Valid, 146 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:38,460 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [165 Valid, 387 Invalid, 185 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [39 Valid, 146 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-06 22:53:38,461 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 337 states. [2023-11-06 22:53:38,504 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 337 to 320. [2023-11-06 22:53:38,505 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 320 states, 245 states have (on average 1.2448979591836735) internal successors, (305), 259 states have internal predecessors, (305), 41 states have call successors, (41), 32 states have call predecessors, (41), 33 states have return successors, (55), 40 states have call predecessors, (55), 41 states have call successors, (55) [2023-11-06 22:53:38,508 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 320 states to 320 states and 401 transitions. [2023-11-06 22:53:38,509 INFO L78 Accepts]: Start accepts. Automaton has 320 states and 401 transitions. Word has length 52 [2023-11-06 22:53:38,509 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:38,509 INFO L495 AbstractCegarLoop]: Abstraction has 320 states and 401 transitions. [2023-11-06 22:53:38,509 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:38,510 INFO L276 IsEmpty]: Start isEmpty. Operand 320 states and 401 transitions. [2023-11-06 22:53:38,511 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2023-11-06 22:53:38,511 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:38,511 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:38,512 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-06 22:53:38,512 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:38,512 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:38,512 INFO L85 PathProgramCache]: Analyzing trace with hash -353979627, now seen corresponding path program 1 times [2023-11-06 22:53:38,513 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:38,513 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1746441925] [2023-11-06 22:53:38,513 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:38,513 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:38,527 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,575 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:53:38,590 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,604 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2023-11-06 22:53:38,607 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,636 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2023-11-06 22:53:38,637 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,640 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:38,640 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:38,640 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1746441925] [2023-11-06 22:53:38,640 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1746441925] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:38,641 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:38,641 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-06 22:53:38,641 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2021471186] [2023-11-06 22:53:38,641 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:38,643 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-06 22:53:38,643 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:38,644 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-06 22:53:38,644 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-06 22:53:38,644 INFO L87 Difference]: Start difference. First operand 320 states and 401 transitions. Second operand has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:38,871 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:38,871 INFO L93 Difference]: Finished difference Result 646 states and 820 transitions. [2023-11-06 22:53:38,872 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-06 22:53:38,872 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2023-11-06 22:53:38,872 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:38,875 INFO L225 Difference]: With dead ends: 646 [2023-11-06 22:53:38,875 INFO L226 Difference]: Without dead ends: 334 [2023-11-06 22:53:38,877 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 8 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 5 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=29, Invalid=61, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:53:38,878 INFO L413 NwaCegarLoop]: 88 mSDtfsCounter, 62 mSDsluCounter, 292 mSDsCounter, 0 mSdLazyCounter, 125 mSolverCounterSat, 21 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 65 SdHoareTripleChecker+Valid, 380 SdHoareTripleChecker+Invalid, 146 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 21 IncrementalHoareTripleChecker+Valid, 125 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:38,878 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [65 Valid, 380 Invalid, 146 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [21 Valid, 125 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:53:38,879 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 334 states. [2023-11-06 22:53:38,916 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 334 to 326. [2023-11-06 22:53:38,917 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 326 states, 251 states have (on average 1.2390438247011952) internal successors, (311), 265 states have internal predecessors, (311), 41 states have call successors, (41), 32 states have call predecessors, (41), 33 states have return successors, (55), 40 states have call predecessors, (55), 41 states have call successors, (55) [2023-11-06 22:53:38,920 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 326 states to 326 states and 407 transitions. [2023-11-06 22:53:38,920 INFO L78 Accepts]: Start accepts. Automaton has 326 states and 407 transitions. Word has length 52 [2023-11-06 22:53:38,921 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:38,921 INFO L495 AbstractCegarLoop]: Abstraction has 326 states and 407 transitions. [2023-11-06 22:53:38,921 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 7.166666666666667) internal successors, (43), 5 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:38,921 INFO L276 IsEmpty]: Start isEmpty. Operand 326 states and 407 transitions. [2023-11-06 22:53:38,923 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2023-11-06 22:53:38,923 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:38,923 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:38,923 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-06 22:53:38,923 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:38,924 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:38,924 INFO L85 PathProgramCache]: Analyzing trace with hash -2042923369, now seen corresponding path program 1 times [2023-11-06 22:53:38,924 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:38,924 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [381632890] [2023-11-06 22:53:38,924 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:38,925 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:38,938 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,979 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-06 22:53:38,980 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:38,983 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2023-11-06 22:53:38,986 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,020 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2023-11-06 22:53:39,022 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,023 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:39,024 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:39,024 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [381632890] [2023-11-06 22:53:39,024 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [381632890] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:39,024 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:39,024 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-06 22:53:39,024 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2102135771] [2023-11-06 22:53:39,025 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:39,025 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-06 22:53:39,025 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:39,026 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-06 22:53:39,026 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-06 22:53:39,026 INFO L87 Difference]: Start difference. First operand 326 states and 407 transitions. Second operand has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:39,191 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:39,191 INFO L93 Difference]: Finished difference Result 601 states and 757 transitions. [2023-11-06 22:53:39,191 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2023-11-06 22:53:39,192 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 52 [2023-11-06 22:53:39,192 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:39,196 INFO L225 Difference]: With dead ends: 601 [2023-11-06 22:53:39,196 INFO L226 Difference]: Without dead ends: 283 [2023-11-06 22:53:39,197 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 13 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=17, Invalid=25, Unknown=0, NotChecked=0, Total=42 [2023-11-06 22:53:39,201 INFO L413 NwaCegarLoop]: 86 mSDtfsCounter, 63 mSDsluCounter, 203 mSDsCounter, 0 mSdLazyCounter, 91 mSolverCounterSat, 17 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 289 SdHoareTripleChecker+Invalid, 108 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 17 IncrementalHoareTripleChecker+Valid, 91 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:39,205 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 289 Invalid, 108 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [17 Valid, 91 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-06 22:53:39,207 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 283 states. [2023-11-06 22:53:39,235 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 283 to 278. [2023-11-06 22:53:39,236 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 278 states, 214 states have (on average 1.219626168224299) internal successors, (261), 226 states have internal predecessors, (261), 35 states have call successors, (35), 27 states have call predecessors, (35), 28 states have return successors, (42), 34 states have call predecessors, (42), 35 states have call successors, (42) [2023-11-06 22:53:39,238 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 278 states to 278 states and 338 transitions. [2023-11-06 22:53:39,239 INFO L78 Accepts]: Start accepts. Automaton has 278 states and 338 transitions. Word has length 52 [2023-11-06 22:53:39,239 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:39,239 INFO L495 AbstractCegarLoop]: Abstraction has 278 states and 338 transitions. [2023-11-06 22:53:39,239 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.6) internal successors, (43), 4 states have internal predecessors, (43), 2 states have call successors, (4), 2 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-06 22:53:39,240 INFO L276 IsEmpty]: Start isEmpty. Operand 278 states and 338 transitions. [2023-11-06 22:53:39,241 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 57 [2023-11-06 22:53:39,241 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:39,245 INFO L195 NwaCegarLoop]: trace histogram [2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:39,245 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2023-11-06 22:53:39,246 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:39,246 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:39,246 INFO L85 PathProgramCache]: Analyzing trace with hash -1510613325, now seen corresponding path program 1 times [2023-11-06 22:53:39,247 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:39,247 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [93744248] [2023-11-06 22:53:39,247 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:39,247 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:39,266 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,480 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:53:39,481 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,487 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-06 22:53:39,488 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,499 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 32 [2023-11-06 22:53:39,502 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,528 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2023-11-06 22:53:39,529 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:39,531 INFO L134 CoverageAnalysis]: Checked inductivity of 3 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 3 trivial. 0 not checked. [2023-11-06 22:53:39,531 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:39,532 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [93744248] [2023-11-06 22:53:39,532 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [93744248] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-06 22:53:39,532 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-06 22:53:39,532 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2023-11-06 22:53:39,532 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [555023469] [2023-11-06 22:53:39,532 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-06 22:53:39,534 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2023-11-06 22:53:39,534 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:39,534 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2023-11-06 22:53:39,535 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=20, Invalid=70, Unknown=0, NotChecked=0, Total=90 [2023-11-06 22:53:39,535 INFO L87 Difference]: Start difference. First operand 278 states and 338 transitions. Second operand has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:53:40,471 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:40,471 INFO L93 Difference]: Finished difference Result 814 states and 1044 transitions. [2023-11-06 22:53:40,472 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 29 states. [2023-11-06 22:53:40,472 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 56 [2023-11-06 22:53:40,472 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:40,477 INFO L225 Difference]: With dead ends: 814 [2023-11-06 22:53:40,477 INFO L226 Difference]: Without dead ends: 632 [2023-11-06 22:53:40,479 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 43 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 32 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 282 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=258, Invalid=864, Unknown=0, NotChecked=0, Total=1122 [2023-11-06 22:53:40,480 INFO L413 NwaCegarLoop]: 109 mSDtfsCounter, 657 mSDsluCounter, 448 mSDsCounter, 0 mSdLazyCounter, 451 mSolverCounterSat, 213 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 665 SdHoareTripleChecker+Valid, 557 SdHoareTripleChecker+Invalid, 664 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 213 IncrementalHoareTripleChecker+Valid, 451 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:40,480 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [665 Valid, 557 Invalid, 664 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [213 Valid, 451 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2023-11-06 22:53:40,481 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 632 states. [2023-11-06 22:53:40,556 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 632 to 590. [2023-11-06 22:53:40,558 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 590 states, 450 states have (on average 1.2066666666666668) internal successors, (543), 480 states have internal predecessors, (543), 75 states have call successors, (75), 57 states have call predecessors, (75), 64 states have return successors, (108), 73 states have call predecessors, (108), 75 states have call successors, (108) [2023-11-06 22:53:40,562 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 590 states to 590 states and 726 transitions. [2023-11-06 22:53:40,562 INFO L78 Accepts]: Start accepts. Automaton has 590 states and 726 transitions. Word has length 56 [2023-11-06 22:53:40,563 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:40,563 INFO L495 AbstractCegarLoop]: Abstraction has 590 states and 726 transitions. [2023-11-06 22:53:40,563 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 4.5) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (5), 4 states have call predecessors, (5), 3 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-06 22:53:40,563 INFO L276 IsEmpty]: Start isEmpty. Operand 590 states and 726 transitions. [2023-11-06 22:53:40,565 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2023-11-06 22:53:40,565 INFO L187 NwaCegarLoop]: Found error trace [2023-11-06 22:53:40,565 INFO L195 NwaCegarLoop]: trace histogram [3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:40,566 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2023-11-06 22:53:40,566 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-06 22:53:40,566 INFO L145 PredicateUnifier]: Initialized classic predicate unifier [2023-11-06 22:53:40,566 INFO L85 PathProgramCache]: Analyzing trace with hash -1787594627, now seen corresponding path program 1 times [2023-11-06 22:53:40,567 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-06 22:53:40,567 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1719734394] [2023-11-06 22:53:40,567 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:40,567 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-06 22:53:40,586 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,774 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-06 22:53:40,775 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,790 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2023-11-06 22:53:40,795 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,818 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-06 22:53:40,819 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,829 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2023-11-06 22:53:40,832 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,840 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 62 [2023-11-06 22:53:40,841 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,856 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 76 [2023-11-06 22:53:40,858 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,860 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-06 22:53:40,861 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,862 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 88 [2023-11-06 22:53:40,863 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:40,866 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 18 proven. 9 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2023-11-06 22:53:40,866 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-06 22:53:40,866 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1719734394] [2023-11-06 22:53:40,866 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1719734394] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-06 22:53:40,867 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [547620682] [2023-11-06 22:53:40,867 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-06 22:53:40,867 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-06 22:53:40,867 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 [2023-11-06 22:53:40,873 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-06 22:53:40,890 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-06 22:53:41,001 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-06 22:53:41,004 INFO L262 TraceCheckSpWp]: Trace formula consists of 330 conjuncts, 8 conjunts are in the unsatisfiable core [2023-11-06 22:53:41,013 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-06 22:53:41,216 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 25 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-06 22:53:41,216 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-06 22:53:41,457 INFO L134 CoverageAnalysis]: Checked inductivity of 34 backedges. 19 proven. 8 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2023-11-06 22:53:41,460 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [547620682] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-06 22:53:41,460 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-06 22:53:41,460 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [12, 6, 6] total 16 [2023-11-06 22:53:41,461 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [666350560] [2023-11-06 22:53:41,462 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-06 22:53:41,462 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 16 states [2023-11-06 22:53:41,462 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-06 22:53:41,463 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 16 interpolants. [2023-11-06 22:53:41,464 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=38, Invalid=202, Unknown=0, NotChecked=0, Total=240 [2023-11-06 22:53:41,465 INFO L87 Difference]: Start difference. First operand 590 states and 726 transitions. Second operand has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2023-11-06 22:53:42,709 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-06 22:53:42,709 INFO L93 Difference]: Finished difference Result 1282 states and 1625 transitions. [2023-11-06 22:53:42,710 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 32 states. [2023-11-06 22:53:42,710 INFO L78 Accepts]: Start accepts. Automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) Word has length 96 [2023-11-06 22:53:42,711 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-06 22:53:42,711 INFO L225 Difference]: With dead ends: 1282 [2023-11-06 22:53:42,712 INFO L226 Difference]: Without dead ends: 0 [2023-11-06 22:53:42,716 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 256 GetRequests, 212 SyntacticMatches, 4 SemanticMatches, 40 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 407 ImplicationChecksByTransitivity, 0.5s TimeCoverageRelationStatistics Valid=301, Invalid=1421, Unknown=0, NotChecked=0, Total=1722 [2023-11-06 22:53:42,716 INFO L413 NwaCegarLoop]: 172 mSDtfsCounter, 447 mSDsluCounter, 1043 mSDsCounter, 0 mSdLazyCounter, 912 mSolverCounterSat, 148 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 448 SdHoareTripleChecker+Valid, 1215 SdHoareTripleChecker+Invalid, 1060 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 148 IncrementalHoareTripleChecker+Valid, 912 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.7s IncrementalHoareTripleChecker+Time [2023-11-06 22:53:42,717 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [448 Valid, 1215 Invalid, 1060 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [148 Valid, 912 Invalid, 0 Unknown, 0 Unchecked, 0.7s Time] [2023-11-06 22:53:42,717 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-06 22:53:42,718 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-06 22:53:42,718 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-06 22:53:42,718 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-06 22:53:42,718 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 96 [2023-11-06 22:53:42,719 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-06 22:53:42,719 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-06 22:53:42,719 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 16 states, 16 states have (on average 7.4375) internal successors, (119), 11 states have internal predecessors, (119), 5 states have call successors, (20), 7 states have call predecessors, (20), 6 states have return successors, (16), 7 states have call predecessors, (16), 5 states have call successors, (16) [2023-11-06 22:53:42,719 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-06 22:53:42,719 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-06 22:53:42,722 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-06 22:53:42,733 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-06 22:53:42,928 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2023-11-06 22:53:42,930 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-06 22:53:48,231 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 160 167) no Hoare annotation was computed. [2023-11-06 22:53:48,231 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 160 167) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse1 (< |old(~pumpRunning~0)| 1)) (.cse2 (= 0 ~systemActive~0))) (and (or (< 2 ~waterLevel~0) .cse0 (< ~switchedOnBeforeTS~0 1) .cse1 .cse2) (or .cse0 (not (= 2 ~waterLevel~0)) .cse1 .cse2))) [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point deactivatePumpFINAL(lines 160 167) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 93 99) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 93 99) the Hoare annotation is: true [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point L930-1(lines 926 937) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 926 937) the Hoare annotation is: true [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 926 937) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point L768(line 768) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 757 786) no Hoare annotation was computed. [2023-11-06 22:53:48,232 INFO L902 garLoopResultBuilder]: At program point L767-2(lines 767 781) the Hoare annotation is: true [2023-11-06 22:53:48,233 INFO L902 garLoopResultBuilder]: At program point L763(line 763) the Hoare annotation is: true [2023-11-06 22:53:48,233 INFO L899 garLoopResultBuilder]: For program point L763-1(line 763) no Hoare annotation was computed. [2023-11-06 22:53:48,233 INFO L902 garLoopResultBuilder]: At program point L782(lines 757 786) the Hoare annotation is: true [2023-11-06 22:53:48,233 INFO L899 garLoopResultBuilder]: For program point L778(line 778) no Hoare annotation was computed. [2023-11-06 22:53:48,233 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 757 786) the Hoare annotation is: true [2023-11-06 22:53:48,233 INFO L899 garLoopResultBuilder]: For program point L771(lines 771 775) no Hoare annotation was computed. [2023-11-06 22:53:48,233 INFO L902 garLoopResultBuilder]: At program point L771-1(lines 771 775) the Hoare annotation is: true [2023-11-06 22:53:48,233 INFO L895 garLoopResultBuilder]: At program point L721(line 721) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (< 2 |old(~waterLevel~0)|)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5) (or (and (= ~pumpRunning~0 0) .cse3 .cse4) (not (= |old(~pumpRunning~0)| 0)) .cse5) (or (and .cse2 (= 2 ~waterLevel~0) .cse3) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1))) [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L721-1(line 721) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L73(lines 73 79) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L73-2(lines 69 91) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L135(lines 135 143) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point timeShiftFINAL(lines 66 92) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L131(lines 131 148) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L738(lines 738 748) no Hoare annotation was computed. [2023-11-06 22:53:48,234 INFO L899 garLoopResultBuilder]: For program point L734(lines 734 751) no Hoare annotation was computed. [2023-11-06 22:53:48,235 INFO L895 garLoopResultBuilder]: At program point L734-1(lines 726 754) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| 2))) (let ((.cse5 (not .cse0)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= ~pumpRunning~0 0)) (.cse9 (< |old(~pumpRunning~0)| 1)) (.cse10 (= 0 ~systemActive~0)) (.cse4 (< 2 |old(~waterLevel~0)|)) (.cse6 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (<= ~waterLevel~0 2)) (.cse8 (<= 1 ~switchedOnBeforeTS~0))) (and (or (and (<= 1 ~pumpRunning~0) (= 2 ~waterLevel~0) .cse0) .cse1 (and .cse2 .cse3 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse4) (or .cse1 (and (= 2 |timeShift_getWaterLevel_#res#1|) (= |timeShift___utac_acc__Specification5_spec__3_~tmp~7#1| 2)) .cse5) (let ((.cse7 (= ~waterLevel~0 1))) (or (and .cse6 .cse7 .cse8) .cse5 .cse9 .cse10 (and .cse2 .cse7 .cse8))) (or .cse1 .cse2 .cse4 (not .cse10)) (or (< |old(~switchedOnBeforeTS~0)| 1) (and .cse2 .cse3 .cse8) .cse9 .cse10 .cse4 (and .cse6 .cse3 .cse8))))) [2023-11-06 22:53:48,235 INFO L895 garLoopResultBuilder]: At program point getWaterLevel_returnLabel#1(lines 970 978) the Hoare annotation is: (let ((.cse3 (= |old(~waterLevel~0)| 2))) (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse8 (not .cse3)) (.cse1 (= ~pumpRunning~0 0)) (.cse9 (< |old(~pumpRunning~0)| 1)) (.cse2 (= 0 ~systemActive~0)) (.cse4 (< 2 |old(~waterLevel~0)|)) (.cse5 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse7 (<= 1 ~switchedOnBeforeTS~0))) (and (or .cse0 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (and (<= 1 ~pumpRunning~0) (= 2 ~waterLevel~0) (not .cse2) .cse3) .cse4) (let ((.cse6 (= ~waterLevel~0 1))) (or (and .cse5 .cse6 .cse7) .cse8 .cse9 .cse2 (and .cse1 .cse6 .cse7))) (or .cse0 (= 2 |timeShift_getWaterLevel_#res#1|) .cse8) (let ((.cse10 (<= ~waterLevel~0 2))) (or (< |old(~switchedOnBeforeTS~0)| 1) (and .cse1 .cse10 .cse7) .cse9 .cse2 .cse4 (and .cse5 .cse10 .cse7)))))) [2023-11-06 22:53:48,235 INFO L899 garLoopResultBuilder]: For program point L739(lines 739 745) no Hoare annotation was computed. [2023-11-06 22:53:48,235 INFO L895 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2 (and .cse3 (<= ~waterLevel~0 2) .cse4)) (or (and .cse3 (= ~waterLevel~0 1) .cse4) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2023-11-06 22:53:48,235 INFO L895 garLoopResultBuilder]: At program point __automaton_fail_returnLabel#1(lines 856 863) the Hoare annotation is: (let ((.cse0 (< 2 |old(~waterLevel~0)|)) (.cse1 (< |old(~pumpRunning~0)| 1)) (.cse2 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0) (or (< |old(~switchedOnBeforeTS~0)| 1) .cse1 .cse2 .cse0) (or (not (= |old(~waterLevel~0)| 2)) .cse1 .cse2))) [2023-11-06 22:53:48,236 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 66 92) the Hoare annotation is: (let ((.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (< 2 |old(~waterLevel~0)|)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 (and .cse2 .cse3 .cse4) .cse5) (or (and (= ~pumpRunning~0 0) .cse3 .cse4) (not (= |old(~pumpRunning~0)| 0)) .cse5) (or (and .cse2 (= 2 ~waterLevel~0) .cse3) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1))) [2023-11-06 22:53:48,236 INFO L895 garLoopResultBuilder]: At program point L137(line 137) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2 (and .cse3 (<= ~waterLevel~0 2) .cse4)) (or (and .cse3 (= ~waterLevel~0 1) .cse4) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2023-11-06 22:53:48,236 INFO L895 garLoopResultBuilder]: At program point L736(line 736) the Hoare annotation is: (let ((.cse1 (not (= |old(~waterLevel~0)| 2))) (.cse5 (< |old(~pumpRunning~0)| 1)) (.cse6 (= 0 ~systemActive~0)) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (= ~pumpRunning~0 0)) (.cse9 (< 2 |old(~waterLevel~0)|))) (and (or .cse0 .cse1) (let ((.cse3 (= ~waterLevel~0 1))) (or (and .cse2 .cse3 .cse4) .cse1 .cse5 .cse6 (and .cse7 .cse3 .cse4))) (let ((.cse8 (<= ~waterLevel~0 2))) (or (< |old(~switchedOnBeforeTS~0)| 1) (and .cse7 .cse8 .cse4) .cse5 .cse6 .cse9 (and .cse2 .cse8 .cse4))) (or .cse0 (and .cse7 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse9))) [2023-11-06 22:53:48,236 INFO L899 garLoopResultBuilder]: For program point L736-1(line 736) no Hoare annotation was computed. [2023-11-06 22:53:48,236 INFO L899 garLoopResultBuilder]: For program point L860(line 860) no Hoare annotation was computed. [2023-11-06 22:53:48,237 INFO L895 garLoopResultBuilder]: At program point L146(line 146) the Hoare annotation is: (let ((.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2) (or (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or .cse3 .cse2 (not .cse1)) (or .cse3 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0)) .cse2))) [2023-11-06 22:53:48,237 INFO L895 garLoopResultBuilder]: At program point __utac_acc__Specification5_spec__2_returnLabel#1(lines 716 725) the Hoare annotation is: (let ((.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse1 (<= 1 ~switchedOnBeforeTS~0)) (.cse2 (< |old(~pumpRunning~0)| 1)) (.cse3 (= 0 ~systemActive~0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (< 2 |old(~waterLevel~0)|))) (and (or (and .cse0 (= 2 ~waterLevel~0) .cse1) (not (= |old(~waterLevel~0)| 2)) .cse2 .cse3) (or (and .cse0 .cse4 .cse1) (< |old(~switchedOnBeforeTS~0)| 1) .cse2 .cse3 .cse5) (or (not (= |old(~pumpRunning~0)| 0)) (and (= ~pumpRunning~0 0) .cse4) .cse5))) [2023-11-06 22:53:48,237 INFO L895 garLoopResultBuilder]: At program point L146-1(lines 127 151) the Hoare annotation is: (let ((.cse3 (= |old(~waterLevel~0)| 2)) (.cse7 (not (= |old(~pumpRunning~0)| 0))) (.cse6 (= ~pumpRunning~0 0)) (.cse4 (< |old(~pumpRunning~0)| 1)) (.cse5 (= 0 ~systemActive~0)) (.cse8 (< 2 |old(~waterLevel~0)|)) (.cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (<= 1 ~switchedOnBeforeTS~0))) (and (let ((.cse1 (= ~waterLevel~0 1))) (or (and .cse0 .cse1 .cse2) (not .cse3) .cse4 .cse5 (and .cse6 .cse1 .cse2))) (or (and (<= 1 ~pumpRunning~0) (= 2 ~waterLevel~0) .cse3) .cse7 (and .cse6 (= |old(~waterLevel~0)| ~waterLevel~0)) .cse8) (or .cse7 .cse8 (not .cse5)) (let ((.cse9 (<= ~waterLevel~0 2))) (or (< |old(~switchedOnBeforeTS~0)| 1) (and .cse6 .cse9 .cse2) .cse4 .cse5 .cse8 (and .cse0 .cse9 .cse2))))) [2023-11-06 22:53:48,237 INFO L899 garLoopResultBuilder]: For program point L80-1(lines 80 86) no Hoare annotation was computed. [2023-11-06 22:53:48,237 INFO L895 garLoopResultBuilder]: At program point isMethaneLevelCritical_returnLabel#1(lines 938 946) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2 (and .cse3 (<= ~waterLevel~0 2) .cse4)) (or (and .cse3 (= ~waterLevel~0 1) .cse4) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2023-11-06 22:53:48,238 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 66 92) no Hoare annotation was computed. [2023-11-06 22:53:48,238 INFO L899 garLoopResultBuilder]: For program point L906(lines 906 910) no Hoare annotation was computed. [2023-11-06 22:53:48,238 INFO L895 garLoopResultBuilder]: At program point isMethaneAlarm_returnLabel#1(lines 168 178) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2 (and .cse3 (<= ~waterLevel~0 2) .cse4)) (or (and .cse3 (= ~waterLevel~0 1) .cse4) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2023-11-06 22:53:48,238 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 860) no Hoare annotation was computed. [2023-11-06 22:53:48,238 INFO L895 garLoopResultBuilder]: At program point L906-2(lines 902 913) the Hoare annotation is: (let ((.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (<= 1 ~switchedOnBeforeTS~0)) (.cse0 (< |old(~pumpRunning~0)| 1)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (< 2 |old(~waterLevel~0)|))) (and (or (< |old(~switchedOnBeforeTS~0)| 1) .cse0 .cse1 .cse2 (and .cse3 (<= ~waterLevel~0 2) .cse4)) (or (and .cse3 (= ~waterLevel~0 1) .cse4) (not (= |old(~waterLevel~0)| 2)) .cse0 .cse1) (or (not (= |old(~pumpRunning~0)| 0)) .cse2))) [2023-11-06 22:53:48,239 INFO L895 garLoopResultBuilder]: At program point startSystem_returnLabel#1(lines 258 265) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse4) (and (= ~pumpRunning~0 0) .cse1 .cse2 .cse3 .cse5 .cse4))) [2023-11-06 22:53:48,239 INFO L902 garLoopResultBuilder]: At program point runTest_returnLabel#1(lines 818 828) the Hoare annotation is: true [2023-11-06 22:53:48,239 INFO L902 garLoopResultBuilder]: At program point L333(lines 270 337) the Hoare annotation is: true [2023-11-06 22:53:48,239 INFO L899 garLoopResultBuilder]: For program point L300(lines 300 306) no Hoare annotation was computed. [2023-11-06 22:53:48,239 INFO L899 garLoopResultBuilder]: For program point L300-1(lines 300 306) no Hoare annotation was computed. [2023-11-06 22:53:48,239 INFO L895 garLoopResultBuilder]: At program point select_features_returnLabel#1(lines 876 882) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:53:48,239 INFO L902 garLoopResultBuilder]: At program point main_returnLabel#1(lines 832 854) the Hoare annotation is: true [2023-11-06 22:53:48,240 INFO L895 garLoopResultBuilder]: At program point L292(line 292) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse4 (not (= 0 ~systemActive~0))) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse4) (and (= ~pumpRunning~0 0) .cse1 .cse2 .cse3 .cse5))) [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point L-1(line -1) no Hoare annotation was computed. [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startFINAL(line -1) no Hoare annotation was computed. [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point L247(lines 247 253) no Hoare annotation was computed. [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point L247-1(lines 247 253) no Hoare annotation was computed. [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point L842(lines 842 849) no Hoare annotation was computed. [2023-11-06 22:53:48,240 INFO L895 garLoopResultBuilder]: At program point L330(lines 279 331) the Hoare annotation is: false [2023-11-06 22:53:48,240 INFO L895 garLoopResultBuilder]: At program point setup_returnLabel#1(lines 811 817) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:53:48,240 INFO L899 garLoopResultBuilder]: For program point L842-2(lines 842 849) no Hoare annotation was computed. [2023-11-06 22:53:48,241 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-06 22:53:48,241 INFO L899 garLoopResultBuilder]: For program point L318(lines 318 324) no Hoare annotation was computed. [2023-11-06 22:53:48,241 INFO L895 garLoopResultBuilder]: At program point L318-2(lines 310 325) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse4 (not (= 0 ~systemActive~0))) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse4) (and (= ~pumpRunning~0 0) .cse1 .cse2 .cse3 .cse5))) [2023-11-06 22:53:48,241 INFO L899 garLoopResultBuilder]: For program point L281(lines 280 329) no Hoare annotation was computed. [2023-11-06 22:53:48,243 INFO L895 garLoopResultBuilder]: At program point __utac_acc__Specification5_spec__1_returnLabel#1(lines 708 715) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:53:48,243 INFO L899 garLoopResultBuilder]: For program point L310(lines 310 325) no Hoare annotation was computed. [2023-11-06 22:53:48,243 INFO L895 garLoopResultBuilder]: At program point L302(line 302) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse4 (not (= 0 ~systemActive~0))) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse4) (and (= ~pumpRunning~0 0) .cse1 .cse2 .cse3 .cse5))) [2023-11-06 22:53:48,243 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-06 22:53:48,244 INFO L895 garLoopResultBuilder]: At program point select_helpers_returnLabel#1(lines 883 889) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:53:48,244 INFO L895 garLoopResultBuilder]: At program point L327(lines 280 329) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse4 (not (= 0 ~systemActive~0))) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse5 (<= ~waterLevel~0 2))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 .cse5 (<= 1 ~switchedOnBeforeTS~0) .cse4) (and (= ~pumpRunning~0 0) .cse1 .cse2 .cse3 .cse5))) [2023-11-06 22:53:48,244 INFO L899 garLoopResultBuilder]: For program point L290(lines 290 296) no Hoare annotation was computed. [2023-11-06 22:53:48,244 INFO L899 garLoopResultBuilder]: For program point L290-1(lines 290 296) no Hoare annotation was computed. [2023-11-06 22:53:48,244 INFO L899 garLoopResultBuilder]: For program point L282(lines 282 286) no Hoare annotation was computed. [2023-11-06 22:53:48,245 INFO L895 garLoopResultBuilder]: At program point L249(line 249) the Hoare annotation is: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse1 (= |ULTIMATE.start_valid_product_#res#1| 1)) (.cse2 (= |ULTIMATE.start_main_~tmp~8#1| 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= 2 ~waterLevel~0) .cse1 .cse2 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 (<= ~waterLevel~0 2) (<= 1 ~switchedOnBeforeTS~0) .cse4))) [2023-11-06 22:53:48,245 INFO L895 garLoopResultBuilder]: At program point stopSystem_returnLabel#1(lines 243 257) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= |ULTIMATE.start_main_~tmp~8#1| 1) (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (<= ~waterLevel~0 2) (= 0 ~systemActive~0)) [2023-11-06 22:53:48,245 INFO L895 garLoopResultBuilder]: At program point valid_product_returnLabel#1(lines 890 898) the Hoare annotation is: (and (= ~pumpRunning~0 0) (= |ULTIMATE.start_valid_product_#res#1| 1) (= ~waterLevel~0 1) (not (= 0 ~systemActive~0))) [2023-11-06 22:53:48,245 INFO L895 garLoopResultBuilder]: At program point activatePump_returnLabel#1(lines 152 159) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse1) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) (and (<= 1 ~pumpRunning~0) (= 2 ~waterLevel~0)) .cse1))) [2023-11-06 22:53:48,246 INFO L895 garLoopResultBuilder]: At program point L120(line 120) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse1) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1))) [2023-11-06 22:53:48,246 INFO L899 garLoopResultBuilder]: For program point L983(lines 983 989) no Hoare annotation was computed. [2023-11-06 22:53:48,246 INFO L899 garLoopResultBuilder]: For program point L120-1(lines 101 125) no Hoare annotation was computed. [2023-11-06 22:53:48,246 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 101 125) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (= 0 ~systemActive~0))) (and (or .cse0 (= ~pumpRunning~0 |old(~pumpRunning~0)|) (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse1) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) (= ~pumpRunning~0 0) .cse1))) [2023-11-06 22:53:48,246 INFO L895 garLoopResultBuilder]: At program point isHighWaterSensorDry_returnLabel#1(lines 979 992) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse1 (= 2 ~waterLevel~0)) (.cse6 (= |old(~pumpRunning~0)| 0))) (let ((.cse4 (< 2 ~waterLevel~0)) (.cse0 (not .cse6)) (.cse2 (= 0 ~systemActive~0)) (.cse3 (and .cse5 .cse1 .cse6 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 0)))) (and (or .cse0 (not .cse1) .cse2 .cse3) (or .cse4 (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse2) (or .cse4 .cse0 (and .cse5 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)) .cse2 .cse3)))) [2023-11-06 22:53:48,247 INFO L895 garLoopResultBuilder]: At program point isHighWaterLevel_returnLabel#1(lines 224 242) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse2 (= 0 ~systemActive~0))) (and (let ((.cse1 (= ~pumpRunning~0 0))) (or .cse0 (not (= |old(~pumpRunning~0)| 0)) (and .cse1 (= 2 ~waterLevel~0)) (and .cse1 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_#res#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp___0~0#1| 0) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1) (= |processEnvironment__wrappee__highWaterSensor_isHighWaterLevel_~tmp~2#1| 1)) .cse2)) (or .cse0 (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse2))) [2023-11-06 22:53:48,247 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 101 125) no Hoare annotation was computed. [2023-11-06 22:53:48,247 INFO L895 garLoopResultBuilder]: At program point L115(line 115) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (not (= |old(~pumpRunning~0)| 0))) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0)) .cse2) (or .cse0 (< ~switchedOnBeforeTS~0 1) (< |old(~pumpRunning~0)| 1) .cse2) (or (not (= ~waterLevel~0 1)) .cse1 .cse2 (= |processEnvironment__wrappee__highWaterSensor_isHighWaterSensorDry_#res#1| 1)))) [2023-11-06 22:53:48,247 INFO L899 garLoopResultBuilder]: For program point L109(lines 109 117) no Hoare annotation was computed. [2023-11-06 22:53:48,248 INFO L899 garLoopResultBuilder]: For program point L105(lines 105 122) no Hoare annotation was computed. [2023-11-06 22:53:48,248 INFO L899 garLoopResultBuilder]: For program point L233(lines 233 237) no Hoare annotation was computed. [2023-11-06 22:53:48,248 INFO L899 garLoopResultBuilder]: For program point L233-2(lines 233 237) no Hoare annotation was computed. [2023-11-06 22:53:48,248 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 914 925) no Hoare annotation was computed. [2023-11-06 22:53:48,248 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 914 925) the Hoare annotation is: (let ((.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse3 (< 2 |old(~waterLevel~0)|)) (.cse0 (< ~pumpRunning~0 1)) (.cse2 (= 0 ~systemActive~0))) (and (or .cse0 (< ~switchedOnBeforeTS~0 1) .cse1 .cse2 .cse3) (or (not (= ~pumpRunning~0 0)) .cse1 .cse3) (or .cse0 (= 2 ~waterLevel~0) (not (= |old(~waterLevel~0)| 2)) .cse2))) [2023-11-06 22:53:48,248 INFO L899 garLoopResultBuilder]: For program point L918-1(lines 914 925) no Hoare annotation was computed. [2023-11-06 22:53:48,249 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 179 187) no Hoare annotation was computed. [2023-11-06 22:53:48,249 INFO L899 garLoopResultBuilder]: For program point isPumpRunningFINAL(lines 179 187) no Hoare annotation was computed. [2023-11-06 22:53:48,249 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 179 187) the Hoare annotation is: true [2023-11-06 22:53:48,252 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-06 22:53:48,254 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-06 22:53:48,290 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 06.11 10:53:48 BoogieIcfgContainer [2023-11-06 22:53:48,290 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-06 22:53:48,291 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-06 22:53:48,291 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-06 22:53:48,291 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-06 22:53:48,292 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 06.11 10:53:35" (3/4) ... [2023-11-06 22:53:48,294 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-06 22:53:48,298 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-06 22:53:48,298 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-06 22:53:48,298 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-06 22:53:48,298 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-06 22:53:48,299 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-06 22:53:48,299 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-06 22:53:48,299 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-06 22:53:48,299 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2023-11-06 22:53:48,308 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 17 nodes and edges [2023-11-06 22:53:48,309 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 7 nodes and edges [2023-11-06 22:53:48,309 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-06 22:53:48,310 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:53:48,311 INFO L939 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-06 22:53:48,339 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,339 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,340 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,340 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2))) [2023-11-06 22:53:48,341 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == \old(pumpRunning)) && (2 == waterLevel)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && (((((((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) == waterLevel)) && (1 <= switchedOnBeforeTS)) || (\old(switchedOnBeforeTS) < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,342 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,342 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || (((pumpRunning == 0) && (waterLevel <= 2)) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel))) && ((!((\old(pumpRunning) == 0)) || ((2 == \result) && (tmp == 2))) || !((\old(waterLevel) == 2)))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,342 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && !((0 == systemActive)))) [2023-11-06 22:53:48,343 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS))) && ((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,343 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) && ((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(waterLevel) == 2)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) [2023-11-06 22:53:48,344 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (0 == systemActive)) [2023-11-06 22:53:48,344 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || ((((1 <= pumpRunning) && (2 == waterLevel)) && !((0 == systemActive))) && (\old(waterLevel) == 2))) || (2 < \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && ((!((\old(pumpRunning) == 0)) || (2 == \result)) || !((\old(waterLevel) == 2)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,344 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,345 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || !((2 == waterLevel))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0))) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)))) [2023-11-06 22:53:48,345 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,345 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (2 == waterLevel))) || (((((pumpRunning == 0) && (\result == 0)) && (tmp___0 == 0)) && (\result == 1)) && (tmp == 1))) || (0 == systemActive)) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) [2023-11-06 22:53:48,346 WARN L220 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && ((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((1 <= pumpRunning) && (2 == waterLevel))) || (0 == systemActive))) [2023-11-06 22:53:48,379 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,379 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,379 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) [2023-11-06 22:53:48,380 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2))) [2023-11-06 22:53:48,380 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((pumpRunning == \old(pumpRunning)) && (2 == waterLevel)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && (((((((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) == waterLevel)) && (1 <= switchedOnBeforeTS)) || (\old(switchedOnBeforeTS) < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,381 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,381 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || (((pumpRunning == 0) && (waterLevel <= 2)) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel))) && ((!((\old(pumpRunning) == 0)) || ((2 == \result) && (tmp == 2))) || !((\old(waterLevel) == 2)))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,381 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && !((0 == systemActive)))) [2023-11-06 22:53:48,381 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS))) && ((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,382 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) && ((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(waterLevel) == 2)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) [2023-11-06 22:53:48,382 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (0 == systemActive)) [2023-11-06 22:53:48,382 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || ((((1 <= pumpRunning) && (2 == waterLevel)) && !((0 == systemActive))) && (\old(waterLevel) == 2))) || (2 < \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && ((!((\old(pumpRunning) == 0)) || (2 == \result)) || !((\old(waterLevel) == 2)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) [2023-11-06 22:53:48,382 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,383 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((!((\old(pumpRunning) == 0)) || !((2 == waterLevel))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0))) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)))) [2023-11-06 22:53:48,383 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) [2023-11-06 22:53:48,383 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (2 == waterLevel))) || (((((pumpRunning == 0) && (\result == 0)) && (tmp___0 == 0)) && (\result == 1)) && (tmp == 1))) || (0 == systemActive)) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) [2023-11-06 22:53:48,384 WARN L115 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: (((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && ((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((1 <= pumpRunning) && (2 == waterLevel))) || (0 == systemActive))) [2023-11-06 22:53:48,399 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.graphml [2023-11-06 22:53:48,399 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/witness.graphml.yaml [2023-11-06 22:53:48,400 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-06 22:53:48,400 INFO L158 Benchmark]: Toolchain (without parser) took 13740.85ms. Allocated memory was 182.5MB in the beginning and 220.2MB in the end (delta: 37.7MB). Free memory was 134.8MB in the beginning and 157.9MB in the end (delta: -23.2MB). Peak memory consumption was 17.1MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,401 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 130.0MB. Free memory is still 69.6MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-06 22:53:48,401 INFO L158 Benchmark]: CACSL2BoogieTranslator took 653.21ms. Allocated memory is still 182.5MB. Free memory was 134.8MB in the beginning and 115.3MB in the end (delta: 19.5MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,402 INFO L158 Benchmark]: Boogie Procedure Inliner took 56.48ms. Allocated memory is still 182.5MB. Free memory was 115.3MB in the beginning and 113.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,402 INFO L158 Benchmark]: Boogie Preprocessor took 70.76ms. Allocated memory is still 182.5MB. Free memory was 113.2MB in the beginning and 111.7MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,402 INFO L158 Benchmark]: RCFGBuilder took 551.21ms. Allocated memory is still 182.5MB. Free memory was 111.7MB in the beginning and 94.3MB in the end (delta: 17.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,403 INFO L158 Benchmark]: TraceAbstraction took 12290.04ms. Allocated memory was 182.5MB in the beginning and 220.2MB in the end (delta: 37.7MB). Free memory was 93.6MB in the beginning and 166.3MB in the end (delta: -72.7MB). Peak memory consumption was 74.9MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,403 INFO L158 Benchmark]: Witness Printer took 108.78ms. Allocated memory is still 220.2MB. Free memory was 165.3MB in the beginning and 157.9MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2023-11-06 22:53:48,405 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 130.0MB. Free memory is still 69.6MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 653.21ms. Allocated memory is still 182.5MB. Free memory was 134.8MB in the beginning and 115.3MB in the end (delta: 19.5MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 56.48ms. Allocated memory is still 182.5MB. Free memory was 115.3MB in the beginning and 113.2MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 70.76ms. Allocated memory is still 182.5MB. Free memory was 113.2MB in the beginning and 111.7MB in the end (delta: 1.5MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 551.21ms. Allocated memory is still 182.5MB. Free memory was 111.7MB in the beginning and 94.3MB in the end (delta: 17.4MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * TraceAbstraction took 12290.04ms. Allocated memory was 182.5MB in the beginning and 220.2MB in the end (delta: 37.7MB). Free memory was 93.6MB in the beginning and 166.3MB in the end (delta: -72.7MB). Peak memory consumption was 74.9MB. Max. memory is 16.1GB. * Witness Printer took 108.78ms. Allocated memory is still 220.2MB. Free memory was 165.3MB in the beginning and 157.9MB in the end (delta: 7.3MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [49] - GenericResultAtLocation [Line: 266]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [266] - GenericResultAtLocation [Line: 338]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [338] - GenericResultAtLocation [Line: 704]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [704] - GenericResultAtLocation [Line: 755]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [755] - GenericResultAtLocation [Line: 855]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [855] - GenericResultAtLocation [Line: 864]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [864] - GenericResultAtLocation [Line: 899]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [899] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 860]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 9 procedures, 98 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 12.2s, OverallIterations: 10, TraceHistogramMax: 3, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 3.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 5.3s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 1765 SdHoareTripleChecker+Valid, 1.9s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 1730 mSDsluCounter, 4173 SdHoareTripleChecker+Invalid, 1.6s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3068 mSDsCounter, 485 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 1883 IncrementalHoareTripleChecker+Invalid, 2368 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 485 mSolverCounterUnsat, 1105 mSDtfsCounter, 1883 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 398 GetRequests, 283 SyntacticMatches, 4 SemanticMatches, 111 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 707 ImplicationChecksByTransitivity, 1.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=590occurred in iteration=9, InterpolantAutomatonStates: 107, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.4s AutomataMinimizationTime, 10 MinimizatonAttempts, 83 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 46 LocationsWithAnnotation, 1425 PreInvPairs, 1723 NumberOfFragments, 1735 HoareAnnotationTreeSize, 1425 FomulaSimplifications, 2886 FormulaSimplificationTreeSizeReduction, 0.6s HoareSimplificationTime, 46 FomulaSimplificationsInter, 9685 FormulaSimplificationTreeSizeReductionInter, 4.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.2s SatisfiabilityAnalysisTime, 2.0s InterpolantComputationTime, 603 NumberOfCodeBlocks, 603 NumberOfCodeBlocksAsserted, 11 NumberOfCheckSat, 687 ConstructedInterpolants, 0 QuantifiedInterpolants, 1255 SizeOfPredicates, 3 NumberOfNonLiveVariables, 330 ConjunctsInSsa, 8 ConjunctsInUnsatCore, 12 InterpolantComputations, 9 PerfectInterpolantSequences, 103/129 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 811]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 876]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 152]: Loop Invariant Derived loop invariant: (((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && ((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((1 <= pumpRunning) && (2 == waterLevel))) || (0 == systemActive))) - InvariantResult [Line: 938]: Loop Invariant Derived loop invariant: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) - InvariantResult [Line: 168]: Loop Invariant Derived loop invariant: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) - InvariantResult [Line: 979]: Loop Invariant Derived loop invariant: (((((!((\old(pumpRunning) == 0)) || !((2 == waterLevel))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0))) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\result == 1))) || (0 == systemActive)) || ((((pumpRunning == 0) && (2 == waterLevel)) && (\old(pumpRunning) == 0)) && (\result == 0)))) - InvariantResult [Line: 726]: Loop Invariant Derived loop invariant: ((((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || (((pumpRunning == 0) && (waterLevel <= 2)) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel))) && ((!((\old(pumpRunning) == 0)) || ((2 == \result) && (tmp == 2))) || !((\old(waterLevel) == 2)))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && (((!((\old(pumpRunning) == 0)) || (pumpRunning == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) - InvariantResult [Line: 224]: Loop Invariant Derived loop invariant: ((((((2 < waterLevel) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (2 == waterLevel))) || (((((pumpRunning == 0) && (\result == 0)) && (tmp___0 == 0)) && (\result == 1)) && (tmp == 1))) || (0 == systemActive)) && ((((2 < waterLevel) || (switchedOnBeforeTS < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) - InvariantResult [Line: 757]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 818]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 279]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 708]: Loop Invariant Derived loop invariant: (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 243]: Loop Invariant Derived loop invariant: ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (0 == systemActive)) - InvariantResult [Line: 902]: Loop Invariant Derived loop invariant: (((((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) && ((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive))) && (!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel)))) - InvariantResult [Line: 280]: Loop Invariant Derived loop invariant: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || (((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2))) - InvariantResult [Line: 258]: Loop Invariant Derived loop invariant: ((((((((1 <= pumpRunning) && (2 == waterLevel)) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && !((0 == systemActive))) || (((((((1 <= pumpRunning) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && !((0 == systemActive)))) || ((((((pumpRunning == 0) && (\result == 1)) && (tmp == 1)) && (splverifierCounter == 0)) && (waterLevel <= 2)) && !((0 == systemActive)))) - InvariantResult [Line: 856]: Loop Invariant Derived loop invariant: (((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) && ((((\old(switchedOnBeforeTS) < 1) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(waterLevel) == 2)) || (\old(pumpRunning) < 1)) || (0 == systemActive))) - InvariantResult [Line: 970]: Loop Invariant Derived loop invariant: ((((((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || ((((1 <= pumpRunning) && (2 == waterLevel)) && !((0 == systemActive))) && (\old(waterLevel) == 2))) || (2 < \old(waterLevel))) && (((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)))) && ((!((\old(pumpRunning) == 0)) || (2 == \result)) || !((\old(waterLevel) == 2)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) - InvariantResult [Line: 890]: Loop Invariant Derived loop invariant: ((((pumpRunning == 0) && (\result == 1)) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 883]: Loop Invariant Derived loop invariant: (((pumpRunning == 0) && (waterLevel == 1)) && !((0 == systemActive))) - InvariantResult [Line: 716]: Loop Invariant Derived loop invariant: ((((((((pumpRunning == \old(pumpRunning)) && (2 == waterLevel)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) && (((((((pumpRunning == \old(pumpRunning)) && (\old(waterLevel) == waterLevel)) && (1 <= switchedOnBeforeTS)) || (\old(switchedOnBeforeTS) < 1)) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) - InvariantResult [Line: 127]: Loop Invariant Derived loop invariant: ((((((((((pumpRunning == \old(pumpRunning)) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS)) || !((\old(waterLevel) == 2))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (((pumpRunning == 0) && (waterLevel == 1)) && (1 <= switchedOnBeforeTS))) && ((((((1 <= pumpRunning) && (2 == waterLevel)) && (\old(waterLevel) == 2)) || !((\old(pumpRunning) == 0))) || ((pumpRunning == 0) && (\old(waterLevel) == waterLevel))) || (2 < \old(waterLevel)))) && ((!((\old(pumpRunning) == 0)) || (2 < \old(waterLevel))) || !((0 == systemActive)))) && ((((((\old(switchedOnBeforeTS) < 1) || (((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS))) || (\old(pumpRunning) < 1)) || (0 == systemActive)) || (2 < \old(waterLevel))) || (((pumpRunning == \old(pumpRunning)) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)))) - InvariantResult [Line: 767]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 832]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 270]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-06 22:53:48,458 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_42ec7b18-40ab-48fc-9561-08ea699d0162/bin/uautomizer-verify-WvqO1wxjHP/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE