./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 527bcce2 Calling Ultimate with: /usr/lib/jvm/java-1.11.0-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx --witnessprinter.witness.filename witness --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 303db4082dd8b7a60cb4b5043655f09159321046818373497160cd54b8948d04 --- Real Ultimate output --- This is Ultimate 0.2.3-dev-527bcce [2023-11-21 20:59:11,184 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-21 20:59:11,300 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-21 20:59:11,305 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-21 20:59:11,306 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-21 20:59:11,330 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-21 20:59:11,330 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-21 20:59:11,331 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-21 20:59:11,332 INFO L151 SettingsManager]: Preferences of Boogie Preprocessor differ from their defaults: [2023-11-21 20:59:11,333 INFO L153 SettingsManager]: * Use memory slicer=true [2023-11-21 20:59:11,333 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-21 20:59:11,334 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-21 20:59:11,335 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-21 20:59:11,335 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-21 20:59:11,336 INFO L153 SettingsManager]: * Use SBE=true [2023-11-21 20:59:11,337 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-21 20:59:11,337 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-21 20:59:11,338 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-21 20:59:11,338 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-21 20:59:11,339 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-21 20:59:11,340 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-21 20:59:11,345 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-21 20:59:11,345 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-21 20:59:11,346 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-21 20:59:11,346 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-21 20:59:11,347 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-21 20:59:11,347 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-21 20:59:11,348 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-21 20:59:11,348 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-21 20:59:11,349 INFO L153 SettingsManager]: * Only consider context switches at boundaries of atomic blocks=true [2023-11-21 20:59:11,349 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-21 20:59:11,350 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-21 20:59:11,350 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-21 20:59:11,351 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-21 20:59:11,351 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopHeads [2023-11-21 20:59:11,352 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-21 20:59:11,352 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-21 20:59:11,353 INFO L153 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2023-11-21 20:59:11,353 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-21 20:59:11,354 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-21 20:59:11,354 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-21 20:59:11,360 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-21 20:59:11,361 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 303db4082dd8b7a60cb4b5043655f09159321046818373497160cd54b8948d04 [2023-11-21 20:59:11,626 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-21 20:59:11,648 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-21 20:59:11,651 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-21 20:59:11,652 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-21 20:59:11,653 INFO L274 PluginConnector]: CDTParser initialized [2023-11-21 20:59:11,654 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/../../sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c [2023-11-21 20:59:14,751 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-21 20:59:15,040 INFO L384 CDTParser]: Found 1 translation units. [2023-11-21 20:59:15,043 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c [2023-11-21 20:59:15,064 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/data/0e7a4d32c/28e40b2401fe4a4db6294135ceb94f82/FLAG6ac71f5af [2023-11-21 20:59:15,082 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/data/0e7a4d32c/28e40b2401fe4a4db6294135ceb94f82 [2023-11-21 20:59:15,087 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-21 20:59:15,089 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-21 20:59:15,092 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-21 20:59:15,092 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-21 20:59:15,098 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-21 20:59:15,099 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,100 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@7a42e091 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15, skipping insertion in model container [2023-11-21 20:59:15,100 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,175 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-21 20:59:15,327 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c[1605,1618] [2023-11-21 20:59:15,502 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-21 20:59:15,516 INFO L202 MainTranslator]: Completed pre-run [2023-11-21 20:59:15,530 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] [2023-11-21 20:59:15,532 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [58] [2023-11-21 20:59:15,532 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [283] [2023-11-21 20:59:15,532 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [353] [2023-11-21 20:59:15,533 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [454] [2023-11-21 20:59:15,533 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [820] [2023-11-21 20:59:15,533 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [855] [2023-11-21 20:59:15,534 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [905] [2023-11-21 20:59:15,545 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/sv-benchmarks/c/product-lines/minepump_spec5_product47.cil.c[1605,1618] [2023-11-21 20:59:15,642 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-21 20:59:15,664 INFO L206 MainTranslator]: Completed translation [2023-11-21 20:59:15,664 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15 WrapperNode [2023-11-21 20:59:15,664 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-21 20:59:15,666 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-21 20:59:15,666 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-21 20:59:15,666 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-21 20:59:15,674 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,689 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,732 INFO L138 Inliner]: procedures = 57, calls = 104, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 214 [2023-11-21 20:59:15,732 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-21 20:59:15,733 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-21 20:59:15,733 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-21 20:59:15,733 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-21 20:59:15,747 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,751 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,755 INFO L184 PluginConnector]: Executing the observer HeapSplitter from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,784 INFO L187 HeapSplitter]: Split 2 memory accesses to 1 slices as follows [2] [2023-11-21 20:59:15,785 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,785 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,791 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,796 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,797 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,799 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,802 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-21 20:59:15,803 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-21 20:59:15,803 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-21 20:59:15,803 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-21 20:59:15,804 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (1/1) ... [2023-11-21 20:59:15,810 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-21 20:59:15,825 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 20:59:15,837 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-21 20:59:15,856 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-21 20:59:15,877 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-21 20:59:15,878 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-21 20:59:15,878 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-21 20:59:15,878 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-21 20:59:15,878 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-21 20:59:15,879 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-21 20:59:15,879 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-21 20:59:15,879 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-21 20:59:15,879 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-21 20:59:15,879 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2023-11-21 20:59:15,880 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2023-11-21 20:59:15,880 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2023-11-21 20:59:15,880 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2023-11-21 20:59:15,880 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2023-11-21 20:59:15,880 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2023-11-21 20:59:15,881 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2023-11-21 20:59:15,881 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2023-11-21 20:59:15,881 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int#0 [2023-11-21 20:59:15,881 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-21 20:59:15,881 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-21 20:59:15,882 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-21 20:59:15,882 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-21 20:59:15,961 INFO L240 CfgBuilder]: Building ICFG [2023-11-21 20:59:15,964 INFO L266 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-21 20:59:16,321 INFO L281 CfgBuilder]: Performing block encoding [2023-11-21 20:59:16,456 INFO L303 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-21 20:59:16,456 INFO L308 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-21 20:59:16,458 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 08:59:16 BoogieIcfgContainer [2023-11-21 20:59:16,458 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-21 20:59:16,461 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-21 20:59:16,461 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-21 20:59:16,464 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-21 20:59:16,464 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.11 08:59:15" (1/3) ... [2023-11-21 20:59:16,465 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@34808e3a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 08:59:16, skipping insertion in model container [2023-11-21 20:59:16,465 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 08:59:15" (2/3) ... [2023-11-21 20:59:16,466 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@34808e3a and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 08:59:16, skipping insertion in model container [2023-11-21 20:59:16,466 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 08:59:16" (3/3) ... [2023-11-21 20:59:16,467 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product47.cil.c [2023-11-21 20:59:16,487 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-21 20:59:16,488 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-21 20:59:16,538 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-21 20:59:16,545 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopHeads, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@2e5fd71, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2023-11-21 20:59:16,546 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-21 20:59:16,549 INFO L276 IsEmpty]: Start isEmpty. Operand has 72 states, 45 states have (on average 1.4222222222222223) internal successors, (64), 54 states have internal predecessors, (64), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) [2023-11-21 20:59:16,559 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2023-11-21 20:59:16,559 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:16,560 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:16,561 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:16,566 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:16,566 INFO L85 PathProgramCache]: Analyzing trace with hash -798935313, now seen corresponding path program 1 times [2023-11-21 20:59:16,576 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:16,577 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1902349239] [2023-11-21 20:59:16,577 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:16,578 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:16,729 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:16,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 20:59:16,848 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:16,857 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-21 20:59:16,864 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:16,872 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:16,872 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:16,874 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1902349239] [2023-11-21 20:59:16,875 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1902349239] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:16,875 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:16,876 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-21 20:59:16,877 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [565823155] [2023-11-21 20:59:16,878 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:16,883 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-21 20:59:16,884 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:17,009 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-21 20:59:17,010 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-21 20:59:17,012 INFO L87 Difference]: Start difference. First operand has 72 states, 45 states have (on average 1.4222222222222223) internal successors, (64), 54 states have internal predecessors, (64), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 13 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:17,119 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:17,119 INFO L93 Difference]: Finished difference Result 142 states and 193 transitions. [2023-11-21 20:59:17,120 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-21 20:59:17,122 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2023-11-21 20:59:17,122 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:17,133 INFO L225 Difference]: With dead ends: 142 [2023-11-21 20:59:17,134 INFO L226 Difference]: Without dead ends: 67 [2023-11-21 20:59:17,140 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-21 20:59:17,145 INFO L413 NwaCegarLoop]: 76 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 76 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:17,147 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 76 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-21 20:59:17,165 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 67 states. [2023-11-21 20:59:17,199 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 67 to 67. [2023-11-21 20:59:17,201 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 67 states, 42 states have (on average 1.3333333333333333) internal successors, (56), 50 states have internal predecessors, (56), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 12 states have call predecessors, (15), 15 states have call successors, (15) [2023-11-21 20:59:17,212 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 67 states to 67 states and 87 transitions. [2023-11-21 20:59:17,214 INFO L78 Accepts]: Start accepts. Automaton has 67 states and 87 transitions. Word has length 21 [2023-11-21 20:59:17,214 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:17,214 INFO L495 AbstractCegarLoop]: Abstraction has 67 states and 87 transitions. [2023-11-21 20:59:17,215 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:17,215 INFO L276 IsEmpty]: Start isEmpty. Operand 67 states and 87 transitions. [2023-11-21 20:59:17,220 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2023-11-21 20:59:17,220 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:17,221 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:17,221 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-21 20:59:17,221 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:17,222 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:17,222 INFO L85 PathProgramCache]: Analyzing trace with hash 631438556, now seen corresponding path program 1 times [2023-11-21 20:59:17,222 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:17,222 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1913463845] [2023-11-21 20:59:17,223 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:17,223 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:17,259 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,355 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-21 20:59:17,357 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,360 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2023-11-21 20:59:17,361 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,364 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:17,364 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:17,365 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1913463845] [2023-11-21 20:59:17,365 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1913463845] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:17,365 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:17,366 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-21 20:59:17,366 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2113538055] [2023-11-21 20:59:17,366 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:17,367 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-21 20:59:17,368 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:17,368 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-21 20:59:17,369 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-21 20:59:17,369 INFO L87 Difference]: Start difference. First operand 67 states and 87 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:17,407 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:17,408 INFO L93 Difference]: Finished difference Result 106 states and 136 transitions. [2023-11-21 20:59:17,408 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-21 20:59:17,409 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2023-11-21 20:59:17,409 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:17,410 INFO L225 Difference]: With dead ends: 106 [2023-11-21 20:59:17,410 INFO L226 Difference]: Without dead ends: 59 [2023-11-21 20:59:17,411 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-21 20:59:17,413 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 14 mSDsluCounter, 45 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 18 SdHoareTripleChecker+Valid, 107 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:17,413 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [18 Valid, 107 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-21 20:59:17,414 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 59 states. [2023-11-21 20:59:17,422 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 59 to 59. [2023-11-21 20:59:17,423 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 59 states, 37 states have (on average 1.3513513513513513) internal successors, (50), 45 states have internal predecessors, (50), 13 states have call successors, (13), 8 states have call predecessors, (13), 8 states have return successors, (13), 10 states have call predecessors, (13), 13 states have call successors, (13) [2023-11-21 20:59:17,424 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 59 states to 59 states and 76 transitions. [2023-11-21 20:59:17,424 INFO L78 Accepts]: Start accepts. Automaton has 59 states and 76 transitions. Word has length 22 [2023-11-21 20:59:17,425 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:17,425 INFO L495 AbstractCegarLoop]: Abstraction has 59 states and 76 transitions. [2023-11-21 20:59:17,425 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:17,425 INFO L276 IsEmpty]: Start isEmpty. Operand 59 states and 76 transitions. [2023-11-21 20:59:17,427 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 26 [2023-11-21 20:59:17,427 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:17,427 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:17,427 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-21 20:59:17,428 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:17,428 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:17,428 INFO L85 PathProgramCache]: Analyzing trace with hash 837058471, now seen corresponding path program 1 times [2023-11-21 20:59:17,429 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:17,429 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2021872517] [2023-11-21 20:59:17,429 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:17,430 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:17,465 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,565 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-21 20:59:17,569 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,572 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2023-11-21 20:59:17,573 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,575 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:17,575 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:17,576 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2021872517] [2023-11-21 20:59:17,576 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2021872517] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:17,576 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:17,576 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2023-11-21 20:59:17,576 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [34963549] [2023-11-21 20:59:17,577 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:17,577 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2023-11-21 20:59:17,577 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:17,586 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2023-11-21 20:59:17,587 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2023-11-21 20:59:17,587 INFO L87 Difference]: Start difference. First operand 59 states and 76 transitions. Second operand has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-21 20:59:17,811 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:17,811 INFO L93 Difference]: Finished difference Result 166 states and 221 transitions. [2023-11-21 20:59:17,812 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2023-11-21 20:59:17,812 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 25 [2023-11-21 20:59:17,812 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:17,814 INFO L225 Difference]: With dead ends: 166 [2023-11-21 20:59:17,814 INFO L226 Difference]: Without dead ends: 109 [2023-11-21 20:59:17,815 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2023-11-21 20:59:17,817 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 87 mSDsluCounter, 95 mSDsCounter, 0 mSdLazyCounter, 75 mSolverCounterSat, 9 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 87 SdHoareTripleChecker+Valid, 163 SdHoareTripleChecker+Invalid, 84 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 9 IncrementalHoareTripleChecker+Valid, 75 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:17,817 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [87 Valid, 163 Invalid, 84 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [9 Valid, 75 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-21 20:59:17,818 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 109 states. [2023-11-21 20:59:17,842 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 109 to 92. [2023-11-21 20:59:17,842 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 92 states, 59 states have (on average 1.3559322033898304) internal successors, (80), 70 states have internal predecessors, (80), 19 states have call successors, (19), 13 states have call predecessors, (19), 13 states have return successors, (20), 15 states have call predecessors, (20), 19 states have call successors, (20) [2023-11-21 20:59:17,844 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 92 states to 92 states and 119 transitions. [2023-11-21 20:59:17,844 INFO L78 Accepts]: Start accepts. Automaton has 92 states and 119 transitions. Word has length 25 [2023-11-21 20:59:17,844 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:17,844 INFO L495 AbstractCegarLoop]: Abstraction has 92 states and 119 transitions. [2023-11-21 20:59:17,845 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 4.75) internal successors, (19), 4 states have internal predecessors, (19), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-21 20:59:17,845 INFO L276 IsEmpty]: Start isEmpty. Operand 92 states and 119 transitions. [2023-11-21 20:59:17,846 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 29 [2023-11-21 20:59:17,847 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:17,847 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:17,847 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-21 20:59:17,847 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:17,848 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:17,848 INFO L85 PathProgramCache]: Analyzing trace with hash -14586727, now seen corresponding path program 1 times [2023-11-21 20:59:17,848 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:17,848 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [189540873] [2023-11-21 20:59:17,848 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:17,849 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:17,866 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,974 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-21 20:59:17,976 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:17,979 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 21 [2023-11-21 20:59:17,981 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,011 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2023-11-21 20:59:18,012 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:18,012 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [189540873] [2023-11-21 20:59:18,012 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [189540873] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:18,012 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:18,013 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2023-11-21 20:59:18,013 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [242358572] [2023-11-21 20:59:18,013 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:18,014 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2023-11-21 20:59:18,014 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:18,014 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2023-11-21 20:59:18,015 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2023-11-21 20:59:18,015 INFO L87 Difference]: Start difference. First operand 92 states and 119 transitions. Second operand has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:18,193 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:18,193 INFO L93 Difference]: Finished difference Result 220 states and 290 transitions. [2023-11-21 20:59:18,194 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-21 20:59:18,194 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 28 [2023-11-21 20:59:18,194 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:18,196 INFO L225 Difference]: With dead ends: 220 [2023-11-21 20:59:18,196 INFO L226 Difference]: Without dead ends: 130 [2023-11-21 20:59:18,198 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2023-11-21 20:59:18,200 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 38 mSDsluCounter, 202 mSDsCounter, 0 mSdLazyCounter, 119 mSolverCounterSat, 8 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 39 SdHoareTripleChecker+Valid, 264 SdHoareTripleChecker+Invalid, 127 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 8 IncrementalHoareTripleChecker+Valid, 119 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:18,200 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [39 Valid, 264 Invalid, 127 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [8 Valid, 119 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-21 20:59:18,201 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 130 states. [2023-11-21 20:59:18,221 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 130 to 126. [2023-11-21 20:59:18,222 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 126 states, 83 states have (on average 1.2771084337349397) internal successors, (106), 93 states have internal predecessors, (106), 23 states have call successors, (23), 19 states have call predecessors, (23), 19 states have return successors, (29), 22 states have call predecessors, (29), 23 states have call successors, (29) [2023-11-21 20:59:18,223 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 126 states to 126 states and 158 transitions. [2023-11-21 20:59:18,223 INFO L78 Accepts]: Start accepts. Automaton has 126 states and 158 transitions. Word has length 28 [2023-11-21 20:59:18,224 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:18,226 INFO L495 AbstractCegarLoop]: Abstraction has 126 states and 158 transitions. [2023-11-21 20:59:18,227 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 4.6) internal successors, (23), 5 states have internal predecessors, (23), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 20:59:18,227 INFO L276 IsEmpty]: Start isEmpty. Operand 126 states and 158 transitions. [2023-11-21 20:59:18,228 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2023-11-21 20:59:18,229 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:18,233 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:18,233 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-21 20:59:18,233 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:18,234 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:18,234 INFO L85 PathProgramCache]: Analyzing trace with hash 1667223061, now seen corresponding path program 1 times [2023-11-21 20:59:18,234 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:18,234 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1507121544] [2023-11-21 20:59:18,234 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:18,235 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:18,267 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,513 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-21 20:59:18,515 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,524 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2023-11-21 20:59:18,531 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,591 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:18,593 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,596 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-21 20:59:18,597 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:18,600 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:18,600 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:18,600 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1507121544] [2023-11-21 20:59:18,600 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1507121544] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:18,602 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:18,602 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-21 20:59:18,602 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1899138680] [2023-11-21 20:59:18,603 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:18,603 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-21 20:59:18,604 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:18,604 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-21 20:59:18,605 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=29, Unknown=0, NotChecked=0, Total=42 [2023-11-21 20:59:18,605 INFO L87 Difference]: Start difference. First operand 126 states and 158 transitions. Second operand has 7 states, 7 states have (on average 3.857142857142857) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2023-11-21 20:59:18,892 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:18,892 INFO L93 Difference]: Finished difference Result 369 states and 470 transitions. [2023-11-21 20:59:18,893 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 9 states. [2023-11-21 20:59:18,893 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.857142857142857) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 37 [2023-11-21 20:59:18,894 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:18,897 INFO L225 Difference]: With dead ends: 369 [2023-11-21 20:59:18,897 INFO L226 Difference]: Without dead ends: 245 [2023-11-21 20:59:18,898 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 20 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=36, Invalid=74, Unknown=0, NotChecked=0, Total=110 [2023-11-21 20:59:18,900 INFO L413 NwaCegarLoop]: 81 mSDtfsCounter, 145 mSDsluCounter, 178 mSDsCounter, 0 mSdLazyCounter, 193 mSolverCounterSat, 58 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 152 SdHoareTripleChecker+Valid, 259 SdHoareTripleChecker+Invalid, 251 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 58 IncrementalHoareTripleChecker+Valid, 193 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:18,901 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [152 Valid, 259 Invalid, 251 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [58 Valid, 193 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-21 20:59:18,902 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 245 states. [2023-11-21 20:59:18,952 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 245 to 237. [2023-11-21 20:59:18,955 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 237 states, 159 states have (on average 1.270440251572327) internal successors, (202), 175 states have internal predecessors, (202), 42 states have call successors, (42), 34 states have call predecessors, (42), 35 states have return successors, (57), 40 states have call predecessors, (57), 42 states have call successors, (57) [2023-11-21 20:59:18,958 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 237 states to 237 states and 301 transitions. [2023-11-21 20:59:18,958 INFO L78 Accepts]: Start accepts. Automaton has 237 states and 301 transitions. Word has length 37 [2023-11-21 20:59:18,959 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:18,959 INFO L495 AbstractCegarLoop]: Abstraction has 237 states and 301 transitions. [2023-11-21 20:59:18,959 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.857142857142857) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2023-11-21 20:59:18,959 INFO L276 IsEmpty]: Start isEmpty. Operand 237 states and 301 transitions. [2023-11-21 20:59:18,964 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 44 [2023-11-21 20:59:18,964 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:18,965 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:18,965 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-21 20:59:18,965 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:18,966 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:18,966 INFO L85 PathProgramCache]: Analyzing trace with hash 1425656810, now seen corresponding path program 1 times [2023-11-21 20:59:18,966 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:18,966 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [739094186] [2023-11-21 20:59:18,967 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:18,967 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:18,986 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,034 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 20:59:19,036 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,039 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2023-11-21 20:59:19,041 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,048 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 23 [2023-11-21 20:59:19,054 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,059 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:19,063 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,065 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2023-11-21 20:59:19,066 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,070 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:19,070 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:19,070 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [739094186] [2023-11-21 20:59:19,070 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [739094186] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:19,071 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:19,071 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2023-11-21 20:59:19,071 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [811520494] [2023-11-21 20:59:19,072 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:19,072 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2023-11-21 20:59:19,072 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:19,073 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2023-11-21 20:59:19,073 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2023-11-21 20:59:19,073 INFO L87 Difference]: Start difference. First operand 237 states and 301 transitions. Second operand has 5 states, 5 states have (on average 6.2) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (6), 4 states have call predecessors, (6), 1 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2023-11-21 20:59:19,328 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:19,328 INFO L93 Difference]: Finished difference Result 478 states and 605 transitions. [2023-11-21 20:59:19,329 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 8 states. [2023-11-21 20:59:19,329 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (6), 4 states have call predecessors, (6), 1 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) Word has length 43 [2023-11-21 20:59:19,330 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:19,332 INFO L225 Difference]: With dead ends: 478 [2023-11-21 20:59:19,332 INFO L226 Difference]: Without dead ends: 170 [2023-11-21 20:59:19,333 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=22, Invalid=34, Unknown=0, NotChecked=0, Total=56 [2023-11-21 20:59:19,334 INFO L413 NwaCegarLoop]: 68 mSDtfsCounter, 76 mSDsluCounter, 119 mSDsCounter, 0 mSdLazyCounter, 129 mSolverCounterSat, 43 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 81 SdHoareTripleChecker+Valid, 187 SdHoareTripleChecker+Invalid, 172 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 43 IncrementalHoareTripleChecker+Valid, 129 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:19,335 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [81 Valid, 187 Invalid, 172 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [43 Valid, 129 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-21 20:59:19,336 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 170 states. [2023-11-21 20:59:19,362 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 170 to 168. [2023-11-21 20:59:19,363 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 168 states, 112 states have (on average 1.2232142857142858) internal successors, (137), 122 states have internal predecessors, (137), 29 states have call successors, (29), 24 states have call predecessors, (29), 26 states have return successors, (39), 29 states have call predecessors, (39), 29 states have call successors, (39) [2023-11-21 20:59:19,365 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 168 states to 168 states and 205 transitions. [2023-11-21 20:59:19,365 INFO L78 Accepts]: Start accepts. Automaton has 168 states and 205 transitions. Word has length 43 [2023-11-21 20:59:19,366 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:19,366 INFO L495 AbstractCegarLoop]: Abstraction has 168 states and 205 transitions. [2023-11-21 20:59:19,366 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 6.2) internal successors, (31), 3 states have internal predecessors, (31), 3 states have call successors, (6), 4 states have call predecessors, (6), 1 states have return successors, (5), 3 states have call predecessors, (5), 3 states have call successors, (5) [2023-11-21 20:59:19,367 INFO L276 IsEmpty]: Start isEmpty. Operand 168 states and 205 transitions. [2023-11-21 20:59:19,367 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2023-11-21 20:59:19,368 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:19,368 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:19,368 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-21 20:59:19,368 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:19,369 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:19,369 INFO L85 PathProgramCache]: Analyzing trace with hash -1855445742, now seen corresponding path program 1 times [2023-11-21 20:59:19,369 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:19,369 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1163812514] [2023-11-21 20:59:19,370 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:19,370 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:19,385 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,689 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 20:59:19,691 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,755 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-21 20:59:19,756 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,768 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 20 [2023-11-21 20:59:19,772 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,777 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:19,778 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,780 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2023-11-21 20:59:19,782 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:19,792 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:19,793 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:19,793 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1163812514] [2023-11-21 20:59:19,793 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1163812514] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:19,793 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 20:59:19,794 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2023-11-21 20:59:19,794 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1716004505] [2023-11-21 20:59:19,794 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:19,794 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2023-11-21 20:59:19,794 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:19,795 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2023-11-21 20:59:19,796 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=18, Invalid=54, Unknown=0, NotChecked=0, Total=72 [2023-11-21 20:59:19,796 INFO L87 Difference]: Start difference. First operand 168 states and 205 transitions. Second operand has 9 states, 8 states have (on average 3.5) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2023-11-21 20:59:20,427 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:20,428 INFO L93 Difference]: Finished difference Result 425 states and 523 transitions. [2023-11-21 20:59:20,428 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2023-11-21 20:59:20,429 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 3.5) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) Word has length 40 [2023-11-21 20:59:20,429 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:20,434 INFO L225 Difference]: With dead ends: 425 [2023-11-21 20:59:20,434 INFO L226 Difference]: Without dead ends: 295 [2023-11-21 20:59:20,435 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 34 GetRequests, 14 SyntacticMatches, 0 SemanticMatches, 20 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 79 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=116, Invalid=346, Unknown=0, NotChecked=0, Total=462 [2023-11-21 20:59:20,440 INFO L413 NwaCegarLoop]: 61 mSDtfsCounter, 266 mSDsluCounter, 230 mSDsCounter, 0 mSdLazyCounter, 334 mSolverCounterSat, 156 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 272 SdHoareTripleChecker+Valid, 291 SdHoareTripleChecker+Invalid, 490 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 156 IncrementalHoareTripleChecker+Valid, 334 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:20,440 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [272 Valid, 291 Invalid, 490 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [156 Valid, 334 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-21 20:59:20,442 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 295 states. [2023-11-21 20:59:20,495 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 295 to 269. [2023-11-21 20:59:20,496 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 269 states, 180 states have (on average 1.2277777777777779) internal successors, (221), 197 states have internal predecessors, (221), 47 states have call successors, (47), 35 states have call predecessors, (47), 41 states have return successors, (64), 48 states have call predecessors, (64), 47 states have call successors, (64) [2023-11-21 20:59:20,499 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 269 states to 269 states and 332 transitions. [2023-11-21 20:59:20,500 INFO L78 Accepts]: Start accepts. Automaton has 269 states and 332 transitions. Word has length 40 [2023-11-21 20:59:20,500 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:20,500 INFO L495 AbstractCegarLoop]: Abstraction has 269 states and 332 transitions. [2023-11-21 20:59:20,501 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 3.5) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2023-11-21 20:59:20,501 INFO L276 IsEmpty]: Start isEmpty. Operand 269 states and 332 transitions. [2023-11-21 20:59:20,503 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 71 [2023-11-21 20:59:20,503 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:20,503 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:20,504 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-21 20:59:20,504 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:20,504 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:20,505 INFO L85 PathProgramCache]: Analyzing trace with hash 1501811118, now seen corresponding path program 1 times [2023-11-21 20:59:20,505 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:20,505 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1728550010] [2023-11-21 20:59:20,505 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:20,506 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:20,547 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,724 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 20:59:20,725 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,738 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-21 20:59:20,752 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,864 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 20:59:20,865 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,885 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 20:59:20,891 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,959 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:20,963 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,988 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2023-11-21 20:59:20,990 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,993 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2023-11-21 20:59:20,996 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:20,999 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:21,000 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:21,002 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-21 20:59:21,003 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:21,004 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 7 proven. 16 refuted. 0 times theorem prover too weak. 9 trivial. 0 not checked. [2023-11-21 20:59:21,005 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:21,005 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1728550010] [2023-11-21 20:59:21,005 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1728550010] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 20:59:21,005 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [644003613] [2023-11-21 20:59:21,005 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:21,006 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 20:59:21,006 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 20:59:21,012 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 20:59:21,018 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-21 20:59:21,125 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:21,128 INFO L262 TraceCheckSpWp]: Trace formula consists of 304 conjuncts, 18 conjunts are in the unsatisfiable core [2023-11-21 20:59:21,136 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 20:59:21,349 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 31 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-21 20:59:21,349 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-21 20:59:21,481 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 16 proven. 1 refuted. 0 times theorem prover too weak. 15 trivial. 0 not checked. [2023-11-21 20:59:21,482 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [644003613] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-21 20:59:21,482 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-21 20:59:21,482 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [13, 6, 6] total 19 [2023-11-21 20:59:21,482 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [888222273] [2023-11-21 20:59:21,483 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-21 20:59:21,483 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 19 states [2023-11-21 20:59:21,483 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:21,484 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 19 interpolants. [2023-11-21 20:59:21,485 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=43, Invalid=299, Unknown=0, NotChecked=0, Total=342 [2023-11-21 20:59:21,485 INFO L87 Difference]: Start difference. First operand 269 states and 332 transitions. Second operand has 19 states, 17 states have (on average 5.352941176470588) internal successors, (91), 14 states have internal predecessors, (91), 5 states have call successors, (19), 7 states have call predecessors, (19), 6 states have return successors, (19), 8 states have call predecessors, (19), 5 states have call successors, (19) [2023-11-21 20:59:27,245 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:27,245 INFO L93 Difference]: Finished difference Result 2047 states and 2672 transitions. [2023-11-21 20:59:27,245 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 158 states. [2023-11-21 20:59:27,246 INFO L78 Accepts]: Start accepts. Automaton has has 19 states, 17 states have (on average 5.352941176470588) internal successors, (91), 14 states have internal predecessors, (91), 5 states have call successors, (19), 7 states have call predecessors, (19), 6 states have return successors, (19), 8 states have call predecessors, (19), 5 states have call successors, (19) Word has length 70 [2023-11-21 20:59:27,248 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:27,264 INFO L225 Difference]: With dead ends: 2047 [2023-11-21 20:59:27,264 INFO L226 Difference]: Without dead ends: 1780 [2023-11-21 20:59:27,278 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 368 GetRequests, 204 SyntacticMatches, 0 SemanticMatches, 164 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 10665 ImplicationChecksByTransitivity, 3.4s TimeCoverageRelationStatistics Valid=2704, Invalid=24686, Unknown=0, NotChecked=0, Total=27390 [2023-11-21 20:59:27,280 INFO L413 NwaCegarLoop]: 154 mSDtfsCounter, 752 mSDsluCounter, 1553 mSDsCounter, 0 mSdLazyCounter, 2780 mSolverCounterSat, 411 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 769 SdHoareTripleChecker+Valid, 1707 SdHoareTripleChecker+Invalid, 3191 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 411 IncrementalHoareTripleChecker+Valid, 2780 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.1s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:27,282 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [769 Valid, 1707 Invalid, 3191 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [411 Valid, 2780 Invalid, 0 Unknown, 0 Unchecked, 2.1s Time] [2023-11-21 20:59:27,286 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1780 states. [2023-11-21 20:59:27,469 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1780 to 1497. [2023-11-21 20:59:27,473 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1497 states, 1013 states have (on average 1.1816386969397827) internal successors, (1197), 1092 states have internal predecessors, (1197), 246 states have call successors, (246), 209 states have call predecessors, (246), 237 states have return successors, (357), 247 states have call predecessors, (357), 246 states have call successors, (357) [2023-11-21 20:59:27,485 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1497 states to 1497 states and 1800 transitions. [2023-11-21 20:59:27,487 INFO L78 Accepts]: Start accepts. Automaton has 1497 states and 1800 transitions. Word has length 70 [2023-11-21 20:59:27,488 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:27,488 INFO L495 AbstractCegarLoop]: Abstraction has 1497 states and 1800 transitions. [2023-11-21 20:59:27,489 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 19 states, 17 states have (on average 5.352941176470588) internal successors, (91), 14 states have internal predecessors, (91), 5 states have call successors, (19), 7 states have call predecessors, (19), 6 states have return successors, (19), 8 states have call predecessors, (19), 5 states have call successors, (19) [2023-11-21 20:59:27,490 INFO L276 IsEmpty]: Start isEmpty. Operand 1497 states and 1800 transitions. [2023-11-21 20:59:27,496 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 74 [2023-11-21 20:59:27,496 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:27,496 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:27,512 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-21 20:59:27,700 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable7 [2023-11-21 20:59:27,701 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:27,701 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:27,701 INFO L85 PathProgramCache]: Analyzing trace with hash -250137366, now seen corresponding path program 1 times [2023-11-21 20:59:27,702 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:27,702 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1629793474] [2023-11-21 20:59:27,703 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:27,703 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:27,730 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:27,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 20:59:27,952 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:27,964 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-21 20:59:27,971 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,097 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 20:59:28,098 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,119 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 20:59:28,123 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,176 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:28,177 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,198 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 44 [2023-11-21 20:59:28,199 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,204 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 50 [2023-11-21 20:59:28,205 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,207 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 55 [2023-11-21 20:59:28,208 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,211 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 2 [2023-11-21 20:59:28,211 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,212 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 66 [2023-11-21 20:59:28,213 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,215 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 3 proven. 18 refuted. 0 times theorem prover too weak. 7 trivial. 0 not checked. [2023-11-21 20:59:28,216 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:28,216 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1629793474] [2023-11-21 20:59:28,216 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1629793474] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 20:59:28,216 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2066937664] [2023-11-21 20:59:28,216 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:28,216 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 20:59:28,216 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 20:59:28,217 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 20:59:28,240 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-21 20:59:28,319 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:28,321 INFO L262 TraceCheckSpWp]: Trace formula consists of 301 conjuncts, 23 conjunts are in the unsatisfiable core [2023-11-21 20:59:28,327 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 20:59:28,439 INFO L134 CoverageAnalysis]: Checked inductivity of 28 backedges. 17 proven. 0 refuted. 0 times theorem prover too weak. 11 trivial. 0 not checked. [2023-11-21 20:59:28,439 INFO L323 TraceCheckSpWp]: Omiting computation of backward sequence because forward sequence was already perfect [2023-11-21 20:59:28,440 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2066937664] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 20:59:28,440 INFO L185 FreeRefinementEngine]: Found 1 perfect and 1 imperfect interpolant sequences. [2023-11-21 20:59:28,440 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [15] total 19 [2023-11-21 20:59:28,440 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [552110364] [2023-11-21 20:59:28,441 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 20:59:28,441 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2023-11-21 20:59:28,441 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:28,442 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2023-11-21 20:59:28,443 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=40, Invalid=302, Unknown=0, NotChecked=0, Total=342 [2023-11-21 20:59:28,443 INFO L87 Difference]: Start difference. First operand 1497 states and 1800 transitions. Second operand has 10 states, 8 states have (on average 5.625) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (9), 3 states have call predecessors, (9), 5 states have return successors, (10), 5 states have call predecessors, (10), 3 states have call successors, (10) [2023-11-21 20:59:29,237 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:29,237 INFO L93 Difference]: Finished difference Result 2555 states and 3165 transitions. [2023-11-21 20:59:29,237 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2023-11-21 20:59:29,238 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 8 states have (on average 5.625) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (9), 3 states have call predecessors, (9), 5 states have return successors, (10), 5 states have call predecessors, (10), 3 states have call successors, (10) Word has length 73 [2023-11-21 20:59:29,239 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:29,251 INFO L225 Difference]: With dead ends: 2555 [2023-11-21 20:59:29,251 INFO L226 Difference]: Without dead ends: 1748 [2023-11-21 20:59:29,255 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 125 GetRequests, 92 SyntacticMatches, 0 SemanticMatches, 33 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 159 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=165, Invalid=1025, Unknown=0, NotChecked=0, Total=1190 [2023-11-21 20:59:29,257 INFO L413 NwaCegarLoop]: 106 mSDtfsCounter, 99 mSDsluCounter, 489 mSDsCounter, 0 mSdLazyCounter, 647 mSolverCounterSat, 47 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 105 SdHoareTripleChecker+Valid, 595 SdHoareTripleChecker+Invalid, 694 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 47 IncrementalHoareTripleChecker+Valid, 647 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:29,258 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [105 Valid, 595 Invalid, 694 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [47 Valid, 647 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-21 20:59:29,260 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1748 states. [2023-11-21 20:59:29,440 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1748 to 1603. [2023-11-21 20:59:29,444 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 1603 states, 1082 states have (on average 1.1691312384473198) internal successors, (1265), 1170 states have internal predecessors, (1265), 267 states have call successors, (267), 230 states have call predecessors, (267), 253 states have return successors, (408), 258 states have call predecessors, (408), 267 states have call successors, (408) [2023-11-21 20:59:29,455 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 1603 states to 1603 states and 1940 transitions. [2023-11-21 20:59:29,456 INFO L78 Accepts]: Start accepts. Automaton has 1603 states and 1940 transitions. Word has length 73 [2023-11-21 20:59:29,458 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:29,458 INFO L495 AbstractCegarLoop]: Abstraction has 1603 states and 1940 transitions. [2023-11-21 20:59:29,458 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 8 states have (on average 5.625) internal successors, (45), 8 states have internal predecessors, (45), 3 states have call successors, (9), 3 states have call predecessors, (9), 5 states have return successors, (10), 5 states have call predecessors, (10), 3 states have call successors, (10) [2023-11-21 20:59:29,459 INFO L276 IsEmpty]: Start isEmpty. Operand 1603 states and 1940 transitions. [2023-11-21 20:59:29,465 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 104 [2023-11-21 20:59:29,466 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 20:59:29,466 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:29,493 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-21 20:59:29,686 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable8 [2023-11-21 20:59:29,686 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 20:59:29,687 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 20:59:29,687 INFO L85 PathProgramCache]: Analyzing trace with hash -463562760, now seen corresponding path program 1 times [2023-11-21 20:59:29,687 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 20:59:29,687 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1851413303] [2023-11-21 20:59:29,687 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:29,687 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 20:59:29,713 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,848 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 20:59:29,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,859 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-21 20:59:29,863 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,888 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 20:59:29,889 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,896 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 20:59:29,898 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,901 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:29,903 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,905 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 42 [2023-11-21 20:59:29,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,950 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 20:59:29,951 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,952 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 20:59:29,954 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,966 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 12 [2023-11-21 20:59:29,967 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,969 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 18 [2023-11-21 20:59:29,970 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,972 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 77 [2023-11-21 20:59:29,973 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,975 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 83 [2023-11-21 20:59:29,978 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,982 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 20:59:29,983 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,984 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 96 [2023-11-21 20:59:29,986 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:29,987 INFO L134 CoverageAnalysis]: Checked inductivity of 87 backedges. 42 proven. 1 refuted. 0 times theorem prover too weak. 44 trivial. 0 not checked. [2023-11-21 20:59:29,988 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 20:59:29,988 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1851413303] [2023-11-21 20:59:29,988 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1851413303] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 20:59:29,988 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [1472683221] [2023-11-21 20:59:29,988 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 20:59:29,989 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 20:59:29,989 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 20:59:29,990 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 20:59:30,012 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2023-11-21 20:59:30,121 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 20:59:30,124 INFO L262 TraceCheckSpWp]: Trace formula consists of 402 conjuncts, 26 conjunts are in the unsatisfiable core [2023-11-21 20:59:30,131 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 20:59:30,612 INFO L134 CoverageAnalysis]: Checked inductivity of 87 backedges. 29 proven. 56 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 20:59:30,614 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-21 20:59:31,200 INFO L134 CoverageAnalysis]: Checked inductivity of 87 backedges. 54 proven. 5 refuted. 0 times theorem prover too weak. 28 trivial. 0 not checked. [2023-11-21 20:59:31,200 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [1472683221] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-21 20:59:31,201 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-21 20:59:31,201 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 13, 11] total 28 [2023-11-21 20:59:31,201 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [927803194] [2023-11-21 20:59:31,201 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-21 20:59:31,204 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 28 states [2023-11-21 20:59:31,204 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 20:59:31,205 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 28 interpolants. [2023-11-21 20:59:31,206 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=109, Invalid=647, Unknown=0, NotChecked=0, Total=756 [2023-11-21 20:59:31,206 INFO L87 Difference]: Start difference. First operand 1603 states and 1940 transitions. Second operand has 28 states, 27 states have (on average 6.185185185185185) internal successors, (167), 25 states have internal predecessors, (167), 14 states have call successors, (39), 8 states have call predecessors, (39), 11 states have return successors, (36), 15 states have call predecessors, (36), 13 states have call successors, (36) [2023-11-21 20:59:37,215 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 20:59:37,215 INFO L93 Difference]: Finished difference Result 4033 states and 4996 transitions. [2023-11-21 20:59:37,215 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 121 states. [2023-11-21 20:59:37,216 INFO L78 Accepts]: Start accepts. Automaton has has 28 states, 27 states have (on average 6.185185185185185) internal successors, (167), 25 states have internal predecessors, (167), 14 states have call successors, (39), 8 states have call predecessors, (39), 11 states have return successors, (36), 15 states have call predecessors, (36), 13 states have call successors, (36) Word has length 103 [2023-11-21 20:59:37,216 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 20:59:37,218 INFO L225 Difference]: With dead ends: 4033 [2023-11-21 20:59:37,218 INFO L226 Difference]: Without dead ends: 0 [2023-11-21 20:59:37,236 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 402 GetRequests, 253 SyntacticMatches, 4 SemanticMatches, 145 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7423 ImplicationChecksByTransitivity, 4.0s TimeCoverageRelationStatistics Valid=2795, Invalid=18667, Unknown=0, NotChecked=0, Total=21462 [2023-11-21 20:59:37,237 INFO L413 NwaCegarLoop]: 111 mSDtfsCounter, 1229 mSDsluCounter, 873 mSDsCounter, 0 mSdLazyCounter, 2501 mSolverCounterSat, 901 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1229 SdHoareTripleChecker+Valid, 984 SdHoareTripleChecker+Invalid, 3402 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 901 IncrementalHoareTripleChecker+Valid, 2501 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.9s IncrementalHoareTripleChecker+Time [2023-11-21 20:59:37,238 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1229 Valid, 984 Invalid, 3402 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [901 Valid, 2501 Invalid, 0 Unknown, 0 Unchecked, 1.9s Time] [2023-11-21 20:59:37,239 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-21 20:59:37,239 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-21 20:59:37,239 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-21 20:59:37,239 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-21 20:59:37,240 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 103 [2023-11-21 20:59:37,240 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 20:59:37,240 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-21 20:59:37,240 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 28 states, 27 states have (on average 6.185185185185185) internal successors, (167), 25 states have internal predecessors, (167), 14 states have call successors, (39), 8 states have call predecessors, (39), 11 states have return successors, (36), 15 states have call predecessors, (36), 13 states have call successors, (36) [2023-11-21 20:59:37,241 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-21 20:59:37,241 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-21 20:59:37,243 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-21 20:59:37,268 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2023-11-21 20:59:37,456 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2023-11-21 20:59:37,458 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-21 20:59:49,588 INFO L899 garLoopResultBuilder]: For program point deactivatePumpEXIT(lines 185 192) no Hoare annotation was computed. [2023-11-21 20:59:49,589 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 185 192) the Hoare annotation is: (or (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= 0 ~systemActive~0)) [2023-11-21 20:59:49,589 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 101 107) no Hoare annotation was computed. [2023-11-21 20:59:49,589 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 101 107) the Hoare annotation is: true [2023-11-21 20:59:49,589 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 932 943) the Hoare annotation is: (let ((.cse2 (= ~methaneLevelCritical~0 0)) (.cse5 (= |old(~methaneLevelCritical~0)| 0))) (let ((.cse1 (not .cse5)) (.cse4 (not (= 2 ~waterLevel~0))) (.cse0 (< 2 ~waterLevel~0)) (.cse7 (not (= ~pumpRunning~0 0))) (.cse3 (not (= 1 ~systemActive~0))) (.cse6 (not .cse2))) (and (or .cse0 .cse1 .cse2 .cse3 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (or .cse3 .cse4 .cse5 .cse6) (or (< ~pumpRunning~0 1) .cse1 .cse2 .cse3 .cse4) (or (not (= ~waterLevel~0 1)) .cse1 .cse7 .cse2 .cse3) (or .cse1 .cse7 .cse2 .cse3 .cse4) (or .cse0 .cse7 .cse3 .cse5 .cse6)))) [2023-11-21 20:59:49,590 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 932 943) no Hoare annotation was computed. [2023-11-21 20:59:49,590 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 355 384) no Hoare annotation was computed. [2023-11-21 20:59:49,590 INFO L899 garLoopResultBuilder]: For program point L380(lines 355 384) no Hoare annotation was computed. [2023-11-21 20:59:49,590 INFO L899 garLoopResultBuilder]: For program point L376(line 376) no Hoare annotation was computed. [2023-11-21 20:59:49,590 INFO L899 garLoopResultBuilder]: For program point L369(lines 369 373) no Hoare annotation was computed. [2023-11-21 20:59:49,590 INFO L902 garLoopResultBuilder]: At program point L369-1(lines 369 373) the Hoare annotation is: true [2023-11-21 20:59:49,591 INFO L902 garLoopResultBuilder]: At program point L365-2(lines 365 379) the Hoare annotation is: true [2023-11-21 20:59:49,591 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 355 384) the Hoare annotation is: true [2023-11-21 20:59:49,591 INFO L902 garLoopResultBuilder]: At program point L361(line 361) the Hoare annotation is: true [2023-11-21 20:59:49,591 INFO L899 garLoopResultBuilder]: For program point L361-1(line 361) no Hoare annotation was computed. [2023-11-21 20:59:49,592 INFO L895 garLoopResultBuilder]: At program point L886(line 886) the Hoare annotation is: (let ((.cse15 (= |old(~waterLevel~0)| ~waterLevel~0))) (let ((.cse16 (= ~switchedOnBeforeTS~0 0)) (.cse6 (= ~pumpRunning~0 0)) (.cse11 (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |old(~waterLevel~0)|)) (and (<= |old(~waterLevel~0)| 0) .cse15))) (.cse12 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| ~waterLevel~0)) (.cse8 (= ~methaneLevelCritical~0 0))) (let ((.cse2 (not (= |old(~waterLevel~0)| 2))) (.cse1 (not .cse8)) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse13 (< 2 |old(~waterLevel~0)|)) (.cse10 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse0 (not (= 1 ~systemActive~0))) (.cse9 (and (not .cse16) .cse6 .cse11 .cse12)) (.cse14 (= |old(~switchedOnBeforeTS~0)| 0)) (.cse17 (< 1 |old(~waterLevel~0)|)) (.cse5 (not (= |old(~pumpRunning~0)| 0))) (.cse7 (not (= 0 ~systemActive~0)))) (and (or .cse0 .cse1 .cse2 (and .cse3 (= ~waterLevel~0 1) .cse4 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~9#1| 1))) (or .cse5 .cse6 .cse7) (or .cse8 .cse0 .cse9 .cse2) (or .cse10 .cse0 .cse1 (and .cse3 .cse11 .cse12 .cse4) .cse13 .cse14) (or .cse5 (and .cse6 .cse12 .cse15 .cse16) .cse0 .cse13) (or .cse17 .cse10 .cse8 .cse0 .cse9 .cse14) (or .cse17 .cse5 (<= ~waterLevel~0 1) .cse7))))) [2023-11-21 20:59:49,592 INFO L899 garLoopResultBuilder]: For program point L886-1(line 886) no Hoare annotation was computed. [2023-11-21 20:59:49,592 INFO L899 garLoopResultBuilder]: For program point L81-2(lines 77 99) no Hoare annotation was computed. [2023-11-21 20:59:49,592 INFO L899 garLoopResultBuilder]: For program point L143(lines 143 151) no Hoare annotation was computed. [2023-11-21 20:59:49,592 INFO L899 garLoopResultBuilder]: For program point L139(lines 139 156) no Hoare annotation was computed. [2023-11-21 20:59:49,593 INFO L895 garLoopResultBuilder]: At program point L871(line 871) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (< 2 |old(~waterLevel~0)|)) (.cse3 (not (= 1 ~systemActive~0))) (.cse5 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|))) (and (or .cse0 (and .cse1 .cse2) (not (= 0 ~systemActive~0))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse3 .cse4 (and .cse5 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (or (and .cse1 .cse5 .cse2) .cse0 .cse3 .cse4) (or .cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= 2 ~waterLevel~0) .cse5) (not (= |old(~waterLevel~0)| 2))))) [2023-11-21 20:59:49,593 INFO L899 garLoopResultBuilder]: For program point L871-1(line 871) no Hoare annotation was computed. [2023-11-21 20:59:49,593 INFO L899 garLoopResultBuilder]: For program point L888(lines 888 898) no Hoare annotation was computed. [2023-11-21 20:59:49,593 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2023-11-21 20:59:49,594 INFO L895 garLoopResultBuilder]: At program point L149(line 149) the Hoare annotation is: (let ((.cse4 (= ~methaneLevelCritical~0 0)) (.cse7 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse1 (not (= 1 ~systemActive~0))) (.cse3 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (<= 1 |old(~waterLevel~0)|)) (.cse5 (= |timeShift_processEnvironment_~tmp~1#1| 0)) (.cse6 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse8 (< 2 |old(~waterLevel~0)|)) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (not (= |old(~waterLevel~0)| 1)) .cse2)) (or (and .cse3 (not (= ~pumpRunning~0 0)) .cse4 .cse5 (= ~waterLevel~0 1) .cse6) .cse1 (not (= |old(~waterLevel~0)| 2))) (or .cse7 .cse4 .cse1 .cse8) (or .cse7 .cse1 (and .cse3 (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2) (and (<= |old(~waterLevel~0)| 0) (= |old(~waterLevel~0)| ~waterLevel~0))) .cse5 .cse6) .cse8) (or .cse0 (not (= 0 ~systemActive~0))))) [2023-11-21 20:59:49,594 INFO L899 garLoopResultBuilder]: For program point L884(lines 884 901) no Hoare annotation was computed. [2023-11-21 20:59:49,594 INFO L899 garLoopResultBuilder]: For program point L884-1(lines 876 904) no Hoare annotation was computed. [2023-11-21 20:59:49,594 INFO L895 garLoopResultBuilder]: At program point L145(line 145) the Hoare annotation is: (let ((.cse2 (<= 1 |old(~waterLevel~0)|)) (.cse4 (= 1 ~systemActive~0))) (let ((.cse1 (not .cse4)) (.cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= ~pumpRunning~0 0)) (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2) (and (<= |old(~waterLevel~0)| 0) (= |old(~waterLevel~0)| ~waterLevel~0))) .cse4 (not (= ~methaneLevelCritical~0 0)) (<= ~waterLevel~0 2) (= |timeShift_processEnvironment_~tmp~1#1| ~methaneLevelCritical~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse0 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and (not (= |old(~waterLevel~0)| 1)) .cse2)) (or .cse1 (not (= |old(~waterLevel~0)| 2)) .cse3) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse1 (< 2 |old(~waterLevel~0)|) .cse3) (or .cse0 (not (= 0 ~systemActive~0)))))) [2023-11-21 20:59:49,595 INFO L895 garLoopResultBuilder]: At program point L141(line 141) the Hoare annotation is: (let ((.cse1 (not (= |old(~waterLevel~0)| 2))) (.cse2 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse3 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse0 (not (= 1 ~systemActive~0))) (.cse5 (<= 1 |old(~waterLevel~0)|)) (.cse4 (not (= |old(~pumpRunning~0)| 0)))) (and (or .cse0 .cse1 (and .cse2 (= ~waterLevel~0 1) .cse3)) (or .cse4 .cse0 .cse1) (or (< 1 |old(~waterLevel~0)|) (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 (and .cse2 (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse5) (= |old(~waterLevel~0)| ~waterLevel~0)) (<= ~waterLevel~0 0) .cse3)) (or .cse4 .cse0 (and (not (= |old(~waterLevel~0)| 1)) .cse5)) (or .cse4 (not (= 0 ~systemActive~0))))) [2023-11-21 20:59:49,595 INFO L899 garLoopResultBuilder]: For program point L141-1(line 141) no Hoare annotation was computed. [2023-11-21 20:59:49,595 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 74 100) the Hoare annotation is: (let ((.cse1 (= ~pumpRunning~0 0)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse4 (< 2 |old(~waterLevel~0)|)) (.cse3 (not (= 1 ~systemActive~0))) (.cse5 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|))) (and (or .cse0 (and .cse1 .cse2) (not (= 0 ~systemActive~0))) (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse3 .cse4 (and .cse5 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (or (and .cse1 .cse5 .cse2) .cse0 .cse3 .cse4) (or .cse3 (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= 2 ~waterLevel~0) .cse5) (not (= |old(~waterLevel~0)| 2))))) [2023-11-21 20:59:49,596 INFO L895 garLoopResultBuilder]: At program point L154(line 154) the Hoare annotation is: (let ((.cse3 (= |old(~pumpRunning~0)| 0))) (let ((.cse1 (< 2 |old(~waterLevel~0)|)) (.cse0 (not (= 1 ~systemActive~0))) (.cse2 (not .cse3))) (and (or (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse0 .cse1 (= |old(~switchedOnBeforeTS~0)| 0)) (or .cse2 .cse0 .cse1 (and (= ~pumpRunning~0 0) (= |old(~waterLevel~0)| ~waterLevel~0) (= ~switchedOnBeforeTS~0 0))) (or .cse0 .cse3 (not (= |old(~waterLevel~0)| 2))) (or .cse2 (not (= 0 ~systemActive~0)))))) [2023-11-21 20:59:49,596 INFO L899 garLoopResultBuilder]: For program point L154-1(lines 135 159) no Hoare annotation was computed. [2023-11-21 20:59:49,596 INFO L899 garLoopResultBuilder]: For program point L889(lines 889 895) no Hoare annotation was computed. [2023-11-21 20:59:49,596 INFO L899 garLoopResultBuilder]: For program point L88-1(lines 88 94) no Hoare annotation was computed. [2023-11-21 20:59:49,596 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 74 100) no Hoare annotation was computed. [2023-11-21 20:59:49,596 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2023-11-21 20:59:49,597 INFO L895 garLoopResultBuilder]: At program point L345(lines 296 346) the Hoare annotation is: false [2023-11-21 20:59:49,597 INFO L899 garLoopResultBuilder]: For program point L333(lines 333 339) no Hoare annotation was computed. [2023-11-21 20:59:49,597 INFO L895 garLoopResultBuilder]: At program point L333-2(lines 327 340) the Hoare annotation is: (let ((.cse0 (= 1 ~systemActive~0)) (.cse2 (= ~pumpRunning~0 0)) (.cse1 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and (= 2 ~waterLevel~0) .cse0 .cse1) (and .cse2 .cse0 .cse1 (or (< ~waterLevel~0 1) (= ~waterLevel~0 1))) (and (<= ~waterLevel~0 1) .cse0 .cse1 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and .cse2 .cse1 (= 0 ~systemActive~0)))) [2023-11-21 20:59:49,597 INFO L899 garLoopResultBuilder]: For program point L317(lines 317 323) no Hoare annotation was computed. [2023-11-21 20:59:49,597 INFO L899 garLoopResultBuilder]: For program point L317-1(lines 317 323) no Hoare annotation was computed. [2023-11-21 20:59:49,598 INFO L899 garLoopResultBuilder]: For program point L441(lines 441 448) no Hoare annotation was computed. [2023-11-21 20:59:49,598 INFO L899 garLoopResultBuilder]: For program point L441-2(lines 441 448) no Hoare annotation was computed. [2023-11-21 20:59:49,598 INFO L895 garLoopResultBuilder]: At program point L342(lines 297 344) the Hoare annotation is: (let ((.cse5 (= ~methaneLevelCritical~0 0))) (let ((.cse1 (<= ~waterLevel~0 1)) (.cse3 (not .cse5)) (.cse0 (= ~pumpRunning~0 0)) (.cse6 (= 2 ~waterLevel~0)) (.cse2 (= 1 ~systemActive~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse5 .cse1 .cse2 .cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and .cse6 .cse2 .cse3 .cse4) (and .cse0 .cse2 .cse4 (= |ULTIMATE.start_main_~tmp~5#1| 1) (= ~waterLevel~0 1)) (and .cse0 .cse6 .cse2 .cse4) (and .cse0 .cse4 (= 0 ~systemActive~0)) (and (<= 1 ~pumpRunning~0) .cse6 .cse2 .cse4)))) [2023-11-21 20:59:49,598 INFO L895 garLoopResultBuilder]: At program point L309(line 309) the Hoare annotation is: (let ((.cse5 (= ~methaneLevelCritical~0 0))) (let ((.cse1 (<= ~waterLevel~0 1)) (.cse3 (not .cse5)) (.cse0 (= ~pumpRunning~0 0)) (.cse7 (= ~waterLevel~0 1)) (.cse8 (<= 1 ~pumpRunning~0)) (.cse6 (= 2 ~waterLevel~0)) (.cse2 (= 1 ~systemActive~0)) (.cse4 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse5 .cse1 .cse2 .cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (and .cse6 .cse2 .cse3 .cse4) (and .cse0 .cse2 .cse4 (= |ULTIMATE.start_main_~tmp~5#1| 1) .cse7) (and .cse0 .cse6 .cse2 .cse4) (and .cse0 .cse4 (= 0 ~systemActive~0)) (and .cse8 .cse5 .cse2 .cse4 .cse7) (and .cse8 .cse6 .cse2 .cse4)))) [2023-11-21 20:59:49,598 INFO L899 garLoopResultBuilder]: For program point L272(lines 272 278) no Hoare annotation was computed. [2023-11-21 20:59:49,599 INFO L899 garLoopResultBuilder]: For program point L272-1(lines 272 278) no Hoare annotation was computed. [2023-11-21 20:59:49,599 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-21 20:59:49,599 INFO L899 garLoopResultBuilder]: For program point L298(lines 297 344) no Hoare annotation was computed. [2023-11-21 20:59:49,599 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-21 20:59:49,599 INFO L899 garLoopResultBuilder]: For program point L327(lines 327 340) no Hoare annotation was computed. [2023-11-21 20:59:49,600 INFO L895 garLoopResultBuilder]: At program point L319(line 319) the Hoare annotation is: (let ((.cse8 (= ~methaneLevelCritical~0 0)) (.cse5 (= ~pumpRunning~0 0))) (let ((.cse0 (not .cse5)) (.cse6 (<= ~waterLevel~0 1)) (.cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse7 (not .cse8)) (.cse9 (= ~waterLevel~0 1)) (.cse1 (= 2 ~waterLevel~0)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0))) (or (and .cse0 .cse1 .cse2 .cse3 .cse4) (and .cse5 .cse6 .cse2 .cse7 .cse3) (and .cse0 .cse8 .cse6 .cse2 .cse3 .cse4) (and .cse1 .cse2 .cse7 .cse3) (and .cse5 .cse2 .cse3 (= |ULTIMATE.start_main_~tmp~5#1| 1) .cse9) (and .cse5 .cse2 .cse3 (or (< ~waterLevel~0 1) .cse9) (= ~switchedOnBeforeTS~0 0)) (and .cse5 .cse1 .cse2 .cse3) (and .cse5 .cse3 (= 0 ~systemActive~0)) (and (<= 1 ~pumpRunning~0) .cse1 .cse2 .cse3)))) [2023-11-21 20:59:49,600 INFO L899 garLoopResultBuilder]: For program point L348(lines 287 352) no Hoare annotation was computed. [2023-11-21 20:59:49,600 INFO L899 garLoopResultBuilder]: For program point L307(lines 307 313) no Hoare annotation was computed. [2023-11-21 20:59:49,600 INFO L899 garLoopResultBuilder]: For program point L307-1(lines 307 313) no Hoare annotation was computed. [2023-11-21 20:59:49,600 INFO L895 garLoopResultBuilder]: At program point L274(line 274) the Hoare annotation is: (and (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0) (not (= 0 ~systemActive~0))) [2023-11-21 20:59:49,601 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 920 931) no Hoare annotation was computed. [2023-11-21 20:59:49,601 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 920 931) the Hoare annotation is: (let ((.cse9 (= ~methaneLevelCritical~0 0))) (let ((.cse5 (not .cse9)) (.cse8 (= 2 ~waterLevel~0)) (.cse10 (not (= |old(~waterLevel~0)| 2))) (.cse3 (< 1 |old(~waterLevel~0)|)) (.cse1 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse0 (not (= ~pumpRunning~0 0))) (.cse6 (not (= |old(~waterLevel~0)| 1))) (.cse4 (not (= 1 ~systemActive~0))) (.cse2 (= 0 ~systemActive~0)) (.cse7 (= ~waterLevel~0 1))) (and (or .cse0 .cse1 (not .cse2)) (or .cse3 .cse4 .cse5 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) .cse1) (or (< ~pumpRunning~0 1) .cse6 .cse4 .cse5 .cse7) (or .cse8 .cse4 (and (<= ~pumpRunning~0 0) .cse9) .cse10) (or .cse0 .cse8 .cse4 .cse10 .cse2) (or .cse3 .cse0 .cse9 .cse4 .cse1 .cse2) (or .cse0 .cse6 .cse4 .cse2 .cse7)))) [2023-11-21 20:59:49,601 INFO L895 garLoopResultBuilder]: At program point L128(line 128) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1 .cse2) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2))) [2023-11-21 20:59:49,601 INFO L899 garLoopResultBuilder]: For program point L128-1(lines 109 133) no Hoare annotation was computed. [2023-11-21 20:59:49,601 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 109 133) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (not (= 1 ~systemActive~0))) (.cse3 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 .cse1 .cse2 (and (not (= ~waterLevel~0 1)) (<= 1 ~waterLevel~0)) .cse3) (or .cse0 .cse1 .cse2 (not (= 2 ~waterLevel~0)) .cse3) (or (< 2 ~waterLevel~0) .cse2 (not (= ~methaneLevelCritical~0 0)) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse3))) [2023-11-21 20:59:49,602 INFO L895 garLoopResultBuilder]: At program point L123(line 123) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1 (and (= ~pumpRunning~0 0) (or (= 2 ~waterLevel~0) (= |processEnvironment__wrappee__methaneQuery_~tmp~0#1| 0))) .cse2) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= ~switchedOnBeforeTS~0 0) .cse2))) [2023-11-21 20:59:49,602 INFO L899 garLoopResultBuilder]: For program point L117(lines 117 125) no Hoare annotation was computed. [2023-11-21 20:59:49,602 INFO L899 garLoopResultBuilder]: For program point L113(lines 113 130) no Hoare annotation was computed. [2023-11-21 20:59:49,602 INFO L895 garLoopResultBuilder]: At program point L173(line 173) the Hoare annotation is: (let ((.cse0 (< 2 ~waterLevel~0)) (.cse1 (not (= 1 ~systemActive~0))) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or .cse0 (not (= |old(~pumpRunning~0)| 0)) .cse1 (and (= ~pumpRunning~0 0) (= 2 ~waterLevel~0)) .cse2) (or .cse0 .cse1 (not (= ~methaneLevelCritical~0 0)) (= ~switchedOnBeforeTS~0 0) .cse2))) [2023-11-21 20:59:49,602 INFO L899 garLoopResultBuilder]: For program point L173-1(line 173) no Hoare annotation was computed. [2023-11-21 20:59:49,603 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__methaneQueryEXIT(lines 109 133) no Hoare annotation was computed. [2023-11-21 20:59:49,603 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 204 212) no Hoare annotation was computed. [2023-11-21 20:59:49,603 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 204 212) the Hoare annotation is: true [2023-11-21 20:59:49,603 INFO L899 garLoopResultBuilder]: For program point isMethaneAlarmEXIT(lines 193 203) no Hoare annotation was computed. [2023-11-21 20:59:49,603 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 193 203) the Hoare annotation is: true [2023-11-21 20:59:49,606 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 20:59:49,608 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-21 20:59:49,621 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.11 08:59:49 BoogieIcfgContainer [2023-11-21 20:59:49,621 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-21 20:59:49,622 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-21 20:59:49,622 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-21 20:59:49,623 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-21 20:59:49,623 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 08:59:16" (3/4) ... [2023-11-21 20:59:49,626 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-21 20:59:49,629 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2023-11-21 20:59:49,630 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-21 20:59:49,630 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-21 20:59:49,630 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-21 20:59:49,630 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-21 20:59:49,631 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-21 20:59:49,631 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2023-11-21 20:59:49,631 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2023-11-21 20:59:49,631 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2023-11-21 20:59:49,640 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 46 nodes and edges [2023-11-21 20:59:49,640 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 11 nodes and edges [2023-11-21 20:59:49,641 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-21 20:59:49,642 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-21 20:59:49,642 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-21 20:59:49,762 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/witness.graphml [2023-11-21 20:59:49,763 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/witness.yml [2023-11-21 20:59:49,763 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-21 20:59:49,763 INFO L158 Benchmark]: Toolchain (without parser) took 34674.50ms. Allocated memory was 176.2MB in the beginning and 545.3MB in the end (delta: 369.1MB). Free memory was 128.9MB in the beginning and 333.6MB in the end (delta: -204.6MB). Peak memory consumption was 166.6MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,764 INFO L158 Benchmark]: CDTParser took 0.30ms. Allocated memory is still 138.4MB. Free memory is still 80.5MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-21 20:59:49,764 INFO L158 Benchmark]: CACSL2BoogieTranslator took 573.03ms. Allocated memory is still 176.2MB. Free memory was 128.9MB in the beginning and 109.3MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,764 INFO L158 Benchmark]: Boogie Procedure Inliner took 66.62ms. Allocated memory is still 176.2MB. Free memory was 109.3MB in the beginning and 106.4MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,765 INFO L158 Benchmark]: Boogie Preprocessor took 69.25ms. Allocated memory is still 176.2MB. Free memory was 106.4MB in the beginning and 104.3MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,765 INFO L158 Benchmark]: RCFGBuilder took 655.13ms. Allocated memory is still 176.2MB. Free memory was 104.3MB in the beginning and 76.5MB in the end (delta: 27.8MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,766 INFO L158 Benchmark]: TraceAbstraction took 33160.87ms. Allocated memory was 176.2MB in the beginning and 545.3MB in the end (delta: 369.1MB). Free memory was 75.7MB in the beginning and 342.0MB in the end (delta: -266.2MB). Peak memory consumption was 210.6MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,766 INFO L158 Benchmark]: Witness Printer took 140.65ms. Allocated memory is still 545.3MB. Free memory was 342.0MB in the beginning and 333.6MB in the end (delta: 8.4MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. [2023-11-21 20:59:49,768 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.30ms. Allocated memory is still 138.4MB. Free memory is still 80.5MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 573.03ms. Allocated memory is still 176.2MB. Free memory was 128.9MB in the beginning and 109.3MB in the end (delta: 19.7MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 66.62ms. Allocated memory is still 176.2MB. Free memory was 109.3MB in the beginning and 106.4MB in the end (delta: 2.9MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 69.25ms. Allocated memory is still 176.2MB. Free memory was 106.4MB in the beginning and 104.3MB in the end (delta: 2.1MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 655.13ms. Allocated memory is still 176.2MB. Free memory was 104.3MB in the beginning and 76.5MB in the end (delta: 27.8MB). Peak memory consumption was 27.3MB. Max. memory is 16.1GB. * TraceAbstraction took 33160.87ms. Allocated memory was 176.2MB in the beginning and 545.3MB in the end (delta: 369.1MB). Free memory was 75.7MB in the beginning and 342.0MB in the end (delta: -266.2MB). Peak memory consumption was 210.6MB. Max. memory is 16.1GB. * Witness Printer took 140.65ms. Allocated memory is still 545.3MB. Free memory was 342.0MB in the beginning and 333.6MB in the end (delta: 8.4MB). Peak memory consumption was 6.3MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] - GenericResultAtLocation [Line: 58]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [58] - GenericResultAtLocation [Line: 283]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [283] - GenericResultAtLocation [Line: 353]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [353] - GenericResultAtLocation [Line: 454]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [454] - GenericResultAtLocation [Line: 820]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [820] - GenericResultAtLocation [Line: 855]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [855] - GenericResultAtLocation [Line: 905]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [905] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 72 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 33.1s, OverallIterations: 10, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 14.6s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 12.1s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2752 SdHoareTripleChecker+Valid, 5.4s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2706 mSDsluCounter, 4633 SdHoareTripleChecker+Invalid, 4.5s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 3784 mSDsCounter, 1634 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 6820 IncrementalHoareTripleChecker+Invalid, 8454 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1634 mSolverCounterUnsat, 849 mSDtfsCounter, 6820 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1001 GetRequests, 609 SyntacticMatches, 4 SemanticMatches, 388 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 18339 ImplicationChecksByTransitivity, 8.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=1603occurred in iteration=9, InterpolantAutomatonStates: 356, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.7s AutomataMinimizationTime, 10 MinimizatonAttempts, 485 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 27 LocationsWithAnnotation, 2574 PreInvPairs, 2869 NumberOfFragments, 1628 HoareAnnotationTreeSize, 2574 FomulaSimplifications, 34775 FormulaSimplificationTreeSizeReduction, 2.4s HoareSimplificationTime, 27 FomulaSimplificationsInter, 43257 FormulaSimplificationTreeSizeReductionInter, 9.6s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 4.1s InterpolantComputationTime, 708 NumberOfCodeBlocks, 708 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 866 ConstructedInterpolants, 0 QuantifiedInterpolants, 2395 SizeOfPredicates, 22 NumberOfNonLiveVariables, 1007 ConjunctsInSsa, 67 ConjunctsInUnsatCore, 15 InterpolantComputations, 8 PerfectInterpolantSequences, 329/427 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 365]: Loop Invariant Derived loop invariant: 1 - InvariantResult [Line: 297]: Loop Invariant Derived loop invariant: (((((((((((pumpRunning == 0) && (waterLevel <= 1)) && (1 == systemActive)) && !((methaneLevelCritical == 0))) && (splverifierCounter == 0)) || (((((methaneLevelCritical == 0) && (waterLevel <= 1)) && (1 == systemActive)) && (splverifierCounter == 0)) && (pumpRunning == switchedOnBeforeTS))) || ((((2 == waterLevel) && (1 == systemActive)) && !((methaneLevelCritical == 0))) && (splverifierCounter == 0))) || (((((pumpRunning == 0) && (1 == systemActive)) && (splverifierCounter == 0)) && (tmp == 1)) && (waterLevel == 1))) || ((((pumpRunning == 0) && (2 == waterLevel)) && (1 == systemActive)) && (splverifierCounter == 0))) || (((pumpRunning == 0) && (splverifierCounter == 0)) && (0 == systemActive))) || ((((1 <= pumpRunning) && (2 == waterLevel)) && (1 == systemActive)) && (splverifierCounter == 0))) - InvariantResult [Line: 296]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 193]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-21 20:59:49,808 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_9d042007-7b81-4973-af18-e631181fcc2e/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Forceful destruction successful, exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE