./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 527bcce2 Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/config/AutomizerReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/config/svcomp-Reach-32bit-Automizer_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx --witnessprinter.witness.filename witness --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Automizer --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 9cfe95aaca007f6467395901a9efc89e5ad27f0fc32ae7ae8a1fe4e27a1f35c1 --- Real Ultimate output --- This is Ultimate 0.2.3-dev-527bcce [2023-11-21 22:12:01,960 INFO L188 SettingsManager]: Resetting all preferences to default values... [2023-11-21 22:12:02,075 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/config/svcomp-Reach-32bit-Automizer_Default.epf [2023-11-21 22:12:02,086 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2023-11-21 22:12:02,087 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2023-11-21 22:12:02,125 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2023-11-21 22:12:02,127 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2023-11-21 22:12:02,128 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2023-11-21 22:12:02,129 INFO L151 SettingsManager]: Preferences of Boogie Preprocessor differ from their defaults: [2023-11-21 22:12:02,134 INFO L153 SettingsManager]: * Use memory slicer=true [2023-11-21 22:12:02,134 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2023-11-21 22:12:02,136 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2023-11-21 22:12:02,136 INFO L151 SettingsManager]: Preferences of BlockEncodingV2 differ from their defaults: [2023-11-21 22:12:02,138 INFO L153 SettingsManager]: * Create parallel compositions if possible=false [2023-11-21 22:12:02,146 INFO L153 SettingsManager]: * Use SBE=true [2023-11-21 22:12:02,146 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2023-11-21 22:12:02,147 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2023-11-21 22:12:02,147 INFO L153 SettingsManager]: * sizeof long=4 [2023-11-21 22:12:02,147 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2023-11-21 22:12:02,148 INFO L153 SettingsManager]: * sizeof POINTER=4 [2023-11-21 22:12:02,148 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2023-11-21 22:12:02,149 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2023-11-21 22:12:02,149 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2023-11-21 22:12:02,149 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2023-11-21 22:12:02,150 INFO L153 SettingsManager]: * sizeof long double=12 [2023-11-21 22:12:02,150 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2023-11-21 22:12:02,151 INFO L153 SettingsManager]: * Use constant arrays=true [2023-11-21 22:12:02,151 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2023-11-21 22:12:02,152 INFO L153 SettingsManager]: * Size of a code block=SequenceOfStatements [2023-11-21 22:12:02,152 INFO L153 SettingsManager]: * Only consider context switches at boundaries of atomic blocks=true [2023-11-21 22:12:02,153 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2023-11-21 22:12:02,154 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-21 22:12:02,154 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2023-11-21 22:12:02,154 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2023-11-21 22:12:02,155 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopHeads [2023-11-21 22:12:02,155 INFO L153 SettingsManager]: * Trace refinement strategy=CAMEL [2023-11-21 22:12:02,155 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2023-11-21 22:12:02,155 INFO L153 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2023-11-21 22:12:02,156 INFO L153 SettingsManager]: * Automaton type used in concurrency analysis=PETRI_NET [2023-11-21 22:12:02,156 INFO L153 SettingsManager]: * Compute Hoare Annotation of negated interpolant automaton, abstraction and CFG=true [2023-11-21 22:12:02,156 INFO L153 SettingsManager]: * Order on configurations for Petri net unfoldings=DBO [2023-11-21 22:12:02,156 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2023-11-21 22:12:02,157 INFO L153 SettingsManager]: * Looper check in Petri net analysis=SEMANTIC WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Automizer Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 9cfe95aaca007f6467395901a9efc89e5ad27f0fc32ae7ae8a1fe4e27a1f35c1 [2023-11-21 22:12:02,434 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2023-11-21 22:12:02,458 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2023-11-21 22:12:02,461 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2023-11-21 22:12:02,462 INFO L270 PluginConnector]: Initializing CDTParser... [2023-11-21 22:12:02,463 INFO L274 PluginConnector]: CDTParser initialized [2023-11-21 22:12:02,464 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/../../sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c [2023-11-21 22:12:05,557 INFO L533 CDTParser]: Created temporary CDT project at NULL [2023-11-21 22:12:05,827 INFO L384 CDTParser]: Found 1 translation units. [2023-11-21 22:12:05,828 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c [2023-11-21 22:12:05,842 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/data/246623367/08a3419a915e40fa81d9e08266feb179/FLAG60761ffe2 [2023-11-21 22:12:05,859 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/data/246623367/08a3419a915e40fa81d9e08266feb179 [2023-11-21 22:12:05,862 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2023-11-21 22:12:05,863 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2023-11-21 22:12:05,865 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2023-11-21 22:12:05,865 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2023-11-21 22:12:05,877 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2023-11-21 22:12:05,878 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 10:12:05" (1/1) ... [2023-11-21 22:12:05,879 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@575c0adb and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:05, skipping insertion in model container [2023-11-21 22:12:05,879 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 21.11 10:12:05" (1/1) ... [2023-11-21 22:12:05,949 INFO L177 MainTranslator]: Built tables and reachable declarations [2023-11-21 22:12:06,102 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c[1605,1618] [2023-11-21 22:12:06,287 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-21 22:12:06,299 INFO L202 MainTranslator]: Completed pre-run [2023-11-21 22:12:06,311 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] [2023-11-21 22:12:06,312 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [58] [2023-11-21 22:12:06,313 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [279] [2023-11-21 22:12:06,313 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [349] [2023-11-21 22:12:06,313 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [453] [2023-11-21 22:12:06,313 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [819] [2023-11-21 22:12:06,314 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [868] [2023-11-21 22:12:06,314 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [906] [2023-11-21 22:12:06,319 WARN L240 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/sv-benchmarks/c/product-lines/minepump_spec5_product50.cil.c[1605,1618] [2023-11-21 22:12:06,386 INFO L209 PostProcessor]: Analyzing one entry point: main [2023-11-21 22:12:06,412 INFO L206 MainTranslator]: Completed translation [2023-11-21 22:12:06,413 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06 WrapperNode [2023-11-21 22:12:06,413 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2023-11-21 22:12:06,415 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2023-11-21 22:12:06,415 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2023-11-21 22:12:06,415 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2023-11-21 22:12:06,423 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,439 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,489 INFO L138 Inliner]: procedures = 58, calls = 102, calls flagged for inlining = 26, calls inlined = 22, statements flattened = 212 [2023-11-21 22:12:06,489 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2023-11-21 22:12:06,490 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2023-11-21 22:12:06,490 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2023-11-21 22:12:06,490 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2023-11-21 22:12:06,504 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,504 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,507 INFO L184 PluginConnector]: Executing the observer HeapSplitter from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,525 INFO L187 HeapSplitter]: Split 2 memory accesses to 1 slices as follows [2] [2023-11-21 22:12:06,525 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,525 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,545 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,551 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,553 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,561 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,566 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2023-11-21 22:12:06,568 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2023-11-21 22:12:06,569 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2023-11-21 22:12:06,570 INFO L274 PluginConnector]: RCFGBuilder initialized [2023-11-21 22:12:06,571 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (1/1) ... [2023-11-21 22:12:06,577 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2023-11-21 22:12:06,590 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 22:12:06,604 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2023-11-21 22:12:06,636 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2023-11-21 22:12:06,651 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2023-11-21 22:12:06,652 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2023-11-21 22:12:06,652 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2023-11-21 22:12:06,652 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2023-11-21 22:12:06,652 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2023-11-21 22:12:06,653 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2023-11-21 22:12:06,653 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2023-11-21 22:12:06,653 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2023-11-21 22:12:06,653 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2023-11-21 22:12:06,653 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2023-11-21 22:12:06,654 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2023-11-21 22:12:06,654 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2023-11-21 22:12:06,654 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2023-11-21 22:12:06,654 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int#0 [2023-11-21 22:12:06,655 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2023-11-21 22:12:06,655 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2023-11-21 22:12:06,655 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2023-11-21 22:12:06,656 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2023-11-21 22:12:06,726 INFO L240 CfgBuilder]: Building ICFG [2023-11-21 22:12:06,729 INFO L266 CfgBuilder]: Building CFG for each procedure with an implementation [2023-11-21 22:12:07,098 INFO L281 CfgBuilder]: Performing block encoding [2023-11-21 22:12:07,263 INFO L303 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2023-11-21 22:12:07,264 INFO L308 CfgBuilder]: Removed 2 assume(true) statements. [2023-11-21 22:12:07,266 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 10:12:07 BoogieIcfgContainer [2023-11-21 22:12:07,266 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2023-11-21 22:12:07,270 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2023-11-21 22:12:07,270 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2023-11-21 22:12:07,274 INFO L274 PluginConnector]: TraceAbstraction initialized [2023-11-21 22:12:07,274 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 21.11 10:12:05" (1/3) ... [2023-11-21 22:12:07,275 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5f60cfb6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 10:12:07, skipping insertion in model container [2023-11-21 22:12:07,275 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 21.11 10:12:06" (2/3) ... [2023-11-21 22:12:07,277 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@5f60cfb6 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 21.11 10:12:07, skipping insertion in model container [2023-11-21 22:12:07,278 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 10:12:07" (3/3) ... [2023-11-21 22:12:07,279 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product50.cil.c [2023-11-21 22:12:07,302 INFO L203 ceAbstractionStarter]: Automizer settings: Hoare:true NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2023-11-21 22:12:07,302 INFO L162 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2023-11-21 22:12:07,351 INFO L356 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2023-11-21 22:12:07,358 INFO L357 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mHoare=true, mAutomataTypeConcurrency=PETRI_NET, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopHeads, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@4d524c2e, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2023-11-21 22:12:07,358 INFO L358 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2023-11-21 22:12:07,362 INFO L276 IsEmpty]: Start isEmpty. Operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) [2023-11-21 22:12:07,371 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2023-11-21 22:12:07,372 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:07,373 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:07,373 INFO L420 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:07,379 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:07,379 INFO L85 PathProgramCache]: Analyzing trace with hash -1895487654, now seen corresponding path program 1 times [2023-11-21 22:12:07,389 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:07,390 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1243175793] [2023-11-21 22:12:07,390 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:07,391 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:07,536 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,604 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 22:12:07,606 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,611 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 14 [2023-11-21 22:12:07,614 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,618 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 22:12:07,618 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:07,618 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1243175793] [2023-11-21 22:12:07,619 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1243175793] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:07,619 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:07,620 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2023-11-21 22:12:07,622 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1726200570] [2023-11-21 22:12:07,623 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:07,627 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2023-11-21 22:12:07,628 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:07,660 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2023-11-21 22:12:07,661 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-21 22:12:07,663 INFO L87 Difference]: Start difference. First operand has 58 states, 37 states have (on average 1.4324324324324325) internal successors, (53), 45 states have internal predecessors, (53), 12 states have call successors, (12), 7 states have call predecessors, (12), 7 states have return successors, (12), 10 states have call predecessors, (12), 12 states have call successors, (12) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 22:12:07,745 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:07,747 INFO L93 Difference]: Finished difference Result 114 states and 155 transitions. [2023-11-21 22:12:07,749 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2023-11-21 22:12:07,750 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2023-11-21 22:12:07,750 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:07,766 INFO L225 Difference]: With dead ends: 114 [2023-11-21 22:12:07,766 INFO L226 Difference]: Without dead ends: 53 [2023-11-21 22:12:07,770 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2023-11-21 22:12:07,774 INFO L413 NwaCegarLoop]: 57 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 57 SdHoareTripleChecker+Invalid, 18 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:07,775 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 57 Invalid, 18 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-21 22:12:07,794 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 53 states. [2023-11-21 22:12:07,816 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 53 to 53. [2023-11-21 22:12:07,818 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 53 states, 34 states have (on average 1.3235294117647058) internal successors, (45), 41 states have internal predecessors, (45), 12 states have call successors, (12), 7 states have call predecessors, (12), 6 states have return successors, (11), 9 states have call predecessors, (11), 11 states have call successors, (11) [2023-11-21 22:12:07,820 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 53 states to 53 states and 68 transitions. [2023-11-21 22:12:07,822 INFO L78 Accepts]: Start accepts. Automaton has 53 states and 68 transitions. Word has length 21 [2023-11-21 22:12:07,822 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:07,822 INFO L495 AbstractCegarLoop]: Abstraction has 53 states and 68 transitions. [2023-11-21 22:12:07,823 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 22:12:07,823 INFO L276 IsEmpty]: Start isEmpty. Operand 53 states and 68 transitions. [2023-11-21 22:12:07,825 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 23 [2023-11-21 22:12:07,826 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:07,826 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:07,826 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2023-11-21 22:12:07,826 INFO L420 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:07,827 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:07,827 INFO L85 PathProgramCache]: Analyzing trace with hash -1077094405, now seen corresponding path program 1 times [2023-11-21 22:12:07,828 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:07,828 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [384691236] [2023-11-21 22:12:07,828 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:07,828 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:07,849 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-21 22:12:07,938 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,941 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 15 [2023-11-21 22:12:07,943 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:07,946 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 22:12:07,946 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:07,946 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [384691236] [2023-11-21 22:12:07,946 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [384691236] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:07,947 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:07,947 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2023-11-21 22:12:07,947 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1300400723] [2023-11-21 22:12:07,947 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:07,950 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2023-11-21 22:12:07,956 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:07,957 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2023-11-21 22:12:07,957 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-21 22:12:07,958 INFO L87 Difference]: Start difference. First operand 53 states and 68 transitions. Second operand has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 22:12:08,016 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:08,016 INFO L93 Difference]: Finished difference Result 83 states and 107 transitions. [2023-11-21 22:12:08,017 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2023-11-21 22:12:08,017 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 22 [2023-11-21 22:12:08,017 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:08,019 INFO L225 Difference]: With dead ends: 83 [2023-11-21 22:12:08,019 INFO L226 Difference]: Without dead ends: 45 [2023-11-21 22:12:08,020 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2023-11-21 22:12:08,021 INFO L413 NwaCegarLoop]: 43 mSDtfsCounter, 7 mSDsluCounter, 34 mSDsCounter, 0 mSdLazyCounter, 25 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 77 SdHoareTripleChecker+Invalid, 25 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 25 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:08,022 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 77 Invalid, 25 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 25 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2023-11-21 22:12:08,023 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 45 states. [2023-11-21 22:12:08,033 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 45 to 45. [2023-11-21 22:12:08,035 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 45 states, 29 states have (on average 1.3448275862068966) internal successors, (39), 36 states have internal predecessors, (39), 9 states have call successors, (9), 6 states have call predecessors, (9), 6 states have return successors, (9), 7 states have call predecessors, (9), 9 states have call successors, (9) [2023-11-21 22:12:08,036 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 45 states to 45 states and 57 transitions. [2023-11-21 22:12:08,037 INFO L78 Accepts]: Start accepts. Automaton has 45 states and 57 transitions. Word has length 22 [2023-11-21 22:12:08,037 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:08,037 INFO L495 AbstractCegarLoop]: Abstraction has 45 states and 57 transitions. [2023-11-21 22:12:08,038 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 5.0) internal successors, (15), 3 states have internal predecessors, (15), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2023-11-21 22:12:08,038 INFO L276 IsEmpty]: Start isEmpty. Operand 45 states and 57 transitions. [2023-11-21 22:12:08,039 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2023-11-21 22:12:08,039 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:08,039 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:08,040 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2023-11-21 22:12:08,040 INFO L420 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:08,040 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:08,041 INFO L85 PathProgramCache]: Analyzing trace with hash 704334258, now seen corresponding path program 1 times [2023-11-21 22:12:08,041 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:08,041 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1070344063] [2023-11-21 22:12:08,041 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:08,042 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:08,069 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:08,335 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2023-11-21 22:12:08,339 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:08,369 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 17 [2023-11-21 22:12:08,372 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:08,390 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 22:12:08,391 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:08,392 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1070344063] [2023-11-21 22:12:08,392 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1070344063] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:08,393 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:08,393 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2023-11-21 22:12:08,394 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [366283309] [2023-11-21 22:12:08,394 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:08,394 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-21 22:12:08,395 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:08,396 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-21 22:12:08,396 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=43, Unknown=0, NotChecked=0, Total=56 [2023-11-21 22:12:08,397 INFO L87 Difference]: Start difference. First operand 45 states and 57 transitions. Second operand has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-21 22:12:09,003 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:09,004 INFO L93 Difference]: Finished difference Result 180 states and 238 transitions. [2023-11-21 22:12:09,004 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2023-11-21 22:12:09,005 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 24 [2023-11-21 22:12:09,006 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:09,017 INFO L225 Difference]: With dead ends: 180 [2023-11-21 22:12:09,017 INFO L226 Difference]: Without dead ends: 137 [2023-11-21 22:12:09,021 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 23 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 17 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 45 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=71, Invalid=271, Unknown=0, NotChecked=0, Total=342 [2023-11-21 22:12:09,022 INFO L413 NwaCegarLoop]: 99 mSDtfsCounter, 84 mSDsluCounter, 304 mSDsCounter, 0 mSdLazyCounter, 445 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 88 SdHoareTripleChecker+Valid, 403 SdHoareTripleChecker+Invalid, 463 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 445 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:09,023 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [88 Valid, 403 Invalid, 463 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 445 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-21 22:12:09,024 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 137 states. [2023-11-21 22:12:09,075 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 137 to 133. [2023-11-21 22:12:09,076 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 133 states, 87 states have (on average 1.2528735632183907) internal successors, (109), 98 states have internal predecessors, (109), 24 states have call successors, (24), 20 states have call predecessors, (24), 21 states have return successors, (36), 23 states have call predecessors, (36), 24 states have call successors, (36) [2023-11-21 22:12:09,080 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 133 states to 133 states and 169 transitions. [2023-11-21 22:12:09,081 INFO L78 Accepts]: Start accepts. Automaton has 133 states and 169 transitions. Word has length 24 [2023-11-21 22:12:09,081 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:09,082 INFO L495 AbstractCegarLoop]: Abstraction has 133 states and 169 transitions. [2023-11-21 22:12:09,083 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 2.5714285714285716) internal successors, (18), 6 states have internal predecessors, (18), 2 states have call successors, (3), 1 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2023-11-21 22:12:09,083 INFO L276 IsEmpty]: Start isEmpty. Operand 133 states and 169 transitions. [2023-11-21 22:12:09,085 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 33 [2023-11-21 22:12:09,088 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:09,088 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:09,089 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2023-11-21 22:12:09,089 INFO L420 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:09,089 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:09,090 INFO L85 PathProgramCache]: Analyzing trace with hash 1050857119, now seen corresponding path program 1 times [2023-11-21 22:12:09,090 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:09,090 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [861436210] [2023-11-21 22:12:09,090 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:09,090 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:09,118 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:09,409 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 10 [2023-11-21 22:12:09,411 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:09,421 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 16 [2023-11-21 22:12:09,438 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:09,487 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 25 [2023-11-21 22:12:09,489 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:09,490 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 22:12:09,491 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:09,491 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [861436210] [2023-11-21 22:12:09,491 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [861436210] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:09,491 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:09,492 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [7] imperfect sequences [] total 7 [2023-11-21 22:12:09,492 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1750055333] [2023-11-21 22:12:09,492 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:09,492 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 7 states [2023-11-21 22:12:09,493 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:09,493 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 7 interpolants. [2023-11-21 22:12:09,494 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=13, Invalid=29, Unknown=0, NotChecked=0, Total=42 [2023-11-21 22:12:09,494 INFO L87 Difference]: Start difference. First operand 133 states and 169 transitions. Second operand has 7 states, 7 states have (on average 3.4285714285714284) internal successors, (24), 6 states have internal predecessors, (24), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-21 22:12:09,945 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:09,946 INFO L93 Difference]: Finished difference Result 456 states and 611 transitions. [2023-11-21 22:12:09,947 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 13 states. [2023-11-21 22:12:09,947 INFO L78 Accepts]: Start accepts. Automaton has has 7 states, 7 states have (on average 3.4285714285714284) internal successors, (24), 6 states have internal predecessors, (24), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) Word has length 32 [2023-11-21 22:12:09,948 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:09,953 INFO L225 Difference]: With dead ends: 456 [2023-11-21 22:12:09,953 INFO L226 Difference]: Without dead ends: 325 [2023-11-21 22:12:09,955 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 25 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 12 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 22 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=57, Invalid=125, Unknown=0, NotChecked=0, Total=182 [2023-11-21 22:12:09,957 INFO L413 NwaCegarLoop]: 75 mSDtfsCounter, 175 mSDsluCounter, 125 mSDsCounter, 0 mSdLazyCounter, 211 mSolverCounterSat, 102 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 180 SdHoareTripleChecker+Valid, 200 SdHoareTripleChecker+Invalid, 313 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 102 IncrementalHoareTripleChecker+Valid, 211 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:09,958 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [180 Valid, 200 Invalid, 313 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [102 Valid, 211 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2023-11-21 22:12:09,959 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 325 states. [2023-11-21 22:12:10,047 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 325 to 290. [2023-11-21 22:12:10,051 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 290 states, 187 states have (on average 1.2406417112299466) internal successors, (232), 210 states have internal predecessors, (232), 55 states have call successors, (55), 47 states have call predecessors, (55), 47 states have return successors, (95), 48 states have call predecessors, (95), 55 states have call successors, (95) [2023-11-21 22:12:10,061 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 290 states to 290 states and 382 transitions. [2023-11-21 22:12:10,061 INFO L78 Accepts]: Start accepts. Automaton has 290 states and 382 transitions. Word has length 32 [2023-11-21 22:12:10,062 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:10,062 INFO L495 AbstractCegarLoop]: Abstraction has 290 states and 382 transitions. [2023-11-21 22:12:10,062 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 7 states, 7 states have (on average 3.4285714285714284) internal successors, (24), 6 states have internal predecessors, (24), 2 states have call successors, (4), 3 states have call predecessors, (4), 2 states have return successors, (3), 2 states have call predecessors, (3), 2 states have call successors, (3) [2023-11-21 22:12:10,062 INFO L276 IsEmpty]: Start isEmpty. Operand 290 states and 382 transitions. [2023-11-21 22:12:10,073 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2023-11-21 22:12:10,073 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:10,073 INFO L195 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:10,073 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2023-11-21 22:12:10,074 INFO L420 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:10,075 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:10,075 INFO L85 PathProgramCache]: Analyzing trace with hash 650227895, now seen corresponding path program 1 times [2023-11-21 22:12:10,075 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:10,075 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [703893619] [2023-11-21 22:12:10,076 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:10,076 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:10,111 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:10,280 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 22:12:10,283 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:10,340 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 13 [2023-11-21 22:12:10,343 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:10,352 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-21 22:12:10,355 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:10,358 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 28 [2023-11-21 22:12:10,360 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:10,361 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2023-11-21 22:12:10,362 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:10,362 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [703893619] [2023-11-21 22:12:10,362 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [703893619] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:10,362 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:10,362 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2023-11-21 22:12:10,363 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1226513812] [2023-11-21 22:12:10,363 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:10,363 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2023-11-21 22:12:10,363 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:10,364 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2023-11-21 22:12:10,364 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=55, Unknown=0, NotChecked=0, Total=72 [2023-11-21 22:12:10,365 INFO L87 Difference]: Start difference. First operand 290 states and 382 transitions. Second operand has 9 states, 8 states have (on average 3.125) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-21 22:12:11,120 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:11,121 INFO L93 Difference]: Finished difference Result 967 states and 1299 transitions. [2023-11-21 22:12:11,124 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 25 states. [2023-11-21 22:12:11,124 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 3.125) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) Word has length 35 [2023-11-21 22:12:11,125 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:11,131 INFO L225 Difference]: With dead ends: 967 [2023-11-21 22:12:11,132 INFO L226 Difference]: Without dead ends: 682 [2023-11-21 22:12:11,134 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 36 GetRequests, 12 SyntacticMatches, 0 SemanticMatches, 24 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 131 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=143, Invalid=507, Unknown=0, NotChecked=0, Total=650 [2023-11-21 22:12:11,143 INFO L413 NwaCegarLoop]: 62 mSDtfsCounter, 168 mSDsluCounter, 280 mSDsCounter, 0 mSdLazyCounter, 444 mSolverCounterSat, 85 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.3s Time, 0 mProtectedPredicate, 0 mProtectedAction, 174 SdHoareTripleChecker+Valid, 342 SdHoareTripleChecker+Invalid, 529 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 85 IncrementalHoareTripleChecker+Valid, 444 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.4s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:11,144 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [174 Valid, 342 Invalid, 529 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [85 Valid, 444 Invalid, 0 Unknown, 0 Unchecked, 0.4s Time] [2023-11-21 22:12:11,146 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 682 states. [2023-11-21 22:12:11,275 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 682 to 607. [2023-11-21 22:12:11,277 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 607 states, 397 states have (on average 1.2392947103274559) internal successors, (492), 444 states have internal predecessors, (492), 110 states have call successors, (110), 92 states have call predecessors, (110), 99 states have return successors, (194), 101 states have call predecessors, (194), 110 states have call successors, (194) [2023-11-21 22:12:11,283 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 607 states to 607 states and 796 transitions. [2023-11-21 22:12:11,284 INFO L78 Accepts]: Start accepts. Automaton has 607 states and 796 transitions. Word has length 35 [2023-11-21 22:12:11,284 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:11,285 INFO L495 AbstractCegarLoop]: Abstraction has 607 states and 796 transitions. [2023-11-21 22:12:11,285 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 3.125) internal successors, (25), 7 states have internal predecessors, (25), 3 states have call successors, (5), 4 states have call predecessors, (5), 2 states have return successors, (4), 2 states have call predecessors, (4), 3 states have call successors, (4) [2023-11-21 22:12:11,285 INFO L276 IsEmpty]: Start isEmpty. Operand 607 states and 796 transitions. [2023-11-21 22:12:11,290 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2023-11-21 22:12:11,291 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:11,291 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:11,291 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2023-11-21 22:12:11,292 INFO L420 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:11,292 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:11,292 INFO L85 PathProgramCache]: Analyzing trace with hash -593642593, now seen corresponding path program 1 times [2023-11-21 22:12:11,292 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:11,293 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [840837360] [2023-11-21 22:12:11,293 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:11,293 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:11,312 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,400 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-21 22:12:11,403 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,414 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:11,415 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,422 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 22 [2023-11-21 22:12:11,423 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,425 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-21 22:12:11,426 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,433 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2023-11-21 22:12:11,436 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,439 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2023-11-21 22:12:11,440 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:11,441 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2023-11-21 22:12:11,442 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:11,442 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [840837360] [2023-11-21 22:12:11,442 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [840837360] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:11,443 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:11,443 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2023-11-21 22:12:11,443 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1983280314] [2023-11-21 22:12:11,443 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:11,444 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2023-11-21 22:12:11,444 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:11,445 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2023-11-21 22:12:11,445 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=16, Invalid=40, Unknown=0, NotChecked=0, Total=56 [2023-11-21 22:12:11,445 INFO L87 Difference]: Start difference. First operand 607 states and 796 transitions. Second operand has 8 states, 8 states have (on average 4.625) internal successors, (37), 5 states have internal predecessors, (37), 3 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (6), 2 states have call predecessors, (6), 3 states have call successors, (6) [2023-11-21 22:12:11,744 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:11,744 INFO L93 Difference]: Finished difference Result 1069 states and 1402 transitions. [2023-11-21 22:12:11,745 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2023-11-21 22:12:11,746 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 4.625) internal successors, (37), 5 states have internal predecessors, (37), 3 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (6), 2 states have call predecessors, (6), 3 states have call successors, (6) Word has length 52 [2023-11-21 22:12:11,746 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:11,750 INFO L225 Difference]: With dead ends: 1069 [2023-11-21 22:12:11,751 INFO L226 Difference]: Without dead ends: 478 [2023-11-21 22:12:11,754 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 22 GetRequests, 13 SyntacticMatches, 0 SemanticMatches, 9 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 7 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=32, Invalid=78, Unknown=0, NotChecked=0, Total=110 [2023-11-21 22:12:11,755 INFO L413 NwaCegarLoop]: 33 mSDtfsCounter, 67 mSDsluCounter, 100 mSDsCounter, 0 mSdLazyCounter, 179 mSolverCounterSat, 32 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 71 SdHoareTripleChecker+Valid, 133 SdHoareTripleChecker+Invalid, 211 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 32 IncrementalHoareTripleChecker+Valid, 179 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:11,756 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [71 Valid, 133 Invalid, 211 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [32 Valid, 179 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2023-11-21 22:12:11,757 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 478 states. [2023-11-21 22:12:11,843 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 478 to 403. [2023-11-21 22:12:11,845 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 403 states, 263 states have (on average 1.2015209125475286) internal successors, (316), 294 states have internal predecessors, (316), 70 states have call successors, (70), 61 states have call predecessors, (70), 69 states have return successors, (116), 68 states have call predecessors, (116), 70 states have call successors, (116) [2023-11-21 22:12:11,848 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 403 states to 403 states and 502 transitions. [2023-11-21 22:12:11,849 INFO L78 Accepts]: Start accepts. Automaton has 403 states and 502 transitions. Word has length 52 [2023-11-21 22:12:11,849 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:11,849 INFO L495 AbstractCegarLoop]: Abstraction has 403 states and 502 transitions. [2023-11-21 22:12:11,850 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 4.625) internal successors, (37), 5 states have internal predecessors, (37), 3 states have call successors, (7), 5 states have call predecessors, (7), 2 states have return successors, (6), 2 states have call predecessors, (6), 3 states have call successors, (6) [2023-11-21 22:12:11,850 INFO L276 IsEmpty]: Start isEmpty. Operand 403 states and 502 transitions. [2023-11-21 22:12:11,852 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 53 [2023-11-21 22:12:11,853 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:11,853 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:11,853 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2023-11-21 22:12:11,853 INFO L420 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:11,854 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:11,854 INFO L85 PathProgramCache]: Analyzing trace with hash 719072555, now seen corresponding path program 1 times [2023-11-21 22:12:11,854 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:11,854 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1472103652] [2023-11-21 22:12:11,854 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:11,855 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:11,888 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,092 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-21 22:12:12,099 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,284 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:12,286 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,287 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 30 [2023-11-21 22:12:12,289 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,297 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2023-11-21 22:12:12,300 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,305 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 45 [2023-11-21 22:12:12,306 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:12,317 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 15 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2023-11-21 22:12:12,317 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:12,318 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1472103652] [2023-11-21 22:12:12,318 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1472103652] provided 1 perfect and 0 imperfect interpolant sequences [2023-11-21 22:12:12,318 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2023-11-21 22:12:12,318 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2023-11-21 22:12:12,318 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1257438454] [2023-11-21 22:12:12,319 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2023-11-21 22:12:12,319 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2023-11-21 22:12:12,319 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:12,320 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2023-11-21 22:12:12,321 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=25, Invalid=65, Unknown=0, NotChecked=0, Total=90 [2023-11-21 22:12:12,321 INFO L87 Difference]: Start difference. First operand 403 states and 502 transitions. Second operand has 10 states, 10 states have (on average 3.9) internal successors, (39), 8 states have internal predecessors, (39), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 3 states have call successors, (5) [2023-11-21 22:12:12,841 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:12,841 INFO L93 Difference]: Finished difference Result 885 states and 1154 transitions. [2023-11-21 22:12:12,842 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 17 states. [2023-11-21 22:12:12,842 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 10 states have (on average 3.9) internal successors, (39), 8 states have internal predecessors, (39), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 3 states have call successors, (5) Word has length 52 [2023-11-21 22:12:12,843 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:12,847 INFO L225 Difference]: With dead ends: 885 [2023-11-21 22:12:12,848 INFO L226 Difference]: Without dead ends: 494 [2023-11-21 22:12:12,850 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 27 GetRequests, 11 SyntacticMatches, 0 SemanticMatches, 16 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 40 ImplicationChecksByTransitivity, 0.2s TimeCoverageRelationStatistics Valid=87, Invalid=219, Unknown=0, NotChecked=0, Total=306 [2023-11-21 22:12:12,854 INFO L413 NwaCegarLoop]: 33 mSDtfsCounter, 120 mSDsluCounter, 115 mSDsCounter, 0 mSdLazyCounter, 254 mSolverCounterSat, 56 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 125 SdHoareTripleChecker+Valid, 148 SdHoareTripleChecker+Invalid, 310 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 56 IncrementalHoareTripleChecker+Valid, 254 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:12,854 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [125 Valid, 148 Invalid, 310 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [56 Valid, 254 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2023-11-21 22:12:12,856 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 494 states. [2023-11-21 22:12:12,955 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 494 to 440. [2023-11-21 22:12:12,956 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 440 states, 290 states have (on average 1.193103448275862) internal successors, (346), 324 states have internal predecessors, (346), 74 states have call successors, (74), 61 states have call predecessors, (74), 75 states have return successors, (142), 75 states have call predecessors, (142), 74 states have call successors, (142) [2023-11-21 22:12:12,961 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 440 states to 440 states and 562 transitions. [2023-11-21 22:12:12,961 INFO L78 Accepts]: Start accepts. Automaton has 440 states and 562 transitions. Word has length 52 [2023-11-21 22:12:12,962 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:12,962 INFO L495 AbstractCegarLoop]: Abstraction has 440 states and 562 transitions. [2023-11-21 22:12:12,962 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 10 states have (on average 3.9) internal successors, (39), 8 states have internal predecessors, (39), 3 states have call successors, (6), 4 states have call predecessors, (6), 2 states have return successors, (5), 2 states have call predecessors, (5), 3 states have call successors, (5) [2023-11-21 22:12:12,962 INFO L276 IsEmpty]: Start isEmpty. Operand 440 states and 562 transitions. [2023-11-21 22:12:12,966 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 56 [2023-11-21 22:12:12,968 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:12,968 INFO L195 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:12,969 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2023-11-21 22:12:12,969 INFO L420 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:12,969 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:12,970 INFO L85 PathProgramCache]: Analyzing trace with hash 252515139, now seen corresponding path program 1 times [2023-11-21 22:12:12,970 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:12,970 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [828350434] [2023-11-21 22:12:12,970 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:12,972 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:12,996 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,177 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 22:12:13,178 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,191 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-21 22:12:13,196 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,247 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:13,249 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,250 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 33 [2023-11-21 22:12:13,252 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,261 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 39 [2023-11-21 22:12:13,264 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,267 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 48 [2023-11-21 22:12:13,268 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,269 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 11 proven. 4 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2023-11-21 22:12:13,270 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:13,270 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [828350434] [2023-11-21 22:12:13,270 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [828350434] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 22:12:13,270 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [55932533] [2023-11-21 22:12:13,270 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:13,270 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:13,271 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 22:12:13,273 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 22:12:13,283 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2023-11-21 22:12:13,397 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:13,400 INFO L262 TraceCheckSpWp]: Trace formula consists of 262 conjuncts, 18 conjunts are in the unsatisfiable core [2023-11-21 22:12:13,409 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 22:12:13,575 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 20 proven. 1 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2023-11-21 22:12:13,575 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-21 22:12:13,741 INFO L134 CoverageAnalysis]: Checked inductivity of 21 backedges. 14 proven. 1 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2023-11-21 22:12:13,742 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [55932533] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-21 22:12:13,742 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-21 22:12:13,742 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [10, 6, 6] total 14 [2023-11-21 22:12:13,743 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1279660607] [2023-11-21 22:12:13,743 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-21 22:12:13,744 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 14 states [2023-11-21 22:12:13,746 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:13,747 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 14 interpolants. [2023-11-21 22:12:13,747 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=39, Invalid=143, Unknown=0, NotChecked=0, Total=182 [2023-11-21 22:12:13,747 INFO L87 Difference]: Start difference. First operand 440 states and 562 transitions. Second operand has 14 states, 14 states have (on average 4.928571428571429) internal successors, (69), 11 states have internal predecessors, (69), 4 states have call successors, (15), 7 states have call predecessors, (15), 4 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) [2023-11-21 22:12:14,960 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:14,960 INFO L93 Difference]: Finished difference Result 1061 states and 1410 transitions. [2023-11-21 22:12:14,961 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 31 states. [2023-11-21 22:12:14,961 INFO L78 Accepts]: Start accepts. Automaton has has 14 states, 14 states have (on average 4.928571428571429) internal successors, (69), 11 states have internal predecessors, (69), 4 states have call successors, (15), 7 states have call predecessors, (15), 4 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) Word has length 55 [2023-11-21 22:12:14,962 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:14,967 INFO L225 Difference]: With dead ends: 1061 [2023-11-21 22:12:14,968 INFO L226 Difference]: Without dead ends: 588 [2023-11-21 22:12:14,972 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 166 GetRequests, 130 SyntacticMatches, 0 SemanticMatches, 36 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 298 ImplicationChecksByTransitivity, 0.5s TimeCoverageRelationStatistics Valid=303, Invalid=1103, Unknown=0, NotChecked=0, Total=1406 [2023-11-21 22:12:14,974 INFO L413 NwaCegarLoop]: 65 mSDtfsCounter, 263 mSDsluCounter, 374 mSDsCounter, 0 mSdLazyCounter, 773 mSolverCounterSat, 124 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.6s Time, 0 mProtectedPredicate, 0 mProtectedAction, 269 SdHoareTripleChecker+Valid, 439 SdHoareTripleChecker+Invalid, 897 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 124 IncrementalHoareTripleChecker+Valid, 773 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.7s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:14,977 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [269 Valid, 439 Invalid, 897 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [124 Valid, 773 Invalid, 0 Unknown, 0 Unchecked, 0.7s Time] [2023-11-21 22:12:14,981 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 588 states. [2023-11-21 22:12:15,073 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 588 to 508. [2023-11-21 22:12:15,075 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 508 states, 333 states have (on average 1.1531531531531531) internal successors, (384), 370 states have internal predecessors, (384), 90 states have call successors, (90), 78 states have call predecessors, (90), 84 states have return successors, (133), 85 states have call predecessors, (133), 90 states have call successors, (133) [2023-11-21 22:12:15,079 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 508 states to 508 states and 607 transitions. [2023-11-21 22:12:15,080 INFO L78 Accepts]: Start accepts. Automaton has 508 states and 607 transitions. Word has length 55 [2023-11-21 22:12:15,081 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:15,081 INFO L495 AbstractCegarLoop]: Abstraction has 508 states and 607 transitions. [2023-11-21 22:12:15,081 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 14 states, 14 states have (on average 4.928571428571429) internal successors, (69), 11 states have internal predecessors, (69), 4 states have call successors, (15), 7 states have call predecessors, (15), 4 states have return successors, (11), 4 states have call predecessors, (11), 4 states have call successors, (11) [2023-11-21 22:12:15,082 INFO L276 IsEmpty]: Start isEmpty. Operand 508 states and 607 transitions. [2023-11-21 22:12:15,084 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 69 [2023-11-21 22:12:15,084 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:15,084 INFO L195 NwaCegarLoop]: trace histogram [4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:15,114 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2023-11-21 22:12:15,300 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:15,301 INFO L420 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:15,301 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:15,301 INFO L85 PathProgramCache]: Analyzing trace with hash 1968386362, now seen corresponding path program 1 times [2023-11-21 22:12:15,301 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:15,301 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1848458403] [2023-11-21 22:12:15,302 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:15,302 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:15,346 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,683 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 8 [2023-11-21 22:12:15,689 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,888 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:15,890 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,905 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 22:12:15,909 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,936 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 3 [2023-11-21 22:12:15,937 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,939 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 19 [2023-11-21 22:12:15,942 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:15,952 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 38 [2023-11-21 22:12:15,954 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:16,005 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 46 [2023-11-21 22:12:16,007 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:16,011 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 52 [2023-11-21 22:12:16,015 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:16,019 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 61 [2023-11-21 22:12:16,021 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:16,023 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 6 proven. 16 refuted. 0 times theorem prover too weak. 14 trivial. 0 not checked. [2023-11-21 22:12:16,023 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:16,023 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1848458403] [2023-11-21 22:12:16,024 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1848458403] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 22:12:16,024 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [556495076] [2023-11-21 22:12:16,024 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:16,024 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:16,025 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 22:12:16,026 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 22:12:16,048 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2023-11-21 22:12:16,139 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:16,141 INFO L262 TraceCheckSpWp]: Trace formula consists of 290 conjuncts, 26 conjunts are in the unsatisfiable core [2023-11-21 22:12:16,149 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 22:12:16,450 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 18 proven. 13 refuted. 0 times theorem prover too weak. 5 trivial. 0 not checked. [2023-11-21 22:12:16,451 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-21 22:12:17,444 INFO L134 CoverageAnalysis]: Checked inductivity of 36 backedges. 15 proven. 1 refuted. 0 times theorem prover too weak. 20 trivial. 0 not checked. [2023-11-21 22:12:17,445 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [556495076] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-21 22:12:17,445 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-21 22:12:17,445 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [15, 9, 9] total 23 [2023-11-21 22:12:17,445 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [229882865] [2023-11-21 22:12:17,446 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-21 22:12:17,447 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 23 states [2023-11-21 22:12:17,448 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:17,449 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 23 interpolants. [2023-11-21 22:12:17,449 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=106, Invalid=400, Unknown=0, NotChecked=0, Total=506 [2023-11-21 22:12:17,450 INFO L87 Difference]: Start difference. First operand 508 states and 607 transitions. Second operand has 23 states, 19 states have (on average 5.0) internal successors, (95), 21 states have internal predecessors, (95), 12 states have call successors, (26), 8 states have call predecessors, (26), 10 states have return successors, (23), 11 states have call predecessors, (23), 12 states have call successors, (23) [2023-11-21 22:12:19,564 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:19,565 INFO L93 Difference]: Finished difference Result 1455 states and 1853 transitions. [2023-11-21 22:12:19,568 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 43 states. [2023-11-21 22:12:19,568 INFO L78 Accepts]: Start accepts. Automaton has has 23 states, 19 states have (on average 5.0) internal successors, (95), 21 states have internal predecessors, (95), 12 states have call successors, (26), 8 states have call predecessors, (26), 10 states have return successors, (23), 11 states have call predecessors, (23), 12 states have call successors, (23) Word has length 68 [2023-11-21 22:12:19,569 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:19,579 INFO L225 Difference]: With dead ends: 1455 [2023-11-21 22:12:19,579 INFO L226 Difference]: Without dead ends: 1054 [2023-11-21 22:12:19,583 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 208 GetRequests, 151 SyntacticMatches, 0 SemanticMatches, 57 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 816 ImplicationChecksByTransitivity, 1.1s TimeCoverageRelationStatistics Valid=668, Invalid=2754, Unknown=0, NotChecked=0, Total=3422 [2023-11-21 22:12:19,586 INFO L413 NwaCegarLoop]: 110 mSDtfsCounter, 796 mSDsluCounter, 667 mSDsCounter, 0 mSdLazyCounter, 1055 mSolverCounterSat, 522 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 803 SdHoareTripleChecker+Valid, 777 SdHoareTripleChecker+Invalid, 1577 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 522 IncrementalHoareTripleChecker+Valid, 1055 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.1s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:19,587 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [803 Valid, 777 Invalid, 1577 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [522 Valid, 1055 Invalid, 0 Unknown, 0 Unchecked, 1.1s Time] [2023-11-21 22:12:19,589 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1054 states. [2023-11-21 22:12:19,744 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1054 to 819. [2023-11-21 22:12:19,746 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 819 states, 540 states have (on average 1.162962962962963) internal successors, (628), 597 states have internal predecessors, (628), 143 states have call successors, (143), 124 states have call predecessors, (143), 135 states have return successors, (221), 137 states have call predecessors, (221), 143 states have call successors, (221) [2023-11-21 22:12:19,752 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 819 states to 819 states and 992 transitions. [2023-11-21 22:12:19,753 INFO L78 Accepts]: Start accepts. Automaton has 819 states and 992 transitions. Word has length 68 [2023-11-21 22:12:19,755 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:19,755 INFO L495 AbstractCegarLoop]: Abstraction has 819 states and 992 transitions. [2023-11-21 22:12:19,755 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 23 states, 19 states have (on average 5.0) internal successors, (95), 21 states have internal predecessors, (95), 12 states have call successors, (26), 8 states have call predecessors, (26), 10 states have return successors, (23), 11 states have call predecessors, (23), 12 states have call successors, (23) [2023-11-21 22:12:19,755 INFO L276 IsEmpty]: Start isEmpty. Operand 819 states and 992 transitions. [2023-11-21 22:12:19,757 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 86 [2023-11-21 22:12:19,758 INFO L187 NwaCegarLoop]: Found error trace [2023-11-21 22:12:19,758 INFO L195 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:19,785 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Forceful destruction successful, exit code 0 [2023-11-21 22:12:19,978 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:19,979 INFO L420 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2023-11-21 22:12:19,979 INFO L160 PredicateUnifier]: Initialized classic predicate unifier [2023-11-21 22:12:19,979 INFO L85 PathProgramCache]: Analyzing trace with hash 2071870669, now seen corresponding path program 1 times [2023-11-21 22:12:19,979 INFO L118 FreeRefinementEngine]: Executing refinement strategy CAMEL [2023-11-21 22:12:19,980 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1410021582] [2023-11-21 22:12:19,980 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:19,980 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2023-11-21 22:12:20,001 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,536 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 5 [2023-11-21 22:12:20,538 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,565 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-21 22:12:20,568 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,637 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:20,638 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,647 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 7 [2023-11-21 22:12:20,649 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,662 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 36 [2023-11-21 22:12:20,666 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,825 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 1 [2023-11-21 22:12:20,827 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,829 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 11 [2023-11-21 22:12:20,830 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,833 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 63 [2023-11-21 22:12:20,835 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,837 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 69 [2023-11-21 22:12:20,839 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,886 INFO L376 atingTraceCheckCraig]: Compute interpolants for subsequence at non-pending call position 78 [2023-11-21 22:12:20,888 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:20,889 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 29 proven. 24 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2023-11-21 22:12:20,890 INFO L136 FreeRefinementEngine]: Strategy CAMEL found an infeasible trace [2023-11-21 22:12:20,890 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1410021582] [2023-11-21 22:12:20,890 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1410021582] provided 0 perfect and 1 imperfect interpolant sequences [2023-11-21 22:12:20,890 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [724078779] [2023-11-21 22:12:20,890 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2023-11-21 22:12:20,891 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:20,891 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 [2023-11-21 22:12:20,892 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2023-11-21 22:12:20,920 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2023-11-21 22:12:21,009 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2023-11-21 22:12:21,012 INFO L262 TraceCheckSpWp]: Trace formula consists of 354 conjuncts, 29 conjunts are in the unsatisfiable core [2023-11-21 22:12:21,023 INFO L285 TraceCheckSpWp]: Computing forward predicates... [2023-11-21 22:12:21,524 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 53 proven. 17 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2023-11-21 22:12:21,524 INFO L327 TraceCheckSpWp]: Computing backward predicates... [2023-11-21 22:12:22,183 INFO L134 CoverageAnalysis]: Checked inductivity of 76 backedges. 49 proven. 5 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2023-11-21 22:12:22,184 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [724078779] provided 0 perfect and 2 imperfect interpolant sequences [2023-11-21 22:12:22,184 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2023-11-21 22:12:22,184 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [22, 12, 11] total 36 [2023-11-21 22:12:22,184 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [710664117] [2023-11-21 22:12:22,184 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2023-11-21 22:12:22,185 INFO L571 AbstractCegarLoop]: INTERPOLANT automaton has 36 states [2023-11-21 22:12:22,185 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy CAMEL [2023-11-21 22:12:22,187 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 36 interpolants. [2023-11-21 22:12:22,187 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=232, Invalid=1028, Unknown=0, NotChecked=0, Total=1260 [2023-11-21 22:12:22,188 INFO L87 Difference]: Start difference. First operand 819 states and 992 transitions. Second operand has 36 states, 35 states have (on average 3.9714285714285715) internal successors, (139), 34 states have internal predecessors, (139), 15 states have call successors, (27), 9 states have call predecessors, (27), 13 states have return successors, (25), 17 states have call predecessors, (25), 15 states have call successors, (25) [2023-11-21 22:12:25,076 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2023-11-21 22:12:25,077 INFO L93 Difference]: Finished difference Result 1673 states and 2054 transitions. [2023-11-21 22:12:25,077 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 55 states. [2023-11-21 22:12:25,078 INFO L78 Accepts]: Start accepts. Automaton has has 36 states, 35 states have (on average 3.9714285714285715) internal successors, (139), 34 states have internal predecessors, (139), 15 states have call successors, (27), 9 states have call predecessors, (27), 13 states have return successors, (25), 17 states have call predecessors, (25), 15 states have call successors, (25) Word has length 85 [2023-11-21 22:12:25,079 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2023-11-21 22:12:25,080 INFO L225 Difference]: With dead ends: 1673 [2023-11-21 22:12:25,080 INFO L226 Difference]: Without dead ends: 0 [2023-11-21 22:12:25,088 INFO L412 NwaCegarLoop]: 0 DeclaredPredicates, 293 GetRequests, 206 SyntacticMatches, 4 SemanticMatches, 83 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2167 ImplicationChecksByTransitivity, 1.7s TimeCoverageRelationStatistics Valid=1465, Invalid=5675, Unknown=0, NotChecked=0, Total=7140 [2023-11-21 22:12:25,089 INFO L413 NwaCegarLoop]: 107 mSDtfsCounter, 1042 mSDsluCounter, 870 mSDsCounter, 0 mSdLazyCounter, 1860 mSolverCounterSat, 743 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1046 SdHoareTripleChecker+Valid, 977 SdHoareTripleChecker+Invalid, 2603 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 743 IncrementalHoareTripleChecker+Valid, 1860 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.4s IncrementalHoareTripleChecker+Time [2023-11-21 22:12:25,090 INFO L414 NwaCegarLoop]: SdHoareTripleChecker [1046 Valid, 977 Invalid, 2603 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [743 Valid, 1860 Invalid, 0 Unknown, 0 Unchecked, 1.4s Time] [2023-11-21 22:12:25,091 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2023-11-21 22:12:25,091 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2023-11-21 22:12:25,092 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2023-11-21 22:12:25,092 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2023-11-21 22:12:25,092 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 85 [2023-11-21 22:12:25,093 INFO L84 Accepts]: Finished accepts. word is rejected. [2023-11-21 22:12:25,093 INFO L495 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2023-11-21 22:12:25,093 INFO L496 AbstractCegarLoop]: INTERPOLANT automaton has has 36 states, 35 states have (on average 3.9714285714285715) internal successors, (139), 34 states have internal predecessors, (139), 15 states have call successors, (27), 9 states have call predecessors, (27), 13 states have return successors, (25), 17 states have call predecessors, (25), 15 states have call successors, (25) [2023-11-21 22:12:25,093 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2023-11-21 22:12:25,093 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2023-11-21 22:12:25,097 INFO L805 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2023-11-21 22:12:25,123 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Forceful destruction successful, exit code 0 [2023-11-21 22:12:25,318 WARN L477 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9,4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2023-11-21 22:12:25,320 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2023-11-21 22:12:31,116 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__baseEXIT(lines 102 108) no Hoare annotation was computed. [2023-11-21 22:12:31,117 INFO L902 garLoopResultBuilder]: At program point processEnvironment__wrappee__baseFINAL(lines 102 108) the Hoare annotation is: true [2023-11-21 22:12:31,117 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 377 388) the Hoare annotation is: true [2023-11-21 22:12:31,117 INFO L899 garLoopResultBuilder]: For program point changeMethaneLevelEXIT(lines 377 388) no Hoare annotation was computed. [2023-11-21 22:12:31,117 INFO L899 garLoopResultBuilder]: For program point L929(line 929) no Hoare annotation was computed. [2023-11-21 22:12:31,117 INFO L899 garLoopResultBuilder]: For program point cleanupEXIT(lines 908 937) no Hoare annotation was computed. [2023-11-21 22:12:31,118 INFO L899 garLoopResultBuilder]: For program point L922(lines 922 926) no Hoare annotation was computed. [2023-11-21 22:12:31,118 INFO L902 garLoopResultBuilder]: At program point L922-1(lines 922 926) the Hoare annotation is: true [2023-11-21 22:12:31,118 INFO L902 garLoopResultBuilder]: At program point L918-2(lines 918 932) the Hoare annotation is: true [2023-11-21 22:12:31,118 INFO L902 garLoopResultBuilder]: At program point L914(line 914) the Hoare annotation is: true [2023-11-21 22:12:31,118 INFO L899 garLoopResultBuilder]: For program point L914-1(line 914) no Hoare annotation was computed. [2023-11-21 22:12:31,118 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 908 937) the Hoare annotation is: true [2023-11-21 22:12:31,119 INFO L899 garLoopResultBuilder]: For program point L933(lines 908 937) no Hoare annotation was computed. [2023-11-21 22:12:31,119 INFO L895 garLoopResultBuilder]: At program point L155(line 155) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= ~pumpRunning~0 0)) (.cse2 (= ~switchedOnBeforeTS~0 0)) (.cse5 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (= |old(~waterLevel~0)| 2))) (.cse4 (= 0 ~systemActive~0))) (and (or .cse0 (and .cse1 (= 2 ~waterLevel~0) .cse2) .cse3 .cse4) (or (< 1 |old(~waterLevel~0)|) (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) .cse5 .cse4) (or .cse0 (and (not (= |old(~waterLevel~0)| 1)) (<= 1 |old(~waterLevel~0)|)) .cse4 (and .cse1 (= |old(~waterLevel~0)| ~waterLevel~0) .cse2)) (or .cse5 .cse3 .cse4))) [2023-11-21 22:12:31,119 INFO L899 garLoopResultBuilder]: For program point L155-1(lines 136 160) no Hoare annotation was computed. [2023-11-21 22:12:31,120 INFO L899 garLoopResultBuilder]: For program point L89-1(lines 89 95) no Hoare annotation was computed. [2023-11-21 22:12:31,120 INFO L895 garLoopResultBuilder]: At program point L849(line 849) the Hoare annotation is: (let ((.cse12 (= ~switchedOnBeforeTS~0 0))) (let ((.cse0 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse10 (not (= |old(~pumpRunning~0)| 0))) (.cse3 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| ~waterLevel~0)) (.cse9 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse6 (not .cse12)) (.cse7 (= ~pumpRunning~0 0)) (.cse2 (= ~switchedOnBeforeTS~0 1)) (.cse4 (= ~pumpRunning~0 1)) (.cse5 (not (= |old(~pumpRunning~0)| 1))) (.cse11 (not (= |old(~waterLevel~0)| 2))) (.cse8 (= 0 ~systemActive~0))) (and (let ((.cse1 (or (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) (<= 1 |old(~waterLevel~0)|)) (and (<= |old(~waterLevel~0)| 0) .cse9)))) (or .cse0 (and .cse1 .cse2 .cse3 .cse4) (not (= |old(~waterLevel~0)| 1)) .cse5 (and .cse6 .cse7 .cse1 .cse3) .cse8)) (or .cse10 .cse11 .cse8) (or .cse0 (and .cse2 .cse3 .cse9 .cse4) (< 0 |old(~waterLevel~0)|) .cse5 (and .cse6 .cse7 .cse3 .cse9) .cse8) (or (< 1 |old(~waterLevel~0)|) .cse10 (and .cse7 .cse3 .cse9 .cse12) .cse8) (let ((.cse13 (= |timeShift___utac_acc__Specification5_spec__3_~tmp~8#1| 1)) (.cse14 (= ~waterLevel~0 1))) (or (and .cse6 .cse7 .cse13 .cse14) (and .cse2 .cse13 .cse14 .cse4) .cse5 .cse11 .cse8))))) [2023-11-21 22:12:31,120 INFO L899 garLoopResultBuilder]: For program point L849-1(line 849) no Hoare annotation was computed. [2023-11-21 22:12:31,121 INFO L899 garLoopResultBuilder]: For program point L82-2(lines 78 100) no Hoare annotation was computed. [2023-11-21 22:12:31,121 INFO L899 garLoopResultBuilder]: For program point L144(lines 144 152) no Hoare annotation was computed. [2023-11-21 22:12:31,121 INFO L899 garLoopResultBuilder]: For program point L140(lines 140 157) no Hoare annotation was computed. [2023-11-21 22:12:31,121 INFO L895 garLoopResultBuilder]: At program point L834(line 834) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse1 (= ~pumpRunning~0 1))) (and (or (< 1 |old(~waterLevel~0)|) (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and (= ~switchedOnBeforeTS~0 1) .cse0 .cse1) .cse2 .cse3) (or (and (= ~pumpRunning~0 0) .cse4 .cse0) (not (= |old(~pumpRunning~0)| 0)) .cse3 (< 2 |old(~waterLevel~0)|)) (or .cse2 (not (= |old(~waterLevel~0)| 2)) .cse3 (and (= 2 ~waterLevel~0) .cse4 .cse1)))) [2023-11-21 22:12:31,121 INFO L899 garLoopResultBuilder]: For program point L834-1(line 834) no Hoare annotation was computed. [2023-11-21 22:12:31,122 INFO L899 garLoopResultBuilder]: For program point L54(line 54) no Hoare annotation was computed. [2023-11-21 22:12:31,122 INFO L899 garLoopResultBuilder]: For program point L851(lines 851 861) no Hoare annotation was computed. [2023-11-21 22:12:31,122 INFO L899 garLoopResultBuilder]: For program point L847(lines 847 864) no Hoare annotation was computed. [2023-11-21 22:12:31,122 INFO L899 garLoopResultBuilder]: For program point L847-1(lines 839 867) no Hoare annotation was computed. [2023-11-21 22:12:31,123 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 75 101) the Hoare annotation is: (let ((.cse0 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse2 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= 0 ~systemActive~0)) (.cse4 (= ~switchedOnBeforeTS~0 |old(~switchedOnBeforeTS~0)|)) (.cse1 (= ~pumpRunning~0 1))) (and (or (< 1 |old(~waterLevel~0)|) (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (and (= ~switchedOnBeforeTS~0 1) .cse0 .cse1) .cse2 .cse3) (or (and (= ~pumpRunning~0 0) .cse4 .cse0) (not (= |old(~pumpRunning~0)| 0)) .cse3 (< 2 |old(~waterLevel~0)|)) (or .cse2 (not (= |old(~waterLevel~0)| 2)) .cse3 (and (= 2 ~waterLevel~0) .cse4 .cse1)))) [2023-11-21 22:12:31,123 INFO L895 garLoopResultBuilder]: At program point L150(line 150) the Hoare annotation is: (let ((.cse1 (not (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|))) (.cse2 (= ~switchedOnBeforeTS~0 1)) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (not (= |old(~pumpRunning~0)| 1))) (.cse0 (= 0 ~systemActive~0))) (and (or (not (= |old(~pumpRunning~0)| 0)) .cse0 (< 2 |old(~waterLevel~0)|)) (or .cse1 (and .cse2 (= |old(~waterLevel~0)| ~waterLevel~0) .cse3) (< 0 |old(~waterLevel~0)|) .cse4 .cse0) (or (and .cse2 (= ~waterLevel~0 1) .cse3) .cse4 (not (= |old(~waterLevel~0)| 2)) .cse0) (or .cse1 (not (= |old(~waterLevel~0)| 1)) (and (= |old(~waterLevel~0)| (+ ~waterLevel~0 1)) .cse2 .cse3) .cse4 .cse0))) [2023-11-21 22:12:31,123 INFO L899 garLoopResultBuilder]: For program point L852(lines 852 858) no Hoare annotation was computed. [2023-11-21 22:12:31,123 INFO L899 garLoopResultBuilder]: For program point timeShiftEXIT(lines 75 101) no Hoare annotation was computed. [2023-11-21 22:12:31,124 INFO L899 garLoopResultBuilder]: For program point timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION(line 54) no Hoare annotation was computed. [2023-11-21 22:12:31,124 INFO L895 garLoopResultBuilder]: At program point L341(lines 292 342) the Hoare annotation is: false [2023-11-21 22:12:31,124 INFO L899 garLoopResultBuilder]: For program point L990(lines 990 997) no Hoare annotation was computed. [2023-11-21 22:12:31,124 INFO L899 garLoopResultBuilder]: For program point L990-2(lines 990 997) no Hoare annotation was computed. [2023-11-21 22:12:31,124 INFO L899 garLoopResultBuilder]: For program point L313(lines 313 319) no Hoare annotation was computed. [2023-11-21 22:12:31,124 INFO L899 garLoopResultBuilder]: For program point L313-1(lines 313 319) no Hoare annotation was computed. [2023-11-21 22:12:31,125 INFO L895 garLoopResultBuilder]: At program point L338(lines 293 340) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse6 (= 2 ~waterLevel~0)) (.cse0 (= |ULTIMATE.start_main_~tmp~9#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= ~switchedOnBeforeTS~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1) .cse4) (and .cse5 .cse6 .cse0 .cse1 .cse3) (and .cse5 (<= ~waterLevel~0 1) .cse0 .cse1 .cse3) (and .cse6 .cse0 .cse1 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 (<= ~waterLevel~0 0) .cse4))) [2023-11-21 22:12:31,125 INFO L895 garLoopResultBuilder]: At program point L305(line 305) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse6 (= 2 ~waterLevel~0)) (.cse0 (= |ULTIMATE.start_main_~tmp~9#1| 1)) (.cse1 (= 1 ~systemActive~0)) (.cse2 (= ~switchedOnBeforeTS~0 1)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 .cse3 (= ~waterLevel~0 1) .cse4) (and .cse5 .cse6 .cse0 .cse1 .cse3) (and .cse5 (<= ~waterLevel~0 1) .cse0 .cse1 .cse3) (and .cse6 .cse0 .cse1 .cse3 .cse4) (and .cse0 .cse1 .cse2 .cse3 (<= ~waterLevel~0 0) .cse4))) [2023-11-21 22:12:31,125 INFO L899 garLoopResultBuilder]: For program point ULTIMATE.startEXIT(line -1) no Hoare annotation was computed. [2023-11-21 22:12:31,126 INFO L899 garLoopResultBuilder]: For program point $Ultimate##0(line -1) no Hoare annotation was computed. [2023-11-21 22:12:31,126 INFO L895 garLoopResultBuilder]: At program point L331-2(lines 323 336) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse0 (<= ~waterLevel~0 1)) (.cse6 (= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_main_~tmp~9#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 (= ~switchedOnBeforeTS~0 1) .cse3 .cse4) (and .cse5 .cse6 .cse1 .cse2 .cse3) (and .cse5 .cse0 .cse1 .cse2 .cse3) (and .cse6 .cse1 .cse2 .cse3 .cse4))) [2023-11-21 22:12:31,126 INFO L899 garLoopResultBuilder]: For program point L294(lines 293 340) no Hoare annotation was computed. [2023-11-21 22:12:31,126 INFO L895 garLoopResultBuilder]: At program point L315(line 315) the Hoare annotation is: (let ((.cse5 (= ~pumpRunning~0 0)) (.cse0 (<= ~waterLevel~0 1)) (.cse6 (= 2 ~waterLevel~0)) (.cse1 (= |ULTIMATE.start_main_~tmp~9#1| 1)) (.cse2 (= 1 ~systemActive~0)) (.cse3 (= |ULTIMATE.start_test_~splverifierCounter~0#1| 0)) (.cse4 (= ~pumpRunning~0 1))) (or (and .cse0 .cse1 .cse2 (= ~switchedOnBeforeTS~0 1) .cse3 .cse4) (and .cse5 .cse6 .cse1 .cse2 .cse3) (and .cse5 .cse0 .cse1 .cse2 .cse3) (and .cse6 .cse1 .cse2 .cse3 .cse4))) [2023-11-21 22:12:31,127 INFO L899 garLoopResultBuilder]: For program point L344(lines 283 348) no Hoare annotation was computed. [2023-11-21 22:12:31,127 INFO L899 garLoopResultBuilder]: For program point L303(lines 303 309) no Hoare annotation was computed. [2023-11-21 22:12:31,127 INFO L899 garLoopResultBuilder]: For program point L303-1(lines 303 309) no Hoare annotation was computed. [2023-11-21 22:12:31,127 INFO L895 garLoopResultBuilder]: At program point L124(line 124) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (< 0 ~waterLevel~0) .cse0 .cse1 .cse2) (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2) (or .cse3 (= |processEnvironment__wrappee__highWaterSensor_~tmp~0#1| 0) (< 1 ~waterLevel~0) .cse1 .cse2) (or (< 2 ~waterLevel~0) .cse3 (= ~pumpRunning~0 0) .cse1 .cse2))) [2023-11-21 22:12:31,127 INFO L899 garLoopResultBuilder]: For program point L118(lines 118 126) no Hoare annotation was computed. [2023-11-21 22:12:31,128 INFO L899 garLoopResultBuilder]: For program point L114(lines 114 131) no Hoare annotation was computed. [2023-11-21 22:12:31,128 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 110 134) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse5 (= ~pumpRunning~0 0)) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 (not (= 2 ~waterLevel~0)) .cse1 .cse2) (or (< 0 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (or .cse4 .cse5 (< 1 ~waterLevel~0) .cse1 .cse2))) [2023-11-21 22:12:31,128 INFO L895 garLoopResultBuilder]: At program point L129(line 129) the Hoare annotation is: (let ((.cse0 (not (= |old(~pumpRunning~0)| 1))) (.cse3 (= ~pumpRunning~0 1)) (.cse4 (not (= |old(~pumpRunning~0)| 0))) (.cse1 (= 0 ~systemActive~0)) (.cse2 (not (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|)))) (and (or (not (= ~waterLevel~0 1)) .cse0 .cse1 .cse2 .cse3) (or (< 0 ~waterLevel~0) .cse0 .cse1 .cse2 .cse3) (or .cse4 (not (= 2 ~waterLevel~0)) .cse1 .cse2) (or .cse4 (< 1 ~waterLevel~0) .cse1 .cse2))) [2023-11-21 22:12:31,129 INFO L899 garLoopResultBuilder]: For program point L129-1(lines 110 134) no Hoare annotation was computed. [2023-11-21 22:12:31,129 INFO L899 garLoopResultBuilder]: For program point processEnvironment__wrappee__highWaterSensorEXIT(lines 110 134) no Hoare annotation was computed. [2023-11-21 22:12:31,129 INFO L899 garLoopResultBuilder]: For program point waterRiseEXIT(lines 365 376) no Hoare annotation was computed. [2023-11-21 22:12:31,129 INFO L895 garLoopResultBuilder]: At program point $Ultimate##0(lines 365 376) the Hoare annotation is: (let ((.cse1 (not (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) (.cse3 (= ~switchedOnBeforeTS~0 0)) (.cse4 (= |old(~waterLevel~0)| ~waterLevel~0)) (.cse5 (not (= ~pumpRunning~0 0))) (.cse6 (= 2 ~waterLevel~0)) (.cse0 (not (= ~pumpRunning~0 1))) (.cse7 (not (= |old(~waterLevel~0)| 2))) (.cse2 (= 0 ~systemActive~0))) (and (or (not (= |old(~waterLevel~0)| 1)) .cse0 .cse1 .cse2 (= ~waterLevel~0 1) .cse3) (or (< 0 |old(~waterLevel~0)|) .cse0 .cse1 .cse4 .cse2 .cse3) (or (< 1 |old(~waterLevel~0)|) .cse5 .cse4 .cse2) (or .cse5 .cse6 .cse7 .cse2) (or .cse6 .cse0 .cse7 .cse2))) [2023-11-21 22:12:31,129 INFO L899 garLoopResultBuilder]: For program point isPumpRunningEXIT(lines 188 196) no Hoare annotation was computed. [2023-11-21 22:12:31,130 INFO L902 garLoopResultBuilder]: At program point $Ultimate##0(lines 188 196) the Hoare annotation is: true [2023-11-21 22:12:31,132 INFO L445 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2023-11-21 22:12:31,135 INFO L178 ceAbstractionStarter]: Computing trace abstraction results [2023-11-21 22:12:31,148 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 21.11 10:12:31 BoogieIcfgContainer [2023-11-21 22:12:31,148 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2023-11-21 22:12:31,149 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2023-11-21 22:12:31,149 INFO L270 PluginConnector]: Initializing Witness Printer... [2023-11-21 22:12:31,149 INFO L274 PluginConnector]: Witness Printer initialized [2023-11-21 22:12:31,150 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 21.11 10:12:07" (3/4) ... [2023-11-21 22:12:31,152 INFO L137 WitnessPrinter]: Generating witness for correct program [2023-11-21 22:12:31,155 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2023-11-21 22:12:31,155 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2023-11-21 22:12:31,155 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2023-11-21 22:12:31,156 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2023-11-21 22:12:31,156 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2023-11-21 22:12:31,156 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2023-11-21 22:12:31,156 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2023-11-21 22:12:31,182 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 47 nodes and edges [2023-11-21 22:12:31,183 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2023-11-21 22:12:31,184 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2023-11-21 22:12:31,184 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-21 22:12:31,185 INFO L943 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2023-11-21 22:12:31,304 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/witness.graphml [2023-11-21 22:12:31,305 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/witness.yml [2023-11-21 22:12:31,306 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2023-11-21 22:12:31,306 INFO L158 Benchmark]: Toolchain (without parser) took 25443.02ms. Allocated memory was 115.3MB in the beginning and 310.4MB in the end (delta: 195.0MB). Free memory was 70.7MB in the beginning and 272.0MB in the end (delta: -201.3MB). Peak memory consumption was 172.0MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,307 INFO L158 Benchmark]: CDTParser took 0.34ms. Allocated memory is still 115.3MB. Free memory is still 86.4MB. There was no memory consumed. Max. memory is 16.1GB. [2023-11-21 22:12:31,307 INFO L158 Benchmark]: CACSL2BoogieTranslator took 548.32ms. Allocated memory is still 115.3MB. Free memory was 70.3MB in the beginning and 50.7MB in the end (delta: 19.6MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,308 INFO L158 Benchmark]: Boogie Procedure Inliner took 74.77ms. Allocated memory is still 115.3MB. Free memory was 50.7MB in the beginning and 87.5MB in the end (delta: -36.7MB). Peak memory consumption was 6.8MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,308 INFO L158 Benchmark]: Boogie Preprocessor took 76.52ms. Allocated memory is still 115.3MB. Free memory was 87.5MB in the beginning and 85.1MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,308 INFO L158 Benchmark]: RCFGBuilder took 698.19ms. Allocated memory is still 115.3MB. Free memory was 85.1MB in the beginning and 56.2MB in the end (delta: 28.9MB). Peak memory consumption was 29.4MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,309 INFO L158 Benchmark]: TraceAbstraction took 23877.88ms. Allocated memory was 115.3MB in the beginning and 310.4MB in the end (delta: 195.0MB). Free memory was 55.5MB in the beginning and 99.1MB in the end (delta: -43.6MB). Peak memory consumption was 156.9MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,310 INFO L158 Benchmark]: Witness Printer took 156.97ms. Allocated memory is still 310.4MB. Free memory was 99.1MB in the beginning and 272.0MB in the end (delta: -172.9MB). Peak memory consumption was 2.2MB. Max. memory is 16.1GB. [2023-11-21 22:12:31,312 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.34ms. Allocated memory is still 115.3MB. Free memory is still 86.4MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 548.32ms. Allocated memory is still 115.3MB. Free memory was 70.3MB in the beginning and 50.7MB in the end (delta: 19.6MB). Peak memory consumption was 18.9MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 74.77ms. Allocated memory is still 115.3MB. Free memory was 50.7MB in the beginning and 87.5MB in the end (delta: -36.7MB). Peak memory consumption was 6.8MB. Max. memory is 16.1GB. * Boogie Preprocessor took 76.52ms. Allocated memory is still 115.3MB. Free memory was 87.5MB in the beginning and 85.1MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 698.19ms. Allocated memory is still 115.3MB. Free memory was 85.1MB in the beginning and 56.2MB in the end (delta: 28.9MB). Peak memory consumption was 29.4MB. Max. memory is 16.1GB. * TraceAbstraction took 23877.88ms. Allocated memory was 115.3MB in the beginning and 310.4MB in the end (delta: 195.0MB). Free memory was 55.5MB in the beginning and 99.1MB in the end (delta: -43.6MB). Peak memory consumption was 156.9MB. Max. memory is 16.1GB. * Witness Printer took 156.97ms. Allocated memory is still 310.4MB. Free memory was 99.1MB in the beginning and 272.0MB in the end (delta: -172.9MB). Peak memory consumption was 2.2MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] - GenericResultAtLocation [Line: 58]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [58] - GenericResultAtLocation [Line: 279]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [279] - GenericResultAtLocation [Line: 349]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [349] - GenericResultAtLocation [Line: 453]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [453] - GenericResultAtLocation [Line: 819]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [819] - GenericResultAtLocation [Line: 868]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [868] - GenericResultAtLocation [Line: 906]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [906] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 8 procedures, 58 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 23.8s, OverallIterations: 10, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.1s, AutomataDifference: 9.2s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 5.8s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2766 SdHoareTripleChecker+Valid, 4.6s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2722 mSDsluCounter, 3553 SdHoareTripleChecker+Invalid, 3.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2869 mSDsCounter, 1683 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 5263 IncrementalHoareTripleChecker+Invalid, 6946 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1683 mSolverCounterUnsat, 684 mSDtfsCounter, 5263 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 813 GetRequests, 554 SyntacticMatches, 4 SemanticMatches, 255 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3526 ImplicationChecksByTransitivity, 4.1s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=819occurred in iteration=9, InterpolantAutomatonStates: 213, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.8s AutomataMinimizationTime, 10 MinimizatonAttempts, 558 StatesRemovedByMinimization, 7 NontrivialMinimizations, HoareAnnotationStatistics: 0.0s HoareAnnotationTime, 21 LocationsWithAnnotation, 1454 PreInvPairs, 1611 NumberOfFragments, 1108 HoareAnnotationTreeSize, 1454 FomulaSimplifications, 38096 FormulaSimplificationTreeSizeReduction, 1.3s HoareSimplificationTime, 21 FomulaSimplificationsInter, 22177 FormulaSimplificationTreeSizeReductionInter, 4.4s HoareSimplificationTimeInter, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 6.3s InterpolantComputationTime, 654 NumberOfCodeBlocks, 654 NumberOfCodeBlocksAsserted, 13 NumberOfCheckSat, 846 ConstructedInterpolants, 0 QuantifiedInterpolants, 3659 SizeOfPredicates, 23 NumberOfNonLiveVariables, 906 ConjunctsInSsa, 73 ConjunctsInUnsatCore, 16 InterpolantComputations, 7 PerfectInterpolantSequences, 367/449 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 293]: Loop Invariant Derived loop invariant: ((((((((((tmp == 1) && (1 == systemActive)) && (switchedOnBeforeTS == 1)) && (splverifierCounter == 0)) && (waterLevel == 1)) && (pumpRunning == 1)) || (((((pumpRunning == 0) && (2 == waterLevel)) && (tmp == 1)) && (1 == systemActive)) && (splverifierCounter == 0))) || (((((pumpRunning == 0) && (waterLevel <= 1)) && (tmp == 1)) && (1 == systemActive)) && (splverifierCounter == 0))) || (((((2 == waterLevel) && (tmp == 1)) && (1 == systemActive)) && (splverifierCounter == 0)) && (pumpRunning == 1))) || ((((((tmp == 1) && (1 == systemActive)) && (switchedOnBeforeTS == 1)) && (splverifierCounter == 0)) && (waterLevel <= 0)) && (pumpRunning == 1))) - InvariantResult [Line: 292]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 918]: Loop Invariant Derived loop invariant: 1 RESULT: Ultimate proved your program to be correct! [2023-11-21 22:12:31,354 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_154a2a5a-a41b-4515-9b3a-4af77682024f/bin/uautomizer-verify-bycVGegfSx/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE