./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version a0165632 Calling Ultimate with: /usr/lib/jvm/java-11-openjdk-amd64/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/plugins/org.eclipse.equinox.launcher_1.5.800.v20200727-1323.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje --witnessprinter.witness.filename witness --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 4d13ffd2557e7d7902d8a5eac414f9fb7393252d85c14855e86000741be6847f --- Real Ultimate output --- This is Ultimate 0.2.5-dev-a016563 [2024-11-09 06:22:44,833 INFO L188 SettingsManager]: Resetting all preferences to default values... [2024-11-09 06:22:44,932 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/config/svcomp-Reach-32bit-Taipan_Default.epf [2024-11-09 06:22:44,938 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2024-11-09 06:22:44,940 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2024-11-09 06:22:44,976 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2024-11-09 06:22:44,978 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2024-11-09 06:22:44,979 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2024-11-09 06:22:44,980 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2024-11-09 06:22:44,981 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2024-11-09 06:22:44,981 INFO L153 SettingsManager]: * User list type=DISABLED [2024-11-09 06:22:44,982 INFO L151 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2024-11-09 06:22:44,983 INFO L153 SettingsManager]: * Explicit value domain=true [2024-11-09 06:22:44,983 INFO L153 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2024-11-09 06:22:44,985 INFO L153 SettingsManager]: * Octagon Domain=false [2024-11-09 06:22:44,986 INFO L153 SettingsManager]: * Abstract domain=CompoundDomain [2024-11-09 06:22:44,986 INFO L153 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2024-11-09 06:22:44,987 INFO L153 SettingsManager]: * Use the RCFG-of-the-future interface=true [2024-11-09 06:22:44,987 INFO L153 SettingsManager]: * Interval Domain=false [2024-11-09 06:22:44,987 INFO L151 SettingsManager]: Preferences of Sifa differ from their defaults: [2024-11-09 06:22:44,988 INFO L153 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2024-11-09 06:22:44,991 INFO L153 SettingsManager]: * Simplification Technique=POLY_PAC [2024-11-09 06:22:44,991 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2024-11-09 06:22:44,992 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2024-11-09 06:22:44,992 INFO L153 SettingsManager]: * sizeof long=4 [2024-11-09 06:22:44,992 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2024-11-09 06:22:45,011 INFO L153 SettingsManager]: * sizeof POINTER=4 [2024-11-09 06:22:45,012 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2024-11-09 06:22:45,012 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2024-11-09 06:22:45,012 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2024-11-09 06:22:45,013 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2024-11-09 06:22:45,013 INFO L153 SettingsManager]: * Allow undefined functions=false [2024-11-09 06:22:45,013 INFO L153 SettingsManager]: * sizeof long double=12 [2024-11-09 06:22:45,014 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2024-11-09 06:22:45,014 INFO L153 SettingsManager]: * Use constant arrays=true [2024-11-09 06:22:45,015 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2024-11-09 06:22:45,016 INFO L153 SettingsManager]: * Only consider context switches at boundaries of atomic blocks=true [2024-11-09 06:22:45,017 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2024-11-09 06:22:45,017 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2024-11-09 06:22:45,018 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2024-11-09 06:22:45,018 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2024-11-09 06:22:45,018 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopHeads [2024-11-09 06:22:45,019 INFO L153 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2024-11-09 06:22:45,020 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2024-11-09 06:22:45,020 INFO L153 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2024-11-09 06:22:45,021 INFO L153 SettingsManager]: * Trace refinement exception blacklist=NONE [2024-11-09 06:22:45,021 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2024-11-09 06:22:45,021 INFO L153 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 (file:/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/plugins/com.sun.xml.bind_2.2.0.v201505121915.jar) to method java.lang.ClassLoader.defineClass(java.lang.String,byte[],int,int) WARNING: Please consider reporting this to the maintainers of com.sun.xml.bind.v2.runtime.reflect.opt.Injector$1 WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 4d13ffd2557e7d7902d8a5eac414f9fb7393252d85c14855e86000741be6847f [2024-11-09 06:22:45,336 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2024-11-09 06:22:45,369 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2024-11-09 06:22:45,372 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2024-11-09 06:22:45,375 INFO L270 PluginConnector]: Initializing CDTParser... [2024-11-09 06:22:45,376 INFO L274 PluginConnector]: CDTParser initialized [2024-11-09 06:22:45,377 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/../../sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c Unable to find full path for "g++" [2024-11-09 06:22:47,354 INFO L533 CDTParser]: Created temporary CDT project at NULL [2024-11-09 06:22:47,599 INFO L384 CDTParser]: Found 1 translation units. [2024-11-09 06:22:47,600 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c [2024-11-09 06:22:47,625 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/data/fe1f49551/66399dc2db814d5fa1f5c2e3c06415e6/FLAG8840dc68f [2024-11-09 06:22:47,639 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/data/fe1f49551/66399dc2db814d5fa1f5c2e3c06415e6 [2024-11-09 06:22:47,642 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2024-11-09 06:22:47,644 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2024-11-09 06:22:47,645 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2024-11-09 06:22:47,645 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2024-11-09 06:22:47,651 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2024-11-09 06:22:47,652 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 09.11 06:22:47" (1/1) ... [2024-11-09 06:22:47,654 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@16637f57 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:47, skipping insertion in model container [2024-11-09 06:22:47,654 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 09.11 06:22:47" (1/1) ... [2024-11-09 06:22:47,702 INFO L175 MainTranslator]: Built tables and reachable declarations [2024-11-09 06:22:47,920 WARN L250 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c[1605,1618] [2024-11-09 06:22:48,076 INFO L210 PostProcessor]: Analyzing one entry point: main [2024-11-09 06:22:48,097 INFO L200 MainTranslator]: Completed pre-run [2024-11-09 06:22:48,112 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] [2024-11-09 06:22:48,114 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification3_spec.i","") [58] [2024-11-09 06:22:48,114 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [95] [2024-11-09 06:22:48,115 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [461] [2024-11-09 06:22:48,115 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [570] [2024-11-09 06:22:48,115 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [608] [2024-11-09 06:22:48,116 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [861] [2024-11-09 06:22:48,116 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [929] [2024-11-09 06:22:48,127 WARN L250 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/sv-benchmarks/c/product-lines/minepump_spec3_product62.cil.c[1605,1618] [2024-11-09 06:22:48,241 INFO L210 PostProcessor]: Analyzing one entry point: main [2024-11-09 06:22:48,276 INFO L204 MainTranslator]: Completed translation [2024-11-09 06:22:48,277 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48 WrapperNode [2024-11-09 06:22:48,277 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2024-11-09 06:22:48,278 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2024-11-09 06:22:48,279 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2024-11-09 06:22:48,279 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2024-11-09 06:22:48,288 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,310 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,355 INFO L138 Inliner]: procedures = 58, calls = 106, calls flagged for inlining = 24, calls inlined = 21, statements flattened = 229 [2024-11-09 06:22:48,359 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2024-11-09 06:22:48,360 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2024-11-09 06:22:48,360 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2024-11-09 06:22:48,360 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2024-11-09 06:22:48,370 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,370 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,373 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,377 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,387 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,396 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,397 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,399 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,404 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2024-11-09 06:22:48,409 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2024-11-09 06:22:48,409 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2024-11-09 06:22:48,410 INFO L274 PluginConnector]: RCFGBuilder initialized [2024-11-09 06:22:48,411 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (1/1) ... [2024-11-09 06:22:48,424 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2024-11-09 06:22:48,443 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 [2024-11-09 06:22:48,459 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2024-11-09 06:22:48,466 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2024-11-09 06:22:48,502 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2024-11-09 06:22:48,502 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2024-11-09 06:22:48,502 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2024-11-09 06:22:48,502 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2024-11-09 06:22:48,503 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2024-11-09 06:22:48,504 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2024-11-09 06:22:48,504 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2024-11-09 06:22:48,504 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneLevelCritical [2024-11-09 06:22:48,504 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneLevelCritical [2024-11-09 06:22:48,505 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2024-11-09 06:22:48,505 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2024-11-09 06:22:48,506 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2024-11-09 06:22:48,506 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2024-11-09 06:22:48,507 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__methaneQuery [2024-11-09 06:22:48,507 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__methaneQuery [2024-11-09 06:22:48,507 INFO L130 BoogieDeclarations]: Found specification of procedure isMethaneAlarm [2024-11-09 06:22:48,508 INFO L138 BoogieDeclarations]: Found implementation of procedure isMethaneAlarm [2024-11-09 06:22:48,509 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2024-11-09 06:22:48,509 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2024-11-09 06:22:48,511 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2024-11-09 06:22:48,511 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2024-11-09 06:22:48,511 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2024-11-09 06:22:48,512 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2024-11-09 06:22:48,512 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2024-11-09 06:22:48,639 INFO L238 CfgBuilder]: Building ICFG [2024-11-09 06:22:48,641 INFO L264 CfgBuilder]: Building CFG for each procedure with an implementation [2024-11-09 06:22:49,070 INFO L? ?]: Removed 54 outVars from TransFormulas that were not future-live. [2024-11-09 06:22:49,070 INFO L287 CfgBuilder]: Performing block encoding [2024-11-09 06:22:49,211 INFO L311 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2024-11-09 06:22:49,211 INFO L316 CfgBuilder]: Removed 2 assume(true) statements. [2024-11-09 06:22:49,212 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 09.11 06:22:49 BoogieIcfgContainer [2024-11-09 06:22:49,212 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2024-11-09 06:22:49,215 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2024-11-09 06:22:49,215 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2024-11-09 06:22:49,219 INFO L274 PluginConnector]: TraceAbstraction initialized [2024-11-09 06:22:49,219 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 09.11 06:22:47" (1/3) ... [2024-11-09 06:22:49,220 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@619263d8 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 09.11 06:22:49, skipping insertion in model container [2024-11-09 06:22:49,220 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 09.11 06:22:48" (2/3) ... [2024-11-09 06:22:49,221 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@619263d8 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 09.11 06:22:49, skipping insertion in model container [2024-11-09 06:22:49,221 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 09.11 06:22:49" (3/3) ... [2024-11-09 06:22:49,222 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec3_product62.cil.c [2024-11-09 06:22:49,243 INFO L214 ceAbstractionStarter]: Automizer settings: Hoare:LoopHeads NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2024-11-09 06:22:49,243 INFO L154 ceAbstractionStarter]: Applying trace abstraction to program that has 1 error locations. [2024-11-09 06:22:49,313 INFO L332 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2024-11-09 06:22:49,321 INFO L333 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopHeads, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@3f4142fe, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2024-11-09 06:22:49,321 INFO L334 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2024-11-09 06:22:49,326 INFO L276 IsEmpty]: Start isEmpty. Operand has 75 states, 45 states have (on average 1.4) internal successors, (63), 55 states have internal predecessors, (63), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) [2024-11-09 06:22:49,338 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 18 [2024-11-09 06:22:49,338 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:49,339 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:49,340 INFO L396 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:49,346 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:49,347 INFO L85 PathProgramCache]: Analyzing trace with hash -822215548, now seen corresponding path program 1 times [2024-11-09 06:22:49,360 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:49,361 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1029813036] [2024-11-09 06:22:49,361 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:49,362 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:49,505 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:49,616 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:49,616 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:49,617 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1029813036] [2024-11-09 06:22:49,617 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1029813036] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:49,620 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:49,620 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2024-11-09 06:22:49,622 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [65113861] [2024-11-09 06:22:49,623 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:49,634 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2024-11-09 06:22:49,637 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:49,669 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2024-11-09 06:22:49,670 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2024-11-09 06:22:49,673 INFO L87 Difference]: Start difference. First operand has 75 states, 45 states have (on average 1.4) internal successors, (63), 55 states have internal predecessors, (63), 18 states have call successors, (18), 10 states have call predecessors, (18), 10 states have return successors, (18), 13 states have call predecessors, (18), 18 states have call successors, (18) Second operand has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:49,779 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:49,780 INFO L93 Difference]: Finished difference Result 148 states and 199 transitions. [2024-11-09 06:22:49,782 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2024-11-09 06:22:49,784 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 17 [2024-11-09 06:22:49,785 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:49,793 INFO L225 Difference]: With dead ends: 148 [2024-11-09 06:22:49,793 INFO L226 Difference]: Without dead ends: 70 [2024-11-09 06:22:49,797 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2024-11-09 06:22:49,801 INFO L432 NwaCegarLoop]: 77 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 19 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 77 SdHoareTripleChecker+Invalid, 20 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 19 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:49,802 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 77 Invalid, 20 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 19 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2024-11-09 06:22:49,823 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 70 states. [2024-11-09 06:22:49,857 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 70 to 70. [2024-11-09 06:22:49,860 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 70 states, 42 states have (on average 1.3095238095238095) internal successors, (55), 51 states have internal predecessors, (55), 18 states have call successors, (18), 10 states have call predecessors, (18), 9 states have return successors, (17), 12 states have call predecessors, (17), 17 states have call successors, (17) [2024-11-09 06:22:49,864 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 70 states to 70 states and 90 transitions. [2024-11-09 06:22:49,866 INFO L78 Accepts]: Start accepts. Automaton has 70 states and 90 transitions. Word has length 17 [2024-11-09 06:22:49,867 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:49,867 INFO L471 AbstractCegarLoop]: Abstraction has 70 states and 90 transitions. [2024-11-09 06:22:49,867 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 6.5) internal successors, (13), 2 states have internal predecessors, (13), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:49,868 INFO L276 IsEmpty]: Start isEmpty. Operand 70 states and 90 transitions. [2024-11-09 06:22:49,870 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 19 [2024-11-09 06:22:49,871 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:49,871 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:49,871 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2024-11-09 06:22:49,872 INFO L396 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:49,873 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:49,873 INFO L85 PathProgramCache]: Analyzing trace with hash -1326089735, now seen corresponding path program 1 times [2024-11-09 06:22:49,873 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:49,874 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1845185058] [2024-11-09 06:22:49,874 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:49,874 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:49,897 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:50,016 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:50,017 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:50,017 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1845185058] [2024-11-09 06:22:50,017 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1845185058] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:50,018 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:50,018 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2024-11-09 06:22:50,018 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [51256066] [2024-11-09 06:22:50,018 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:50,019 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2024-11-09 06:22:50,020 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:50,021 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2024-11-09 06:22:50,021 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-09 06:22:50,021 INFO L87 Difference]: Start difference. First operand 70 states and 90 transitions. Second operand has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:50,079 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:50,079 INFO L93 Difference]: Finished difference Result 117 states and 151 transitions. [2024-11-09 06:22:50,080 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2024-11-09 06:22:50,080 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 18 [2024-11-09 06:22:50,080 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:50,082 INFO L225 Difference]: With dead ends: 117 [2024-11-09 06:22:50,082 INFO L226 Difference]: Without dead ends: 62 [2024-11-09 06:22:50,083 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-09 06:22:50,084 INFO L432 NwaCegarLoop]: 63 mSDtfsCounter, 7 mSDsluCounter, 54 mSDsCounter, 0 mSdLazyCounter, 29 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 117 SdHoareTripleChecker+Invalid, 29 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 29 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:50,085 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 117 Invalid, 29 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 29 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2024-11-09 06:22:50,086 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 62 states. [2024-11-09 06:22:50,098 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 62 to 62. [2024-11-09 06:22:50,101 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 62 states, 37 states have (on average 1.3243243243243243) internal successors, (49), 46 states have internal predecessors, (49), 15 states have call successors, (15), 9 states have call predecessors, (15), 9 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2024-11-09 06:22:50,102 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 62 states to 62 states and 79 transitions. [2024-11-09 06:22:50,102 INFO L78 Accepts]: Start accepts. Automaton has 62 states and 79 transitions. Word has length 18 [2024-11-09 06:22:50,103 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:50,103 INFO L471 AbstractCegarLoop]: Abstraction has 62 states and 79 transitions. [2024-11-09 06:22:50,103 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 4.666666666666667) internal successors, (14), 3 states have internal predecessors, (14), 1 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:50,103 INFO L276 IsEmpty]: Start isEmpty. Operand 62 states and 79 transitions. [2024-11-09 06:22:50,104 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 21 [2024-11-09 06:22:50,104 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:50,107 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:50,108 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2024-11-09 06:22:50,108 INFO L396 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:50,109 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:50,109 INFO L85 PathProgramCache]: Analyzing trace with hash -236189220, now seen corresponding path program 1 times [2024-11-09 06:22:50,109 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:50,109 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2117423021] [2024-11-09 06:22:50,110 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:50,110 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:50,137 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:50,456 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:50,456 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:50,457 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2117423021] [2024-11-09 06:22:50,457 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2117423021] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:50,457 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:50,457 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2024-11-09 06:22:50,457 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [24129069] [2024-11-09 06:22:50,458 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:50,458 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2024-11-09 06:22:50,458 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:50,459 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2024-11-09 06:22:50,459 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=8, Invalid=12, Unknown=0, NotChecked=0, Total=20 [2024-11-09 06:22:50,460 INFO L87 Difference]: Start difference. First operand 62 states and 79 transitions. Second operand has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:50,711 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:50,711 INFO L93 Difference]: Finished difference Result 194 states and 248 transitions. [2024-11-09 06:22:50,715 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2024-11-09 06:22:50,716 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) Word has length 20 [2024-11-09 06:22:50,716 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:50,718 INFO L225 Difference]: With dead ends: 194 [2024-11-09 06:22:50,718 INFO L226 Difference]: Without dead ends: 134 [2024-11-09 06:22:50,722 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=18, Invalid=24, Unknown=0, NotChecked=0, Total=42 [2024-11-09 06:22:50,723 INFO L432 NwaCegarLoop]: 67 mSDtfsCounter, 67 mSDsluCounter, 200 mSDsCounter, 0 mSdLazyCounter, 95 mSolverCounterSat, 4 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 267 SdHoareTripleChecker+Invalid, 99 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 4 IncrementalHoareTripleChecker+Valid, 95 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:50,724 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 267 Invalid, 99 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [4 Valid, 95 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2024-11-09 06:22:50,725 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 134 states. [2024-11-09 06:22:50,763 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 134 to 119. [2024-11-09 06:22:50,763 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 119 states, 74 states have (on average 1.2432432432432432) internal successors, (92), 85 states have internal predecessors, (92), 24 states have call successors, (24), 17 states have call predecessors, (24), 20 states have return successors, (27), 21 states have call predecessors, (27), 24 states have call successors, (27) [2024-11-09 06:22:50,765 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 119 states to 119 states and 143 transitions. [2024-11-09 06:22:50,765 INFO L78 Accepts]: Start accepts. Automaton has 119 states and 143 transitions. Word has length 20 [2024-11-09 06:22:50,766 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:50,766 INFO L471 AbstractCegarLoop]: Abstraction has 119 states and 143 transitions. [2024-11-09 06:22:50,766 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 3.4) internal successors, (17), 5 states have internal predecessors, (17), 2 states have call successors, (2), 2 states have call predecessors, (2), 1 states have return successors, (1), 1 states have call predecessors, (1), 1 states have call successors, (1) [2024-11-09 06:22:50,766 INFO L276 IsEmpty]: Start isEmpty. Operand 119 states and 143 transitions. [2024-11-09 06:22:50,767 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 24 [2024-11-09 06:22:50,767 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:50,768 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:50,768 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2024-11-09 06:22:50,768 INFO L396 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:50,773 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:50,773 INFO L85 PathProgramCache]: Analyzing trace with hash -882467163, now seen corresponding path program 1 times [2024-11-09 06:22:50,773 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:50,773 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1462694973] [2024-11-09 06:22:50,774 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:50,774 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:50,807 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:50,928 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:50,928 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:50,928 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1462694973] [2024-11-09 06:22:50,929 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1462694973] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:50,929 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:50,929 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2024-11-09 06:22:50,929 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [2001462118] [2024-11-09 06:22:50,929 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:50,930 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2024-11-09 06:22:50,930 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:50,932 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2024-11-09 06:22:50,932 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-09 06:22:50,932 INFO L87 Difference]: Start difference. First operand 119 states and 143 transitions. Second operand has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2024-11-09 06:22:50,993 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:50,994 INFO L93 Difference]: Finished difference Result 236 states and 286 transitions. [2024-11-09 06:22:50,995 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2024-11-09 06:22:50,995 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) Word has length 23 [2024-11-09 06:22:50,995 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:50,997 INFO L225 Difference]: With dead ends: 236 [2024-11-09 06:22:50,997 INFO L226 Difference]: Without dead ends: 119 [2024-11-09 06:22:50,998 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 4 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-09 06:22:51,003 INFO L432 NwaCegarLoop]: 61 mSDtfsCounter, 67 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 17 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 67 SdHoareTripleChecker+Valid, 61 SdHoareTripleChecker+Invalid, 17 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 17 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.0s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:51,004 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [67 Valid, 61 Invalid, 17 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 17 Invalid, 0 Unknown, 0 Unchecked, 0.0s Time] [2024-11-09 06:22:51,005 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 119 states. [2024-11-09 06:22:51,033 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 119 to 119. [2024-11-09 06:22:51,037 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 119 states, 74 states have (on average 1.2162162162162162) internal successors, (90), 85 states have internal predecessors, (90), 24 states have call successors, (24), 17 states have call predecessors, (24), 20 states have return successors, (27), 21 states have call predecessors, (27), 24 states have call successors, (27) [2024-11-09 06:22:51,038 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 119 states to 119 states and 141 transitions. [2024-11-09 06:22:51,042 INFO L78 Accepts]: Start accepts. Automaton has 119 states and 141 transitions. Word has length 23 [2024-11-09 06:22:51,043 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:51,043 INFO L471 AbstractCegarLoop]: Abstraction has 119 states and 141 transitions. [2024-11-09 06:22:51,043 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 6.0) internal successors, (18), 3 states have internal predecessors, (18), 2 states have call successors, (3), 2 states have call predecessors, (3), 1 states have return successors, (2), 2 states have call predecessors, (2), 2 states have call successors, (2) [2024-11-09 06:22:51,043 INFO L276 IsEmpty]: Start isEmpty. Operand 119 states and 141 transitions. [2024-11-09 06:22:51,045 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 35 [2024-11-09 06:22:51,045 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:51,045 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:51,045 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2024-11-09 06:22:51,046 INFO L396 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:51,046 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:51,046 INFO L85 PathProgramCache]: Analyzing trace with hash -2114866574, now seen corresponding path program 1 times [2024-11-09 06:22:51,046 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:51,047 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1892191119] [2024-11-09 06:22:51,047 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:51,047 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:51,075 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:51,177 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:51,178 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:51,178 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1892191119] [2024-11-09 06:22:51,178 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1892191119] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:51,178 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:51,178 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2024-11-09 06:22:51,179 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1569893063] [2024-11-09 06:22:51,179 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:51,179 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2024-11-09 06:22:51,179 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:51,180 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2024-11-09 06:22:51,180 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2024-11-09 06:22:51,180 INFO L87 Difference]: Start difference. First operand 119 states and 141 transitions. Second operand has 5 states, 5 states have (on average 5.0) internal successors, (25), 5 states have internal predecessors, (25), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2024-11-09 06:22:51,498 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:51,498 INFO L93 Difference]: Finished difference Result 252 states and 307 transitions. [2024-11-09 06:22:51,499 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2024-11-09 06:22:51,499 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 5.0) internal successors, (25), 5 states have internal predecessors, (25), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) Word has length 34 [2024-11-09 06:22:51,500 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:51,502 INFO L225 Difference]: With dead ends: 252 [2024-11-09 06:22:51,502 INFO L226 Difference]: Without dead ends: 192 [2024-11-09 06:22:51,507 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 12 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2024-11-09 06:22:51,508 INFO L432 NwaCegarLoop]: 73 mSDtfsCounter, 134 mSDsluCounter, 97 mSDsCounter, 0 mSdLazyCounter, 159 mSolverCounterSat, 76 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 135 SdHoareTripleChecker+Valid, 170 SdHoareTripleChecker+Invalid, 235 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 76 IncrementalHoareTripleChecker+Valid, 159 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:51,508 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [135 Valid, 170 Invalid, 235 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [76 Valid, 159 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2024-11-09 06:22:51,510 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 192 states. [2024-11-09 06:22:51,564 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 192 to 186. [2024-11-09 06:22:51,565 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 186 states, 120 states have (on average 1.2083333333333333) internal successors, (145), 130 states have internal predecessors, (145), 31 states have call successors, (31), 26 states have call predecessors, (31), 34 states have return successors, (41), 35 states have call predecessors, (41), 31 states have call successors, (41) [2024-11-09 06:22:51,567 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 186 states to 186 states and 217 transitions. [2024-11-09 06:22:51,569 INFO L78 Accepts]: Start accepts. Automaton has 186 states and 217 transitions. Word has length 34 [2024-11-09 06:22:51,570 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:51,570 INFO L471 AbstractCegarLoop]: Abstraction has 186 states and 217 transitions. [2024-11-09 06:22:51,570 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 5.0) internal successors, (25), 5 states have internal predecessors, (25), 3 states have call successors, (5), 3 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 3 states have call successors, (4) [2024-11-09 06:22:51,571 INFO L276 IsEmpty]: Start isEmpty. Operand 186 states and 217 transitions. [2024-11-09 06:22:51,574 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 40 [2024-11-09 06:22:51,575 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:51,575 INFO L215 NwaCegarLoop]: trace histogram [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:51,575 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2024-11-09 06:22:51,575 INFO L396 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:51,576 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:51,576 INFO L85 PathProgramCache]: Analyzing trace with hash 2075432895, now seen corresponding path program 1 times [2024-11-09 06:22:51,576 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:51,577 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1700521464] [2024-11-09 06:22:51,577 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:51,577 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:51,607 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:52,020 INFO L134 CoverageAnalysis]: Checked inductivity of 0 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:52,020 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:52,020 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1700521464] [2024-11-09 06:22:52,020 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1700521464] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:22:52,021 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:22:52,021 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [9] imperfect sequences [] total 9 [2024-11-09 06:22:52,021 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1179392380] [2024-11-09 06:22:52,021 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:22:52,022 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 9 states [2024-11-09 06:22:52,022 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:22:52,022 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 9 interpolants. [2024-11-09 06:22:52,023 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=22, Invalid=50, Unknown=0, NotChecked=0, Total=72 [2024-11-09 06:22:52,023 INFO L87 Difference]: Start difference. First operand 186 states and 217 transitions. Second operand has 9 states, 8 states have (on average 3.5) internal successors, (28), 8 states have internal predecessors, (28), 6 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2024-11-09 06:22:52,776 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:22:52,777 INFO L93 Difference]: Finished difference Result 543 states and 670 transitions. [2024-11-09 06:22:52,777 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 14 states. [2024-11-09 06:22:52,778 INFO L78 Accepts]: Start accepts. Automaton has has 9 states, 8 states have (on average 3.5) internal successors, (28), 8 states have internal predecessors, (28), 6 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) Word has length 39 [2024-11-09 06:22:52,778 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:22:52,783 INFO L225 Difference]: With dead ends: 543 [2024-11-09 06:22:52,793 INFO L226 Difference]: Without dead ends: 416 [2024-11-09 06:22:52,794 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 19 GetRequests, 6 SyntacticMatches, 0 SemanticMatches, 13 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 30 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=61, Invalid=149, Unknown=0, NotChecked=0, Total=210 [2024-11-09 06:22:52,796 INFO L432 NwaCegarLoop]: 86 mSDtfsCounter, 314 mSDsluCounter, 194 mSDsCounter, 0 mSdLazyCounter, 451 mSolverCounterSat, 139 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 336 SdHoareTripleChecker+Valid, 280 SdHoareTripleChecker+Invalid, 590 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 139 IncrementalHoareTripleChecker+Valid, 451 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.6s IncrementalHoareTripleChecker+Time [2024-11-09 06:22:52,798 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [336 Valid, 280 Invalid, 590 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [139 Valid, 451 Invalid, 0 Unknown, 0 Unchecked, 0.6s Time] [2024-11-09 06:22:52,800 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 416 states. [2024-11-09 06:22:52,888 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 416 to 384. [2024-11-09 06:22:52,889 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 384 states, 251 states have (on average 1.2350597609561753) internal successors, (310), 271 states have internal predecessors, (310), 68 states have call successors, (68), 52 states have call predecessors, (68), 64 states have return successors, (89), 71 states have call predecessors, (89), 68 states have call successors, (89) [2024-11-09 06:22:52,892 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 384 states to 384 states and 467 transitions. [2024-11-09 06:22:52,893 INFO L78 Accepts]: Start accepts. Automaton has 384 states and 467 transitions. Word has length 39 [2024-11-09 06:22:52,894 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:22:52,894 INFO L471 AbstractCegarLoop]: Abstraction has 384 states and 467 transitions. [2024-11-09 06:22:52,894 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 9 states, 8 states have (on average 3.5) internal successors, (28), 8 states have internal predecessors, (28), 6 states have call successors, (6), 3 states have call predecessors, (6), 3 states have return successors, (5), 3 states have call predecessors, (5), 5 states have call successors, (5) [2024-11-09 06:22:52,895 INFO L276 IsEmpty]: Start isEmpty. Operand 384 states and 467 transitions. [2024-11-09 06:22:52,896 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 45 [2024-11-09 06:22:52,899 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:22:52,899 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:22:52,899 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2024-11-09 06:22:52,900 INFO L396 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:22:52,900 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:22:52,900 INFO L85 PathProgramCache]: Analyzing trace with hash 216051022, now seen corresponding path program 1 times [2024-11-09 06:22:52,901 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:22:52,901 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1336118217] [2024-11-09 06:22:52,901 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:52,901 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:22:52,927 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:53,174 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2024-11-09 06:22:53,175 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:22:53,176 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1336118217] [2024-11-09 06:22:53,176 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1336118217] provided 0 perfect and 1 imperfect interpolant sequences [2024-11-09 06:22:53,176 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [2101567749] [2024-11-09 06:22:53,176 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:22:53,176 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-09 06:22:53,177 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 [2024-11-09 06:22:53,179 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2024-11-09 06:22:53,185 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2024-11-09 06:22:53,273 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:22:53,279 INFO L255 TraceCheckSpWp]: Trace formula consists of 197 conjuncts, 13 conjuncts are in the unsatisfiable core [2024-11-09 06:22:53,288 INFO L278 TraceCheckSpWp]: Computing forward predicates... [2024-11-09 06:22:53,540 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 2 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-09 06:22:53,540 INFO L311 TraceCheckSpWp]: Computing backward predicates... [2024-11-09 06:22:54,042 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 1 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2024-11-09 06:22:54,042 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [2101567749] provided 0 perfect and 2 imperfect interpolant sequences [2024-11-09 06:22:54,042 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [2092373850] [2024-11-09 06:22:54,064 INFO L159 IcfgInterpreter]: Started Sifa with 43 locations of interest [2024-11-09 06:22:54,064 INFO L166 IcfgInterpreter]: Building call graph [2024-11-09 06:22:54,068 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2024-11-09 06:22:54,073 INFO L176 IcfgInterpreter]: Starting interpretation [2024-11-09 06:22:54,074 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2024-11-09 06:22:55,083 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 120 for LOIs [2024-11-09 06:22:55,127 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 142 for LOIs [2024-11-09 06:22:56,822 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 141 for LOIs [2024-11-09 06:22:57,414 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 141 for LOIs [2024-11-09 06:22:58,248 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 141 for LOIs [2024-11-09 06:22:58,684 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 148 for LOIs [2024-11-09 06:22:58,842 INFO L180 IcfgInterpreter]: Interpretation finished [2024-11-09 06:23:10,429 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSifa [2092373850] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:23:10,430 INFO L185 FreeRefinementEngine]: Found 1 perfect and 3 imperfect interpolant sequences. [2024-11-09 06:23:10,430 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [24] imperfect sequences [10, 9, 10] total 45 [2024-11-09 06:23:10,430 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1142664000] [2024-11-09 06:23:10,431 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:23:10,431 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 25 states [2024-11-09 06:23:10,431 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:10,432 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 25 interpolants. [2024-11-09 06:23:10,433 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=217, Invalid=1763, Unknown=0, NotChecked=0, Total=1980 [2024-11-09 06:23:10,433 INFO L87 Difference]: Start difference. First operand 384 states and 467 transitions. Second operand has 25 states, 21 states have (on average 1.4285714285714286) internal successors, (30), 19 states have internal predecessors, (30), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2024-11-09 06:23:17,732 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:17,733 INFO L93 Difference]: Finished difference Result 781 states and 954 transitions. [2024-11-09 06:23:17,735 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 24 states. [2024-11-09 06:23:17,735 INFO L78 Accepts]: Start accepts. Automaton has has 25 states, 21 states have (on average 1.4285714285714286) internal successors, (30), 19 states have internal predecessors, (30), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) Word has length 44 [2024-11-09 06:23:17,736 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:17,741 INFO L225 Difference]: With dead ends: 781 [2024-11-09 06:23:17,741 INFO L226 Difference]: Without dead ends: 475 [2024-11-09 06:23:17,743 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 152 GetRequests, 92 SyntacticMatches, 5 SemanticMatches, 55 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 865 ImplicationChecksByTransitivity, 16.2s TimeCoverageRelationStatistics Valid=329, Invalid=2863, Unknown=0, NotChecked=0, Total=3192 [2024-11-09 06:23:17,744 INFO L432 NwaCegarLoop]: 47 mSDtfsCounter, 87 mSDsluCounter, 378 mSDsCounter, 0 mSdLazyCounter, 1198 mSolverCounterSat, 56 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 2.7s Time, 0 mProtectedPredicate, 0 mProtectedAction, 87 SdHoareTripleChecker+Valid, 425 SdHoareTripleChecker+Invalid, 1254 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 56 IncrementalHoareTripleChecker+Valid, 1198 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.9s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:17,745 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [87 Valid, 425 Invalid, 1254 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [56 Valid, 1198 Invalid, 0 Unknown, 0 Unchecked, 2.9s Time] [2024-11-09 06:23:17,746 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 475 states. [2024-11-09 06:23:17,841 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 475 to 458. [2024-11-09 06:23:17,842 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 458 states, 301 states have (on average 1.212624584717608) internal successors, (365), 322 states have internal predecessors, (365), 80 states have call successors, (80), 64 states have call predecessors, (80), 76 states have return successors, (101), 82 states have call predecessors, (101), 80 states have call successors, (101) [2024-11-09 06:23:17,845 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 458 states to 458 states and 546 transitions. [2024-11-09 06:23:17,846 INFO L78 Accepts]: Start accepts. Automaton has 458 states and 546 transitions. Word has length 44 [2024-11-09 06:23:17,846 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:17,847 INFO L471 AbstractCegarLoop]: Abstraction has 458 states and 546 transitions. [2024-11-09 06:23:17,847 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 25 states, 21 states have (on average 1.4285714285714286) internal successors, (30), 19 states have internal predecessors, (30), 7 states have call successors, (7), 5 states have call predecessors, (7), 4 states have return successors, (6), 6 states have call predecessors, (6), 6 states have call successors, (6) [2024-11-09 06:23:17,847 INFO L276 IsEmpty]: Start isEmpty. Operand 458 states and 546 transitions. [2024-11-09 06:23:17,848 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 48 [2024-11-09 06:23:17,849 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:23:17,849 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:17,872 INFO L540 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Forceful destruction successful, exit code 0 [2024-11-09 06:23:18,054 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-09 06:23:18,054 INFO L396 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:23:18,055 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:23:18,055 INFO L85 PathProgramCache]: Analyzing trace with hash 193768461, now seen corresponding path program 1 times [2024-11-09 06:23:18,055 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:23:18,055 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1549467399] [2024-11-09 06:23:18,055 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:18,055 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:23:18,073 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:18,327 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2024-11-09 06:23:18,328 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:23:18,328 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1549467399] [2024-11-09 06:23:18,328 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1549467399] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:23:18,328 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:23:18,329 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [11] imperfect sequences [] total 11 [2024-11-09 06:23:18,329 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [566639141] [2024-11-09 06:23:18,329 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:23:18,329 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 11 states [2024-11-09 06:23:18,330 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:18,330 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 11 interpolants. [2024-11-09 06:23:18,331 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=22, Invalid=88, Unknown=0, NotChecked=0, Total=110 [2024-11-09 06:23:18,331 INFO L87 Difference]: Start difference. First operand 458 states and 546 transitions. Second operand has 11 states, 9 states have (on average 3.4444444444444446) internal successors, (31), 8 states have internal predecessors, (31), 2 states have call successors, (8), 1 states have call predecessors, (8), 4 states have return successors, (7), 5 states have call predecessors, (7), 2 states have call successors, (7) [2024-11-09 06:23:19,215 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:19,215 INFO L93 Difference]: Finished difference Result 1105 states and 1384 transitions. [2024-11-09 06:23:19,215 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2024-11-09 06:23:19,216 INFO L78 Accepts]: Start accepts. Automaton has has 11 states, 9 states have (on average 3.4444444444444446) internal successors, (31), 8 states have internal predecessors, (31), 2 states have call successors, (8), 1 states have call predecessors, (8), 4 states have return successors, (7), 5 states have call predecessors, (7), 2 states have call successors, (7) Word has length 47 [2024-11-09 06:23:19,216 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:19,224 INFO L225 Difference]: With dead ends: 1105 [2024-11-09 06:23:19,225 INFO L226 Difference]: Without dead ends: 822 [2024-11-09 06:23:19,227 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 28 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 23 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 71 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=140, Invalid=460, Unknown=0, NotChecked=0, Total=600 [2024-11-09 06:23:19,230 INFO L432 NwaCegarLoop]: 150 mSDtfsCounter, 205 mSDsluCounter, 767 mSDsCounter, 0 mSdLazyCounter, 634 mSolverCounterSat, 63 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 211 SdHoareTripleChecker+Valid, 917 SdHoareTripleChecker+Invalid, 697 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 63 IncrementalHoareTripleChecker+Valid, 634 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:19,230 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [211 Valid, 917 Invalid, 697 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [63 Valid, 634 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2024-11-09 06:23:19,234 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 822 states. [2024-11-09 06:23:19,382 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 822 to 800. [2024-11-09 06:23:19,384 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 800 states, 527 states have (on average 1.1973434535104364) internal successors, (631), 564 states have internal predecessors, (631), 140 states have call successors, (140), 108 states have call predecessors, (140), 132 states have return successors, (202), 143 states have call predecessors, (202), 140 states have call successors, (202) [2024-11-09 06:23:19,391 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 800 states to 800 states and 973 transitions. [2024-11-09 06:23:19,393 INFO L78 Accepts]: Start accepts. Automaton has 800 states and 973 transitions. Word has length 47 [2024-11-09 06:23:19,393 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:19,393 INFO L471 AbstractCegarLoop]: Abstraction has 800 states and 973 transitions. [2024-11-09 06:23:19,393 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 11 states, 9 states have (on average 3.4444444444444446) internal successors, (31), 8 states have internal predecessors, (31), 2 states have call successors, (8), 1 states have call predecessors, (8), 4 states have return successors, (7), 5 states have call predecessors, (7), 2 states have call successors, (7) [2024-11-09 06:23:19,394 INFO L276 IsEmpty]: Start isEmpty. Operand 800 states and 973 transitions. [2024-11-09 06:23:19,398 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 77 [2024-11-09 06:23:19,398 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:23:19,398 INFO L215 NwaCegarLoop]: trace histogram [4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:19,400 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7 [2024-11-09 06:23:19,400 INFO L396 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:23:19,400 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:23:19,400 INFO L85 PathProgramCache]: Analyzing trace with hash -438833478, now seen corresponding path program 1 times [2024-11-09 06:23:19,401 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:23:19,401 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [201911267] [2024-11-09 06:23:19,401 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:19,401 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:23:19,420 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:19,706 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2024-11-09 06:23:19,706 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:23:19,707 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [201911267] [2024-11-09 06:23:19,707 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [201911267] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:23:19,707 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:23:19,707 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2024-11-09 06:23:19,708 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [573944853] [2024-11-09 06:23:19,708 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:23:19,708 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2024-11-09 06:23:19,709 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:19,710 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2024-11-09 06:23:19,710 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2024-11-09 06:23:19,710 INFO L87 Difference]: Start difference. First operand 800 states and 973 transitions. Second operand has 8 states, 8 states have (on average 6.0) internal successors, (48), 7 states have internal predecessors, (48), 6 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (10), 5 states have call predecessors, (10), 6 states have call successors, (10) [2024-11-09 06:23:20,203 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:20,203 INFO L93 Difference]: Finished difference Result 1393 states and 1722 transitions. [2024-11-09 06:23:20,203 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 11 states. [2024-11-09 06:23:20,204 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 8 states have (on average 6.0) internal successors, (48), 7 states have internal predecessors, (48), 6 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (10), 5 states have call predecessors, (10), 6 states have call successors, (10) Word has length 76 [2024-11-09 06:23:20,204 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:20,212 INFO L225 Difference]: With dead ends: 1393 [2024-11-09 06:23:20,212 INFO L226 Difference]: Without dead ends: 865 [2024-11-09 06:23:20,214 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 15 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 10 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 12 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=45, Invalid=87, Unknown=0, NotChecked=0, Total=132 [2024-11-09 06:23:20,215 INFO L432 NwaCegarLoop]: 44 mSDtfsCounter, 134 mSDsluCounter, 64 mSDsCounter, 0 mSdLazyCounter, 215 mSolverCounterSat, 77 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 144 SdHoareTripleChecker+Valid, 108 SdHoareTripleChecker+Invalid, 292 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 77 IncrementalHoareTripleChecker+Valid, 215 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:20,215 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [144 Valid, 108 Invalid, 292 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [77 Valid, 215 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2024-11-09 06:23:20,216 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 865 states. [2024-11-09 06:23:20,354 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 865 to 790. [2024-11-09 06:23:20,356 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 790 states, 522 states have (on average 1.1992337164750957) internal successors, (626), 557 states have internal predecessors, (626), 137 states have call successors, (137), 109 states have call predecessors, (137), 130 states have return successors, (194), 139 states have call predecessors, (194), 137 states have call successors, (194) [2024-11-09 06:23:20,360 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 790 states to 790 states and 957 transitions. [2024-11-09 06:23:20,362 INFO L78 Accepts]: Start accepts. Automaton has 790 states and 957 transitions. Word has length 76 [2024-11-09 06:23:20,362 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:20,362 INFO L471 AbstractCegarLoop]: Abstraction has 790 states and 957 transitions. [2024-11-09 06:23:20,362 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 8 states have (on average 6.0) internal successors, (48), 7 states have internal predecessors, (48), 6 states have call successors, (11), 3 states have call predecessors, (11), 3 states have return successors, (10), 5 states have call predecessors, (10), 6 states have call successors, (10) [2024-11-09 06:23:20,363 INFO L276 IsEmpty]: Start isEmpty. Operand 790 states and 957 transitions. [2024-11-09 06:23:20,365 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 77 [2024-11-09 06:23:20,366 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:23:20,366 INFO L215 NwaCegarLoop]: trace histogram [4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:20,366 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2024-11-09 06:23:20,366 INFO L396 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:23:20,367 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:23:20,367 INFO L85 PathProgramCache]: Analyzing trace with hash -1667739196, now seen corresponding path program 1 times [2024-11-09 06:23:20,367 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:23:20,367 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [519743523] [2024-11-09 06:23:20,368 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:20,368 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:23:20,396 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:20,789 INFO L134 CoverageAnalysis]: Checked inductivity of 32 backedges. 16 proven. 0 refuted. 0 times theorem prover too weak. 16 trivial. 0 not checked. [2024-11-09 06:23:20,789 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:23:20,789 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [519743523] [2024-11-09 06:23:20,789 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [519743523] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:23:20,789 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:23:20,790 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [10] imperfect sequences [] total 10 [2024-11-09 06:23:20,790 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1468640303] [2024-11-09 06:23:20,790 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:23:20,790 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 10 states [2024-11-09 06:23:20,791 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:20,791 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 10 interpolants. [2024-11-09 06:23:20,791 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=21, Invalid=69, Unknown=0, NotChecked=0, Total=90 [2024-11-09 06:23:20,792 INFO L87 Difference]: Start difference. First operand 790 states and 957 transitions. Second operand has 10 states, 9 states have (on average 5.333333333333333) internal successors, (48), 8 states have internal predecessors, (48), 5 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (10), 4 states have call predecessors, (10), 5 states have call successors, (10) [2024-11-09 06:23:21,767 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:21,768 INFO L93 Difference]: Finished difference Result 1393 states and 1719 transitions. [2024-11-09 06:23:21,768 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 21 states. [2024-11-09 06:23:21,769 INFO L78 Accepts]: Start accepts. Automaton has has 10 states, 9 states have (on average 5.333333333333333) internal successors, (48), 8 states have internal predecessors, (48), 5 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (10), 4 states have call predecessors, (10), 5 states have call successors, (10) Word has length 76 [2024-11-09 06:23:21,771 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:21,778 INFO L225 Difference]: With dead ends: 1393 [2024-11-09 06:23:21,778 INFO L226 Difference]: Without dead ends: 840 [2024-11-09 06:23:21,780 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 30 GetRequests, 8 SyntacticMatches, 0 SemanticMatches, 22 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 119 ImplicationChecksByTransitivity, 0.3s TimeCoverageRelationStatistics Valid=139, Invalid=413, Unknown=0, NotChecked=0, Total=552 [2024-11-09 06:23:21,781 INFO L432 NwaCegarLoop]: 42 mSDtfsCounter, 290 mSDsluCounter, 122 mSDsCounter, 0 mSdLazyCounter, 414 mSolverCounterSat, 191 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 299 SdHoareTripleChecker+Valid, 164 SdHoareTripleChecker+Invalid, 605 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 191 IncrementalHoareTripleChecker+Valid, 414 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:21,782 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [299 Valid, 164 Invalid, 605 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [191 Valid, 414 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2024-11-09 06:23:21,784 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 840 states. [2024-11-09 06:23:21,931 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 840 to 794. [2024-11-09 06:23:21,933 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 794 states, 524 states have (on average 1.1946564885496183) internal successors, (626), 559 states have internal predecessors, (626), 137 states have call successors, (137), 111 states have call predecessors, (137), 132 states have return successors, (194), 139 states have call predecessors, (194), 137 states have call successors, (194) [2024-11-09 06:23:21,937 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 794 states to 794 states and 957 transitions. [2024-11-09 06:23:21,939 INFO L78 Accepts]: Start accepts. Automaton has 794 states and 957 transitions. Word has length 76 [2024-11-09 06:23:21,939 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:21,939 INFO L471 AbstractCegarLoop]: Abstraction has 794 states and 957 transitions. [2024-11-09 06:23:21,940 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 10 states, 9 states have (on average 5.333333333333333) internal successors, (48), 8 states have internal predecessors, (48), 5 states have call successors, (11), 4 states have call predecessors, (11), 3 states have return successors, (10), 4 states have call predecessors, (10), 5 states have call successors, (10) [2024-11-09 06:23:21,940 INFO L276 IsEmpty]: Start isEmpty. Operand 794 states and 957 transitions. [2024-11-09 06:23:21,941 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 79 [2024-11-09 06:23:21,941 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:23:21,942 INFO L215 NwaCegarLoop]: trace histogram [4, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:21,942 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable9 [2024-11-09 06:23:21,942 INFO L396 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:23:21,943 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:23:21,943 INFO L85 PathProgramCache]: Analyzing trace with hash 1719612622, now seen corresponding path program 1 times [2024-11-09 06:23:21,944 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:23:21,944 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2060463331] [2024-11-09 06:23:21,944 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:21,944 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:23:21,966 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:22,106 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 16 proven. 3 refuted. 0 times theorem prover too weak. 12 trivial. 0 not checked. [2024-11-09 06:23:22,107 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:23:22,107 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2060463331] [2024-11-09 06:23:22,107 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2060463331] provided 0 perfect and 1 imperfect interpolant sequences [2024-11-09 06:23:22,111 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [88084768] [2024-11-09 06:23:22,111 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:22,111 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-09 06:23:22,111 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 [2024-11-09 06:23:22,115 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2024-11-09 06:23:22,117 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2024-11-09 06:23:22,232 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:22,234 INFO L255 TraceCheckSpWp]: Trace formula consists of 274 conjuncts, 22 conjuncts are in the unsatisfiable core [2024-11-09 06:23:22,241 INFO L278 TraceCheckSpWp]: Computing forward predicates... [2024-11-09 06:23:22,519 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 12 proven. 11 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2024-11-09 06:23:22,519 INFO L311 TraceCheckSpWp]: Computing backward predicates... [2024-11-09 06:23:22,983 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 6 proven. 2 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2024-11-09 06:23:22,984 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [88084768] provided 0 perfect and 2 imperfect interpolant sequences [2024-11-09 06:23:22,984 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [315503887] [2024-11-09 06:23:22,987 INFO L159 IcfgInterpreter]: Started Sifa with 54 locations of interest [2024-11-09 06:23:22,988 INFO L166 IcfgInterpreter]: Building call graph [2024-11-09 06:23:22,988 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2024-11-09 06:23:22,989 INFO L176 IcfgInterpreter]: Starting interpretation [2024-11-09 06:23:22,989 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2024-11-09 06:23:26,119 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 156 for LOIs [2024-11-09 06:23:26,183 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 41 for LOIs [2024-11-09 06:23:26,711 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__methaneQuery with input of size 39 for LOIs [2024-11-09 06:23:26,780 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 39 for LOIs [2024-11-09 06:23:26,870 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneAlarm with input of size 49 for LOIs [2024-11-09 06:23:27,007 INFO L197 IcfgInterpreter]: Interpreting procedure isMethaneLevelCritical with input of size 9 for LOIs [2024-11-09 06:23:27,009 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 21 for LOIs [2024-11-09 06:23:27,013 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 64 for LOIs [2024-11-09 06:23:27,058 INFO L180 IcfgInterpreter]: Interpretation finished [2024-11-09 06:23:33,354 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '15988#(and (= ~pumpRunning~0 0) (<= 0 |old(~pumpRunning~0)|) (= 2 ~waterLevel~0) (= ~methaneLevelCritical~0 0) (<= |old(~pumpRunning~0)| 1))' at error location [2024-11-09 06:23:33,354 WARN L311 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2024-11-09 06:23:33,354 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2024-11-09 06:23:33,354 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [8, 9, 8] total 20 [2024-11-09 06:23:33,354 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1615284292] [2024-11-09 06:23:33,354 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2024-11-09 06:23:33,355 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2024-11-09 06:23:33,355 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:33,356 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2024-11-09 06:23:33,357 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=296, Invalid=2896, Unknown=0, NotChecked=0, Total=3192 [2024-11-09 06:23:33,357 INFO L87 Difference]: Start difference. First operand 794 states and 957 transitions. Second operand has 20 states, 18 states have (on average 6.277777777777778) internal successors, (113), 18 states have internal predecessors, (113), 8 states have call successors, (31), 7 states have call predecessors, (31), 8 states have return successors, (28), 10 states have call predecessors, (28), 8 states have call successors, (28) [2024-11-09 06:23:39,525 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:39,525 INFO L93 Difference]: Finished difference Result 3339 states and 4278 transitions. [2024-11-09 06:23:39,525 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 105 states. [2024-11-09 06:23:39,526 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 18 states have (on average 6.277777777777778) internal successors, (113), 18 states have internal predecessors, (113), 8 states have call successors, (31), 7 states have call predecessors, (31), 8 states have return successors, (28), 10 states have call predecessors, (28), 8 states have call successors, (28) Word has length 78 [2024-11-09 06:23:39,527 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:39,543 INFO L225 Difference]: With dead ends: 3339 [2024-11-09 06:23:39,543 INFO L226 Difference]: Without dead ends: 2516 [2024-11-09 06:23:39,552 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 370 GetRequests, 210 SyntacticMatches, 6 SemanticMatches, 154 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 8678 ImplicationChecksByTransitivity, 9.9s TimeCoverageRelationStatistics Valid=2099, Invalid=22081, Unknown=0, NotChecked=0, Total=24180 [2024-11-09 06:23:39,553 INFO L432 NwaCegarLoop]: 107 mSDtfsCounter, 939 mSDsluCounter, 930 mSDsCounter, 0 mSdLazyCounter, 2952 mSolverCounterSat, 683 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.9s Time, 0 mProtectedPredicate, 0 mProtectedAction, 941 SdHoareTripleChecker+Valid, 1037 SdHoareTripleChecker+Invalid, 3635 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 683 IncrementalHoareTripleChecker+Valid, 2952 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 2.3s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:39,554 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [941 Valid, 1037 Invalid, 3635 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [683 Valid, 2952 Invalid, 0 Unknown, 0 Unchecked, 2.3s Time] [2024-11-09 06:23:39,557 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 2516 states. [2024-11-09 06:23:39,906 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 2516 to 2295. [2024-11-09 06:23:39,911 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 2295 states, 1503 states have (on average 1.147039254823686) internal successors, (1724), 1576 states have internal predecessors, (1724), 397 states have call successors, (397), 343 states have call predecessors, (397), 394 states have return successors, (623), 404 states have call predecessors, (623), 397 states have call successors, (623) [2024-11-09 06:23:39,921 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 2295 states to 2295 states and 2744 transitions. [2024-11-09 06:23:39,925 INFO L78 Accepts]: Start accepts. Automaton has 2295 states and 2744 transitions. Word has length 78 [2024-11-09 06:23:39,926 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:39,926 INFO L471 AbstractCegarLoop]: Abstraction has 2295 states and 2744 transitions. [2024-11-09 06:23:39,926 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 18 states have (on average 6.277777777777778) internal successors, (113), 18 states have internal predecessors, (113), 8 states have call successors, (31), 7 states have call predecessors, (31), 8 states have return successors, (28), 10 states have call predecessors, (28), 8 states have call successors, (28) [2024-11-09 06:23:39,926 INFO L276 IsEmpty]: Start isEmpty. Operand 2295 states and 2744 transitions. [2024-11-09 06:23:39,928 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 84 [2024-11-09 06:23:39,929 INFO L207 NwaCegarLoop]: Found error trace [2024-11-09 06:23:39,929 INFO L215 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:39,955 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2024-11-09 06:23:40,129 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable10,3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-09 06:23:40,130 INFO L396 AbstractCegarLoop]: === Iteration 12 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-09 06:23:40,130 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-09 06:23:40,130 INFO L85 PathProgramCache]: Analyzing trace with hash 820840853, now seen corresponding path program 1 times [2024-11-09 06:23:40,130 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-09 06:23:40,131 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1255091546] [2024-11-09 06:23:40,131 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-09 06:23:40,131 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-09 06:23:40,148 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-09 06:23:40,309 INFO L134 CoverageAnalysis]: Checked inductivity of 35 backedges. 10 proven. 0 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2024-11-09 06:23:40,309 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-09 06:23:40,309 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1255091546] [2024-11-09 06:23:40,309 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1255091546] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-09 06:23:40,309 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-09 06:23:40,310 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2024-11-09 06:23:40,310 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1684579997] [2024-11-09 06:23:40,310 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-09 06:23:40,310 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2024-11-09 06:23:40,311 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-09 06:23:40,312 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2024-11-09 06:23:40,312 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=8, Invalid=12, Unknown=0, NotChecked=0, Total=20 [2024-11-09 06:23:40,312 INFO L87 Difference]: Start difference. First operand 2295 states and 2744 transitions. Second operand has 5 states, 5 states have (on average 8.4) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (10), 1 states have call predecessors, (10), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2024-11-09 06:23:40,716 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-09 06:23:40,716 INFO L93 Difference]: Finished difference Result 4218 states and 5080 transitions. [2024-11-09 06:23:40,717 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 5 states. [2024-11-09 06:23:40,717 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 8.4) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (10), 1 states have call predecessors, (10), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) Word has length 83 [2024-11-09 06:23:40,717 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-09 06:23:40,721 INFO L225 Difference]: With dead ends: 4218 [2024-11-09 06:23:40,721 INFO L226 Difference]: Without dead ends: 0 [2024-11-09 06:23:40,733 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 6 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 4 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=13, Invalid=17, Unknown=0, NotChecked=0, Total=30 [2024-11-09 06:23:40,734 INFO L432 NwaCegarLoop]: 83 mSDtfsCounter, 61 mSDsluCounter, 193 mSDsCounter, 0 mSdLazyCounter, 77 mSolverCounterSat, 2 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 61 SdHoareTripleChecker+Valid, 276 SdHoareTripleChecker+Invalid, 79 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 2 IncrementalHoareTripleChecker+Valid, 77 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2024-11-09 06:23:40,735 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [61 Valid, 276 Invalid, 79 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [2 Valid, 77 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2024-11-09 06:23:40,735 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2024-11-09 06:23:40,735 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2024-11-09 06:23:40,735 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2024-11-09 06:23:40,736 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2024-11-09 06:23:40,738 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 83 [2024-11-09 06:23:40,739 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-09 06:23:40,739 INFO L471 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2024-11-09 06:23:40,739 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 8.4) internal successors, (42), 5 states have internal predecessors, (42), 2 states have call successors, (10), 1 states have call predecessors, (10), 2 states have return successors, (12), 2 states have call predecessors, (12), 2 states have call successors, (12) [2024-11-09 06:23:40,739 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2024-11-09 06:23:40,740 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2024-11-09 06:23:40,742 INFO L782 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2024-11-09 06:23:40,743 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable11 [2024-11-09 06:23:40,745 INFO L407 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-09 06:23:40,748 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2024-11-09 06:24:13,493 INFO L170 ceAbstractionStarter]: Computing trace abstraction results [2024-11-09 06:24:13,523 WARN L162 FloydHoareUtils]: Requires clause for deactivatePump contained old-variable. Original clause: (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (not (= |old(~pumpRunning~0)| 0)) (<= ~waterLevel~0 1) (= 1 ~systemActive~0)) Eliminated clause: (and (not (= ~pumpRunning~0 0)) (<= ~waterLevel~0 1) (= 1 ~systemActive~0)) [2024-11-09 06:24:13,533 WARN L162 FloydHoareUtils]: Requires clause for changeMethaneLevel contained old-variable. Original clause: (and (or (= |old(~methaneLevelCritical~0)| 0) (not (= ~methaneLevelCritical~0 0))) (= 1 ~systemActive~0) (<= ~waterLevel~0 2)) Eliminated clause: (and (= 1 ~systemActive~0) (<= ~waterLevel~0 2)) [2024-11-09 06:24:13,536 WARN L162 FloydHoareUtils]: Requires clause for timeShift contained old-variable. Original clause: (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (= 1 ~systemActive~0) (= |old(~waterLevel~0)| ~waterLevel~0) (<= |old(~waterLevel~0)| 2)) Eliminated clause: (and (= 1 ~systemActive~0) (<= ~waterLevel~0 2)) [2024-11-09 06:24:13,565 WARN L162 FloydHoareUtils]: Requires clause for processEnvironment__wrappee__highWaterSensor contained old-variable. Original clause: (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (let ((.cse0 (= 1 ~systemActive~0))) (or (and (<= ~waterLevel~0 1) .cse0) (and .cse0 (= |old(~pumpRunning~0)| 0) (<= ~waterLevel~0 2))))) Eliminated clause: (let ((.cse0 (= 1 ~systemActive~0))) (or (and (<= ~waterLevel~0 1) .cse0) (and (= ~pumpRunning~0 0) .cse0 (<= ~waterLevel~0 2)))) [2024-11-09 06:24:13,572 WARN L162 FloydHoareUtils]: Requires clause for waterRise contained old-variable. Original clause: (and (let ((.cse1 (<= |old(~waterLevel~0)| 2)) (.cse0 (= 1 ~systemActive~0))) (or (and .cse0 (<= |old(~waterLevel~0)| 1)) (and (= ~pumpRunning~0 0) .cse0 .cse1) (and .cse0 .cse1 (= ~pumpRunning~0 1)) (and .cse0 (not (= ~methaneLevelCritical~0 0)) (= |old(~waterLevel~0)| 2)))) (= |old(~waterLevel~0)| ~waterLevel~0)) Eliminated clause: (let ((.cse1 (<= ~waterLevel~0 2)) (.cse0 (= 1 ~systemActive~0))) (or (and (<= ~waterLevel~0 1) .cse0) (and .cse0 .cse1 (= ~pumpRunning~0 1)) (and (= ~pumpRunning~0 0) .cse0 .cse1) (and (= 2 ~waterLevel~0) .cse0 (not (= ~methaneLevelCritical~0 0))))) [2024-11-09 06:24:13,578 WARN L162 FloydHoareUtils]: Requires clause for processEnvironment__wrappee__methaneQuery contained old-variable. Original clause: (and (= ~pumpRunning~0 |old(~pumpRunning~0)|) (let ((.cse0 (= 1 ~systemActive~0))) (or (and (<= ~waterLevel~0 1) .cse0) (and .cse0 (= |old(~pumpRunning~0)| 0) (<= ~waterLevel~0 2))))) Eliminated clause: (let ((.cse0 (= 1 ~systemActive~0))) (or (and (<= ~waterLevel~0 1) .cse0) (and (= ~pumpRunning~0 0) .cse0 (<= ~waterLevel~0 2)))) [2024-11-09 06:24:13,588 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 09.11 06:24:13 BoogieIcfgContainer [2024-11-09 06:24:13,588 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2024-11-09 06:24:13,589 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2024-11-09 06:24:13,589 INFO L270 PluginConnector]: Initializing Witness Printer... [2024-11-09 06:24:13,589 INFO L274 PluginConnector]: Witness Printer initialized [2024-11-09 06:24:13,590 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 09.11 06:22:49" (3/4) ... [2024-11-09 06:24:13,592 INFO L142 WitnessPrinter]: Generating witness for correct program [2024-11-09 06:24:13,596 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2024-11-09 06:24:13,596 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2024-11-09 06:24:13,597 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2024-11-09 06:24:13,597 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2024-11-09 06:24:13,597 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2024-11-09 06:24:13,597 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneLevelCritical [2024-11-09 06:24:13,598 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2024-11-09 06:24:13,598 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2024-11-09 06:24:13,598 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__methaneQuery [2024-11-09 06:24:13,598 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isMethaneAlarm [2024-11-09 06:24:13,606 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 48 nodes and edges [2024-11-09 06:24:13,606 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2024-11-09 06:24:13,607 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2024-11-09 06:24:13,607 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2024-11-09 06:24:13,608 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2024-11-09 06:24:13,638 WARN L216 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == \old(pumpRunning)) && (1 == systemActive)) && (\old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 2)) [2024-11-09 06:24:13,693 WARN L141 nessWitnessGenerator]: Not writing invariant because ACSL is forbidden: ((((pumpRunning == \old(pumpRunning)) && (1 == systemActive)) && (\old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 2)) [2024-11-09 06:24:13,751 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/witness.graphml [2024-11-09 06:24:13,751 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/witness.yml [2024-11-09 06:24:13,751 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2024-11-09 06:24:13,752 INFO L158 Benchmark]: Toolchain (without parser) took 86108.65ms. Allocated memory was 130.0MB in the beginning and 853.5MB in the end (delta: 723.5MB). Free memory was 92.4MB in the beginning and 705.5MB in the end (delta: -613.2MB). Peak memory consumption was 112.4MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,753 INFO L158 Benchmark]: CDTParser took 0.36ms. Allocated memory is still 130.0MB. Free memory is still 100.1MB. There was no memory consumed. Max. memory is 16.1GB. [2024-11-09 06:24:13,753 INFO L158 Benchmark]: CACSL2BoogieTranslator took 632.53ms. Allocated memory is still 130.0MB. Free memory was 91.9MB in the beginning and 69.6MB in the end (delta: 22.3MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,753 INFO L158 Benchmark]: Boogie Procedure Inliner took 80.66ms. Allocated memory is still 130.0MB. Free memory was 69.6MB in the beginning and 67.2MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,754 INFO L158 Benchmark]: Boogie Preprocessor took 48.77ms. Allocated memory is still 130.0MB. Free memory was 67.2MB in the beginning and 65.4MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,754 INFO L158 Benchmark]: RCFGBuilder took 802.85ms. Allocated memory was 130.0MB in the beginning and 172.0MB in the end (delta: 41.9MB). Free memory was 65.4MB in the beginning and 128.4MB in the end (delta: -63.0MB). Peak memory consumption was 28.0MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,755 INFO L158 Benchmark]: TraceAbstraction took 84373.54ms. Allocated memory was 172.0MB in the beginning and 853.5MB in the end (delta: 681.6MB). Free memory was 128.4MB in the beginning and 713.9MB in the end (delta: -585.5MB). Peak memory consumption was 514.3MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,755 INFO L158 Benchmark]: Witness Printer took 163.03ms. Allocated memory is still 853.5MB. Free memory was 713.9MB in the beginning and 705.5MB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2024-11-09 06:24:13,757 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.36ms. Allocated memory is still 130.0MB. Free memory is still 100.1MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 632.53ms. Allocated memory is still 130.0MB. Free memory was 91.9MB in the beginning and 69.6MB in the end (delta: 22.3MB). Peak memory consumption was 21.0MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 80.66ms. Allocated memory is still 130.0MB. Free memory was 69.6MB in the beginning and 67.2MB in the end (delta: 2.4MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * Boogie Preprocessor took 48.77ms. Allocated memory is still 130.0MB. Free memory was 67.2MB in the beginning and 65.4MB in the end (delta: 1.7MB). Peak memory consumption was 2.1MB. Max. memory is 16.1GB. * RCFGBuilder took 802.85ms. Allocated memory was 130.0MB in the beginning and 172.0MB in the end (delta: 41.9MB). Free memory was 65.4MB in the beginning and 128.4MB in the end (delta: -63.0MB). Peak memory consumption was 28.0MB. Max. memory is 16.1GB. * TraceAbstraction took 84373.54ms. Allocated memory was 172.0MB in the beginning and 853.5MB in the end (delta: 681.6MB). Free memory was 128.4MB in the beginning and 713.9MB in the end (delta: -585.5MB). Peak memory consumption was 514.3MB. Max. memory is 16.1GB. * Witness Printer took 163.03ms. Allocated memory is still 853.5MB. Free memory was 713.9MB in the beginning and 705.5MB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [49] - GenericResultAtLocation [Line: 58]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification3_spec.i","") [58] - GenericResultAtLocation [Line: 95]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [95] - GenericResultAtLocation [Line: 461]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [461] - GenericResultAtLocation [Line: 570]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [570] - GenericResultAtLocation [Line: 608]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [608] - GenericResultAtLocation [Line: 861]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [861] - GenericResultAtLocation [Line: 929]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [929] * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 54]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 11 procedures, 75 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 51.5s, OverallIterations: 12, TraceHistogramMax: 4, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 18.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.0s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2358 SdHoareTripleChecker+Valid, 7.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2305 mSDsluCounter, 3899 SdHoareTripleChecker+Invalid, 6.7s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2999 mSDsCounter, 1292 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 6260 IncrementalHoareTripleChecker+Invalid, 7552 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1292 mSolverCounterUnsat, 900 mSDtfsCounter, 6260 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 649 GetRequests, 344 SyntacticMatches, 11 SemanticMatches, 294 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 9781 ImplicationChecksByTransitivity, 27.0s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=2295occurred in iteration=11, InterpolantAutomatonStates: 223, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 1.2s AutomataMinimizationTime, 12 MinimizatonAttempts, 434 StatesRemovedByMinimization, 8 NontrivialMinimizations, HoareAnnotationStatistics: No data available, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.3s SatisfiabilityAnalysisTime, 4.2s InterpolantComputationTime, 677 NumberOfCodeBlocks, 677 NumberOfCodeBlocksAsserted, 14 NumberOfCheckSat, 783 ConstructedInterpolants, 0 QuantifiedInterpolants, 2245 SizeOfPredicates, 9 NumberOfNonLiveVariables, 471 ConjunctsInSsa, 35 ConjunctsInUnsatCore, 16 InterpolantComputations, 10 PerfectInterpolantSequences, 180/200 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: OVERALL_TIME: 4.8s, ICFG_INTERPRETER_ENTERED_PROCEDURES: 7, DAG_INTERPRETER_EARLY_EXIT_QUERIES_NONTRIVIAL: 46, DAG_INTERPRETER_EARLY_EXITS: 1, TOOLS_POST_APPLICATIONS: 41, TOOLS_POST_TIME: 1.9s, TOOLS_POST_CALL_APPLICATIONS: 25, TOOLS_POST_CALL_TIME: 1.2s, TOOLS_POST_RETURN_APPLICATIONS: 18, TOOLS_POST_RETURN_TIME: 0.9s, TOOLS_QUANTIFIERELIM_APPLICATIONS: 84, TOOLS_QUANTIFIERELIM_TIME: 4.0s, TOOLS_QUANTIFIERELIM_MAX_TIME: 0.2s, FLUID_QUERY_TIME: 0.0s, FLUID_QUERIES: 124, FLUID_YES_ANSWERS: 0, DOMAIN_JOIN_APPLICATIONS: 16, DOMAIN_JOIN_TIME: 0.5s, DOMAIN_ALPHA_APPLICATIONS: 0, DOMAIN_ALPHA_TIME: 0.0s, DOMAIN_WIDEN_APPLICATIONS: 0, DOMAIN_WIDEN_TIME: 0.0s, DOMAIN_ISSUBSETEQ_APPLICATIONS: 0, DOMAIN_ISSUBSETEQ_TIME: 0.0s, DOMAIN_ISBOTTOM_APPLICATIONS: 46, DOMAIN_ISBOTTOM_TIME: 0.1s, LOOP_SUMMARIZER_APPLICATIONS: 0, LOOP_SUMMARIZER_CACHE_MISSES: 0, LOOP_SUMMARIZER_OVERALL_TIME: 0.0s, LOOP_SUMMARIZER_NEW_COMPUTATION_TIME: 0.0s, LOOP_SUMMARIZER_FIXPOINT_ITERATIONS: 0, CALL_SUMMARIZER_APPLICATIONS: 18, CALL_SUMMARIZER_CACHE_MISSES: 5, CALL_SUMMARIZER_OVERALL_TIME: 0.1s, CALL_SUMMARIZER_NEW_COMPUTATION_TIME: 0.1s, PROCEDURE_GRAPH_BUILDER_TIME: 0.0s, PATH_EXPR_TIME: 0.0s, REGEX_TO_DAG_TIME: 0.0s, DAG_COMPRESSION_TIME: 0.0s, DAG_COMPRESSION_PROCESSED_NODES: 348, DAG_COMPRESSION_RETAINED_NODES: 122, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 941]: Loop Invariant Derived loop invariant: 0 - InvariantResult [Line: 872]: Location Invariant Derived location invariant: 0 - InvariantResult [Line: 873]: Loop Invariant Derived loop invariant: (((((waterLevel <= 1) && (1 == systemActive)) && (splverifierCounter == 0)) || ((((1 == systemActive) && (methaneLevelCritical != 0)) && (splverifierCounter == 0)) && (waterLevel <= 2))) || ((((2 == waterLevel) && (1 == systemActive)) && (splverifierCounter == 0)) && (pumpRunning == 1))) - InvariantResult [Line: 617]: Location Invariant Derived location invariant: ((((pumpRunning == \old(pumpRunning)) && (1 == systemActive)) && (\old(waterLevel) == waterLevel)) && (\old(waterLevel) <= 2)) - ProcedureContractResult [Line: 751]: Procedure Contract for deactivatePump Derived contract for procedure deactivatePump. Requires: (((pumpRunning != 0) && (waterLevel <= 1)) && (1 == systemActive)) Ensures: (((((\old(pumpRunning) != 0) && (pumpRunning == 0)) && (waterLevel <= 1)) && (1 == systemActive)) && (((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 641]: Procedure Contract for processEnvironment__wrappee__base Derived contract for procedure processEnvironment__wrappee__base. Requires: ((waterLevel <= 1) && (1 == systemActive)) Ensures: (((waterLevel <= 1) && (1 == systemActive)) && ((((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 494]: Procedure Contract for changeMethaneLevel Derived contract for procedure changeMethaneLevel. Requires: ((1 == systemActive) && (waterLevel <= 2)) Ensures: (((1 == systemActive) && (waterLevel <= 2)) && (((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 931]: Procedure Contract for cleanup Derived contract for procedure cleanup. Requires: 0 Ensures: (0 && ((((head == \old(head)) && (methaneLevelCritical == \old(methaneLevelCritical))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 617]: Procedure Contract for timeShift Derived contract for procedure timeShift. Requires: ((1 == systemActive) && (waterLevel <= 2)) Ensures: ((((((((\old(pumpRunning) != 1) || ((waterLevel <= 1) && (pumpRunning == 1))) || ((pumpRunning == 0) && (waterLevel <= 1))) && (((((2 == waterLevel) && (methaneLevelCritical != 0)) || (\old(waterLevel) != 2)) || (waterLevel == 1)) || ((2 == waterLevel) && (pumpRunning == 1)))) && (1 == systemActive)) && ((((((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) || (((pumpRunning == \old(pumpRunning)) && (\old(pumpRunning) != 0)) && (waterLevel <= 1))) || (((waterLevel != 1) && (\old(waterLevel) == waterLevel)) && (pumpRunning == 1))) || (((waterLevel != 1) && (methaneLevelCritical != 0)) && (\old(waterLevel) == waterLevel))) || (((\old(pumpRunning) != 0) && (pumpRunning == 0)) && (waterLevel <= 1)))) && (\old(waterLevel) <= 2)) && ((((head == \old(head)) && (methaneLevelCritical == \old(methaneLevelCritical))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 506]: Procedure Contract for isMethaneLevelCritical Derived contract for procedure isMethaneLevelCritical. Requires: ((((waterLevel <= 1) && (1 == systemActive)) || (((pumpRunning == 0) && (2 == waterLevel)) && (1 == systemActive))) || ((((methaneLevelCritical != 0) || (pumpRunning == 1)) && (1 == systemActive)) && (waterLevel <= 2))) Ensures: (((((((waterLevel <= 1) && (1 == systemActive)) || ((pumpRunning == 0) && (1 == systemActive))) || (((methaneLevelCritical != 0) || (pumpRunning == 1)) && (1 == systemActive))) && (\result == methaneLevelCritical)) && ((2 == waterLevel) || (waterLevel < 2))) && ((((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 649]: Procedure Contract for processEnvironment__wrappee__highWaterSensor Derived contract for procedure processEnvironment__wrappee__highWaterSensor. Requires: (((waterLevel <= 1) && (1 == systemActive)) || (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel <= 2))) Ensures: (((((((waterLevel <= 1) && (1 == systemActive)) || (((1 == systemActive) && (\old(pumpRunning) == 0)) && (waterLevel <= 2))) && (((waterLevel != 1) || (\old(pumpRunning) != 0)) || (pumpRunning == 0))) && ((((\old(pumpRunning) != 0) || (methaneLevelCritical != 0)) || ((pumpRunning == 0) && (waterLevel <= 1))) || (pumpRunning == 1))) && ((pumpRunning == \old(pumpRunning)) || (\old(pumpRunning) == 0))) && (((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 482]: Procedure Contract for waterRise Derived contract for procedure waterRise. Requires: (((((waterLevel <= 1) && (1 == systemActive)) || (((1 == systemActive) && (waterLevel <= 2)) && (pumpRunning == 1))) || (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel <= 2))) || (((2 == waterLevel) && (1 == systemActive)) && (methaneLevelCritical != 0))) Ensures: ((((((((pumpRunning == 0) || (\old(waterLevel) < 2)) || (methaneLevelCritical != 0)) || (pumpRunning == 1)) && (1 == systemActive)) && (waterLevel <= 2)) && ((((long long) \old(waterLevel) + 1) == waterLevel) || ((2 <= \old(waterLevel)) && (\old(waterLevel) == waterLevel)))) && (((((head == \old(head)) && (methaneLevelCritical == \old(methaneLevelCritical))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 675]: Procedure Contract for processEnvironment__wrappee__methaneQuery Derived contract for procedure processEnvironment__wrappee__methaneQuery. Requires: (((waterLevel <= 1) && (1 == systemActive)) || (((pumpRunning == 0) && (1 == systemActive)) && (waterLevel <= 2))) Ensures: (((((((waterLevel <= 1) && (1 == systemActive)) || (((1 == systemActive) && (\old(pumpRunning) == 0)) && (waterLevel <= 2))) && (((waterLevel != 1) || (\old(pumpRunning) != 0)) || (pumpRunning == 0))) && ((((\old(pumpRunning) != 0) || (methaneLevelCritical != 0)) || ((pumpRunning == 0) && (waterLevel <= 1))) || (pumpRunning == 1))) && (((pumpRunning == \old(pumpRunning)) || (pumpRunning == 0)) || (\old(pumpRunning) == 0))) && (((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) - ProcedureContractResult [Line: 759]: Procedure Contract for isMethaneAlarm Derived contract for procedure isMethaneAlarm. Requires: (((((waterLevel != 1) && (waterLevel <= 1)) && (1 == systemActive)) || (((pumpRunning != 0) && (waterLevel <= 1)) && (1 == systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (1 == systemActive))) Ensures: ((((\result == 0) || (methaneLevelCritical != 0)) && (((((waterLevel != 1) && (waterLevel <= 1)) && (1 == systemActive)) || (((pumpRunning != 0) && (waterLevel <= 1)) && (1 == systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (1 == systemActive)))) && ((((((head == \old(head)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (cleanupTimeShifts == \old(cleanupTimeShifts)))) RESULT: Ultimate proved your program to be correct! [2024-11-09 06:24:13,812 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_8c89235b-d96c-4ad8-8654-fecba5844e03/bin/utaipan-verify-YMUCfTKeje/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE