./Ultimate.py --spec ../../sv-benchmarks/c/properties/unreach-call.prp --file ../../sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c --full-output --architecture 32bit -------------------------------------------------------------------------------- Checking for ERROR reachability Using default analysis Version 826ab2ba Calling Ultimate with: /usr/bin/java -Dosgi.configuration.area=/tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/data/config -Xmx15G -Xms4m -jar /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/plugins/org.eclipse.equinox.launcher_1.6.800.v20240513-1750.jar -data @noDefault -ultimatedata /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/data -tc /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/config/TaipanReach.xml -i ../../sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c -s /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/config/svcomp-Reach-32bit-Taipan_Default.epf --cacsl2boogietranslator.entry.function main --witnessprinter.witness.directory /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E --witnessprinter.witness.filename witness --witnessprinter.write.witness.besides.input.file false --witnessprinter.graph.data.specification CHECK( init(main()), LTL(G ! call(reach_error())) ) --witnessprinter.graph.data.producer Taipan --witnessprinter.graph.data.architecture 32bit --witnessprinter.graph.data.programhash 88f09ec5af0f641c9edfe2f7047937341e46c7f8baabeed0fd38f069cd3b5278 --- Real Ultimate output --- This is Ultimate 0.3.0-dev-826ab2b [2024-11-14 04:57:37,183 INFO L188 SettingsManager]: Resetting all preferences to default values... [2024-11-14 04:57:37,274 INFO L114 SettingsManager]: Loading settings from /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/config/svcomp-Reach-32bit-Taipan_Default.epf [2024-11-14 04:57:37,279 WARN L101 SettingsManager]: Preference file contains the following unknown settings: [2024-11-14 04:57:37,279 WARN L103 SettingsManager]: * de.uni_freiburg.informatik.ultimate.core.Log level for class [2024-11-14 04:57:37,304 INFO L130 SettingsManager]: Preferences different from defaults after loading the file: [2024-11-14 04:57:37,305 INFO L151 SettingsManager]: Preferences of UltimateCore differ from their defaults: [2024-11-14 04:57:37,305 INFO L153 SettingsManager]: * Log level for class=de.uni_freiburg.informatik.ultimate.lib.smtlibutils.quantifier.QuantifierPusher=ERROR; [2024-11-14 04:57:37,305 INFO L151 SettingsManager]: Preferences of Boogie Procedure Inliner differ from their defaults: [2024-11-14 04:57:37,305 INFO L153 SettingsManager]: * Ignore calls to procedures called more than once=ONLY_FOR_SEQUENTIAL_PROGRAMS [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * User list type=DISABLED [2024-11-14 04:57:37,306 INFO L151 SettingsManager]: Preferences of Abstract Interpretation differ from their defaults: [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Explicit value domain=true [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Abstract domain for RCFG-of-the-future=PoormanAbstractDomain [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Octagon Domain=false [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Abstract domain=CompoundDomain [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Check feasibility of abstract posts with an SMT solver=true [2024-11-14 04:57:37,306 INFO L153 SettingsManager]: * Use the RCFG-of-the-future interface=true [2024-11-14 04:57:37,307 INFO L153 SettingsManager]: * Interval Domain=false [2024-11-14 04:57:37,307 INFO L151 SettingsManager]: Preferences of Sifa differ from their defaults: [2024-11-14 04:57:37,307 INFO L153 SettingsManager]: * Call Summarizer=TopInputCallSummarizer [2024-11-14 04:57:37,307 INFO L153 SettingsManager]: * Simplification Technique=POLY_PAC [2024-11-14 04:57:37,308 INFO L151 SettingsManager]: Preferences of CACSL2BoogieTranslator differ from their defaults: [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * Pointer base address is valid at dereference=IGNORE [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * sizeof long=4 [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * Overapproximate operations on floating types=true [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * sizeof POINTER=4 [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * Check division by zero=IGNORE [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * Pointer to allocated memory at dereference=IGNORE [2024-11-14 04:57:37,308 INFO L153 SettingsManager]: * If two pointers are subtracted or compared they have the same base address=IGNORE [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * Check array bounds for arrays that are off heap=IGNORE [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * Allow undefined functions=false [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * sizeof long double=12 [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * Check if freed pointer was valid=false [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * Use constant arrays=true [2024-11-14 04:57:37,309 INFO L151 SettingsManager]: Preferences of RCFGBuilder differ from their defaults: [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * Only consider context switches at boundaries of atomic blocks=true [2024-11-14 04:57:37,309 INFO L153 SettingsManager]: * SMT solver=External_DefaultMode [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2024-11-14 04:57:37,310 INFO L151 SettingsManager]: Preferences of TraceAbstraction differ from their defaults: [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Compute Interpolants along a Counterexample=FPandBP [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Positions where we compute the Hoare Annotation=LoopHeads [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Trace refinement strategy=SIFA_TAIPAN [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Command for external solver=z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Apply one-shot large block encoding in concurrent analysis=false [2024-11-14 04:57:37,310 INFO L153 SettingsManager]: * Trace refinement exception blacklist=NONE [2024-11-14 04:57:37,311 INFO L153 SettingsManager]: * SMT solver=External_ModelsAndUnsatCoreMode [2024-11-14 04:57:37,311 INFO L153 SettingsManager]: * Abstract interpretation Mode=USE_PREDICATES Applying setting for plugin de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: Entry function -> main Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness directory -> /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Witness filename -> witness Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Write witness besides input file -> false Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data specification -> CHECK( init(main()), LTL(G ! call(reach_error())) ) Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data producer -> Taipan Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data architecture -> 32bit Applying setting for plugin de.uni_freiburg.informatik.ultimate.witnessprinter: Graph data programhash -> 88f09ec5af0f641c9edfe2f7047937341e46c7f8baabeed0fd38f069cd3b5278 [2024-11-14 04:57:37,609 INFO L75 nceAwareModelManager]: Repository-Root is: /tmp [2024-11-14 04:57:37,622 INFO L261 ainManager$Toolchain]: [Toolchain 1]: Applicable parser(s) successfully (re)initialized [2024-11-14 04:57:37,625 INFO L217 ainManager$Toolchain]: [Toolchain 1]: Toolchain selected. [2024-11-14 04:57:37,626 INFO L270 PluginConnector]: Initializing CDTParser... [2024-11-14 04:57:37,627 INFO L274 PluginConnector]: CDTParser initialized [2024-11-14 04:57:37,629 INFO L431 ainManager$Toolchain]: [Toolchain 1]: Parsing single file: /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/../../sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c Unable to find full path for "g++" [2024-11-14 04:57:39,642 INFO L533 CDTParser]: Created temporary CDT project at NULL [2024-11-14 04:57:40,061 INFO L384 CDTParser]: Found 1 translation units. [2024-11-14 04:57:40,062 INFO L180 CDTParser]: Scanning /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c [2024-11-14 04:57:40,090 INFO L427 CDTParser]: About to delete temporary CDT project at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/data/81a50ad68/238368989fd642b2aeef4769d96644c3/FLAGfc885c7c2 [2024-11-14 04:57:40,113 INFO L435 CDTParser]: Successfully deleted /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/data/81a50ad68/238368989fd642b2aeef4769d96644c3 [2024-11-14 04:57:40,116 INFO L299 ainManager$Toolchain]: ####################### [Toolchain 1] ####################### [2024-11-14 04:57:40,118 INFO L133 ToolchainWalker]: Walking toolchain with 6 elements. [2024-11-14 04:57:40,120 INFO L112 PluginConnector]: ------------------------CACSL2BoogieTranslator---------------------------- [2024-11-14 04:57:40,120 INFO L270 PluginConnector]: Initializing CACSL2BoogieTranslator... [2024-11-14 04:57:40,125 INFO L274 PluginConnector]: CACSL2BoogieTranslator initialized [2024-11-14 04:57:40,126 INFO L184 PluginConnector]: Executing the observer ACSLObjectContainerObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,127 INFO L204 PluginConnector]: Invalid model from CACSL2BoogieTranslator for observer de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator.ACSLObjectContainerObserver@56832954 and model type de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40, skipping insertion in model container [2024-11-14 04:57:40,128 INFO L184 PluginConnector]: Executing the observer CACSL2BoogieTranslatorObserver from plugin CACSL2BoogieTranslator for "CDTParser AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,187 INFO L175 MainTranslator]: Built tables and reachable declarations [2024-11-14 04:57:40,403 WARN L250 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c[3971,3984] [2024-11-14 04:57:40,545 INFO L210 PostProcessor]: Analyzing one entry point: main [2024-11-14 04:57:40,565 INFO L200 MainTranslator]: Completed pre-run [2024-11-14 04:57:40,575 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [49] [2024-11-14 04:57:40,577 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [101] [2024-11-14 04:57:40,578 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [211] [2024-11-14 04:57:40,578 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [220] [2024-11-14 04:57:40,578 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [323] [2024-11-14 04:57:40,578 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [560] [2024-11-14 04:57:40,579 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [627] [2024-11-14 04:57:40,579 WARN L75 lationResultReporter]: Unsoundness Warning: Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [662] [2024-11-14 04:57:40,604 WARN L250 ndardFunctionHandler]: Function reach_error is already implemented but we override the implementation for the call at /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/sv-benchmarks/c/product-lines/minepump_spec5_product54.cil.c[3971,3984] [2024-11-14 04:57:40,663 INFO L210 PostProcessor]: Analyzing one entry point: main [2024-11-14 04:57:40,684 INFO L204 MainTranslator]: Completed translation [2024-11-14 04:57:40,684 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40 WrapperNode [2024-11-14 04:57:40,685 INFO L131 PluginConnector]: ------------------------ END CACSL2BoogieTranslator---------------------------- [2024-11-14 04:57:40,686 INFO L112 PluginConnector]: ------------------------Boogie Procedure Inliner---------------------------- [2024-11-14 04:57:40,686 INFO L270 PluginConnector]: Initializing Boogie Procedure Inliner... [2024-11-14 04:57:40,686 INFO L274 PluginConnector]: Boogie Procedure Inliner initialized [2024-11-14 04:57:40,693 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,706 INFO L184 PluginConnector]: Executing the observer Inliner from plugin Boogie Procedure Inliner for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,744 INFO L138 Inliner]: procedures = 59, calls = 106, calls flagged for inlining = 26, calls inlined = 23, statements flattened = 235 [2024-11-14 04:57:40,747 INFO L131 PluginConnector]: ------------------------ END Boogie Procedure Inliner---------------------------- [2024-11-14 04:57:40,748 INFO L112 PluginConnector]: ------------------------Boogie Preprocessor---------------------------- [2024-11-14 04:57:40,748 INFO L270 PluginConnector]: Initializing Boogie Preprocessor... [2024-11-14 04:57:40,748 INFO L274 PluginConnector]: Boogie Preprocessor initialized [2024-11-14 04:57:40,756 INFO L184 PluginConnector]: Executing the observer EnsureBoogieModelObserver from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,757 INFO L184 PluginConnector]: Executing the observer TypeChecker from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,759 INFO L184 PluginConnector]: Executing the observer ConstExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,763 INFO L184 PluginConnector]: Executing the observer StructExpander from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,772 INFO L184 PluginConnector]: Executing the observer UnstructureCode from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,780 INFO L184 PluginConnector]: Executing the observer FunctionInliner from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,785 INFO L184 PluginConnector]: Executing the observer LTLStepAnnotator from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,786 INFO L184 PluginConnector]: Executing the observer BoogieSymbolTableConstructor from plugin Boogie Preprocessor for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,791 INFO L131 PluginConnector]: ------------------------ END Boogie Preprocessor---------------------------- [2024-11-14 04:57:40,792 INFO L112 PluginConnector]: ------------------------RCFGBuilder---------------------------- [2024-11-14 04:57:40,792 INFO L270 PluginConnector]: Initializing RCFGBuilder... [2024-11-14 04:57:40,793 INFO L274 PluginConnector]: RCFGBuilder initialized [2024-11-14 04:57:40,797 INFO L184 PluginConnector]: Executing the observer RCFGBuilderObserver from plugin RCFGBuilder for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (1/1) ... [2024-11-14 04:57:40,810 INFO L173 SolverBuilder]: Constructing external solver with command: z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 [2024-11-14 04:57:40,831 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 [2024-11-14 04:57:40,847 INFO L229 MonitoredProcess]: Starting monitored process 1 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (exit command is (exit), workingDir is null) [2024-11-14 04:57:40,854 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Waiting until timeout for monitored process [2024-11-14 04:57:40,885 INFO L130 BoogieDeclarations]: Found specification of procedure #Ultimate.allocInit [2024-11-14 04:57:40,885 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__base [2024-11-14 04:57:40,885 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__base [2024-11-14 04:57:40,886 INFO L130 BoogieDeclarations]: Found specification of procedure timeShift [2024-11-14 04:57:40,886 INFO L138 BoogieDeclarations]: Found implementation of procedure timeShift [2024-11-14 04:57:40,886 INFO L130 BoogieDeclarations]: Found specification of procedure cleanup [2024-11-14 04:57:40,886 INFO L138 BoogieDeclarations]: Found implementation of procedure cleanup [2024-11-14 04:57:40,886 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__highWaterSensor [2024-11-14 04:57:40,887 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__highWaterSensor [2024-11-14 04:57:40,888 INFO L130 BoogieDeclarations]: Found specification of procedure waterRise [2024-11-14 04:57:40,888 INFO L138 BoogieDeclarations]: Found implementation of procedure waterRise [2024-11-14 04:57:40,888 INFO L130 BoogieDeclarations]: Found specification of procedure processEnvironment__wrappee__lowWaterSensor [2024-11-14 04:57:40,888 INFO L138 BoogieDeclarations]: Found implementation of procedure processEnvironment__wrappee__lowWaterSensor [2024-11-14 04:57:40,888 INFO L130 BoogieDeclarations]: Found specification of procedure isPumpRunning [2024-11-14 04:57:40,889 INFO L138 BoogieDeclarations]: Found implementation of procedure isPumpRunning [2024-11-14 04:57:40,890 INFO L130 BoogieDeclarations]: Found specification of procedure deactivatePump [2024-11-14 04:57:40,890 INFO L138 BoogieDeclarations]: Found implementation of procedure deactivatePump [2024-11-14 04:57:40,890 INFO L130 BoogieDeclarations]: Found specification of procedure write~init~int [2024-11-14 04:57:40,890 INFO L130 BoogieDeclarations]: Found specification of procedure changeMethaneLevel [2024-11-14 04:57:40,890 INFO L138 BoogieDeclarations]: Found implementation of procedure changeMethaneLevel [2024-11-14 04:57:40,890 INFO L130 BoogieDeclarations]: Found specification of procedure ULTIMATE.start [2024-11-14 04:57:40,890 INFO L138 BoogieDeclarations]: Found implementation of procedure ULTIMATE.start [2024-11-14 04:57:40,983 INFO L238 CfgBuilder]: Building ICFG [2024-11-14 04:57:40,985 INFO L264 CfgBuilder]: Building CFG for each procedure with an implementation [2024-11-14 04:57:41,460 INFO L? ?]: Removed 51 outVars from TransFormulas that were not future-live. [2024-11-14 04:57:41,460 INFO L287 CfgBuilder]: Performing block encoding [2024-11-14 04:57:41,646 INFO L311 CfgBuilder]: Using the 1 location(s) as analysis (start of procedure ULTIMATE.start) [2024-11-14 04:57:41,647 INFO L316 CfgBuilder]: Removed 2 assume(true) statements. [2024-11-14 04:57:41,647 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.11 04:57:41 BoogieIcfgContainer [2024-11-14 04:57:41,647 INFO L131 PluginConnector]: ------------------------ END RCFGBuilder---------------------------- [2024-11-14 04:57:41,651 INFO L112 PluginConnector]: ------------------------TraceAbstraction---------------------------- [2024-11-14 04:57:41,652 INFO L270 PluginConnector]: Initializing TraceAbstraction... [2024-11-14 04:57:41,657 INFO L274 PluginConnector]: TraceAbstraction initialized [2024-11-14 04:57:41,658 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "CDTParser AST 14.11 04:57:40" (1/3) ... [2024-11-14 04:57:41,658 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6e92dc6d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.11 04:57:41, skipping insertion in model container [2024-11-14 04:57:41,658 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator AST 14.11 04:57:40" (2/3) ... [2024-11-14 04:57:41,659 INFO L204 PluginConnector]: Invalid model from TraceAbstraction for observer de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction.TraceAbstractionObserver@6e92dc6d and model type de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction AST 14.11 04:57:41, skipping insertion in model container [2024-11-14 04:57:41,659 INFO L184 PluginConnector]: Executing the observer TraceAbstractionObserver from plugin TraceAbstraction for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.11 04:57:41" (3/3) ... [2024-11-14 04:57:41,660 INFO L112 eAbstractionObserver]: Analyzing ICFG minepump_spec5_product54.cil.c [2024-11-14 04:57:41,674 INFO L217 ceAbstractionStarter]: Automizer settings: Hoare:LoopHeads NWA Interpolation:FPandBP Determinization: PREDICATE_ABSTRACTION [2024-11-14 04:57:41,676 INFO L154 ceAbstractionStarter]: Applying trace abstraction to ICFG minepump_spec5_product54.cil.c that has 10 procedures, 69 locations, 1 initial locations, 2 loop locations, and 1 error locations. [2024-11-14 04:57:41,750 INFO L332 AbstractCegarLoop]: ======== Iteration 0 == of CEGAR loop == AllErrorsAtOnce ======== [2024-11-14 04:57:41,766 INFO L333 AbstractCegarLoop]: Settings: SEPARATE_VIOLATION_CHECK=true, mInterprocedural=true, mMaxIterations=1000000, mWatchIteration=1000000, mArtifact=RCFG, mInterpolation=FPandBP, mInterpolantAutomaton=STRAIGHT_LINE, mDumpAutomata=false, mAutomataFormat=ATS_NUMERATE, mDumpPath=., mDeterminiation=PREDICATE_ABSTRACTION, mMinimize=MINIMIZE_SEVPA, mAutomataTypeConcurrency=FINITE_AUTOMATA, mHoareTripleChecks=INCREMENTAL, mHoareAnnotationPositions=LoopHeads, mDumpOnlyReuseAutomata=false, mLimitTraceHistogram=0, mErrorLocTimeLimit=0, mLimitPathProgramCount=0, mCollectInterpolantStatistics=true, mHeuristicEmptinessCheck=false, mHeuristicEmptinessCheckAStarHeuristic=ZERO, mHeuristicEmptinessCheckAStarHeuristicRandomSeed=1337, mHeuristicEmptinessCheckSmtFeatureScoringMethod=DAGSIZE, mSMTFeatureExtraction=false, mSMTFeatureExtractionDumpPath=., mOverrideInterpolantAutomaton=false, mMcrInterpolantMethod=WP, mPorIndependenceSettings=[Lde.uni_freiburg.informatik.ultimate.lib.tracecheckerutils.partialorder.independence.IndependenceSettings;@5164e89, mLbeIndependenceSettings=[IndependenceType=SEMANTIC, AbstractionType=NONE, UseConditional=false, UseSemiCommutativity=true, Solver=Z3, SolverTimeout=1000ms] [2024-11-14 04:57:41,767 INFO L334 AbstractCegarLoop]: Starting to check reachability of 1 error locations. [2024-11-14 04:57:41,772 INFO L276 IsEmpty]: Start isEmpty. Operand has 69 states, 42 states have (on average 1.4285714285714286) internal successors, (60), 52 states have internal predecessors, (60), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) [2024-11-14 04:57:41,783 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 22 [2024-11-14 04:57:41,783 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:41,784 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:41,785 INFO L396 AbstractCegarLoop]: === Iteration 1 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:41,790 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:41,791 INFO L85 PathProgramCache]: Analyzing trace with hash -130416555, now seen corresponding path program 1 times [2024-11-14 04:57:41,799 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:41,799 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [959687827] [2024-11-14 04:57:41,799 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:41,800 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:41,916 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:42,014 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2024-11-14 04:57:42,015 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:42,015 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [959687827] [2024-11-14 04:57:42,016 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [959687827] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:42,016 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:42,016 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [2] imperfect sequences [] total 2 [2024-11-14 04:57:42,017 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1079343174] [2024-11-14 04:57:42,018 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:42,022 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 2 states [2024-11-14 04:57:42,022 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:42,042 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 2 interpolants. [2024-11-14 04:57:42,043 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2024-11-14 04:57:42,045 INFO L87 Difference]: Start difference. First operand has 69 states, 42 states have (on average 1.4285714285714286) internal successors, (60), 52 states have internal predecessors, (60), 16 states have call successors, (16), 9 states have call predecessors, (16), 9 states have return successors, (16), 11 states have call predecessors, (16), 16 states have call successors, (16) Second operand has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2024-11-14 04:57:42,143 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:42,144 INFO L93 Difference]: Finished difference Result 136 states and 185 transitions. [2024-11-14 04:57:42,145 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 2 states. [2024-11-14 04:57:42,147 INFO L78 Accepts]: Start accepts. Automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) Word has length 21 [2024-11-14 04:57:42,147 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:42,156 INFO L225 Difference]: With dead ends: 136 [2024-11-14 04:57:42,156 INFO L226 Difference]: Without dead ends: 64 [2024-11-14 04:57:42,160 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 2 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 0 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=1, Invalid=1, Unknown=0, NotChecked=0, Total=2 [2024-11-14 04:57:42,166 INFO L432 NwaCegarLoop]: 71 mSDtfsCounter, 0 mSDsluCounter, 0 mSDsCounter, 0 mSdLazyCounter, 18 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 0 SdHoareTripleChecker+Valid, 71 SdHoareTripleChecker+Invalid, 19 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 18 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:42,169 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [0 Valid, 71 Invalid, 19 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 18 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2024-11-14 04:57:42,180 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 64 states. [2024-11-14 04:57:42,199 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 64 to 64. [2024-11-14 04:57:42,201 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 64 states, 39 states have (on average 1.3333333333333333) internal successors, (52), 48 states have internal predecessors, (52), 16 states have call successors, (16), 9 states have call predecessors, (16), 8 states have return successors, (15), 10 states have call predecessors, (15), 15 states have call successors, (15) [2024-11-14 04:57:42,206 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 64 states to 64 states and 83 transitions. [2024-11-14 04:57:42,208 INFO L78 Accepts]: Start accepts. Automaton has 64 states and 83 transitions. Word has length 21 [2024-11-14 04:57:42,208 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:42,208 INFO L471 AbstractCegarLoop]: Abstraction has 64 states and 83 transitions. [2024-11-14 04:57:42,208 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 2 states, 2 states have (on average 7.0) internal successors, (14), 2 states have internal predecessors, (14), 1 states have call successors, (4), 2 states have call predecessors, (4), 1 states have return successors, (2), 1 states have call predecessors, (2), 1 states have call successors, (2) [2024-11-14 04:57:42,208 INFO L276 IsEmpty]: Start isEmpty. Operand 64 states and 83 transitions. [2024-11-14 04:57:42,211 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 25 [2024-11-14 04:57:42,211 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:42,211 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:42,211 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable0 [2024-11-14 04:57:42,211 INFO L396 AbstractCegarLoop]: === Iteration 2 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:42,212 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:42,212 INFO L85 PathProgramCache]: Analyzing trace with hash 1331200684, now seen corresponding path program 1 times [2024-11-14 04:57:42,212 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:42,212 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1884343800] [2024-11-14 04:57:42,213 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:42,213 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:42,245 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:42,478 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 1 proven. 0 refuted. 0 times theorem prover too weak. 1 trivial. 0 not checked. [2024-11-14 04:57:42,478 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:42,478 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1884343800] [2024-11-14 04:57:42,478 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1884343800] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:42,478 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:42,478 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2024-11-14 04:57:42,478 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1007341327] [2024-11-14 04:57:42,479 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:42,480 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2024-11-14 04:57:42,480 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:42,480 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2024-11-14 04:57:42,481 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=9, Invalid=21, Unknown=0, NotChecked=0, Total=30 [2024-11-14 04:57:42,481 INFO L87 Difference]: Start difference. First operand 64 states and 83 transitions. Second operand has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2024-11-14 04:57:42,817 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:42,817 INFO L93 Difference]: Finished difference Result 172 states and 238 transitions. [2024-11-14 04:57:42,818 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2024-11-14 04:57:42,818 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) Word has length 24 [2024-11-14 04:57:42,819 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:42,820 INFO L225 Difference]: With dead ends: 172 [2024-11-14 04:57:42,820 INFO L226 Difference]: Without dead ends: 110 [2024-11-14 04:57:42,821 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 10 GetRequests, 3 SyntacticMatches, 0 SemanticMatches, 7 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=21, Invalid=51, Unknown=0, NotChecked=0, Total=72 [2024-11-14 04:57:42,822 INFO L432 NwaCegarLoop]: 76 mSDtfsCounter, 50 mSDsluCounter, 250 mSDsCounter, 0 mSdLazyCounter, 126 mSolverCounterSat, 7 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 51 SdHoareTripleChecker+Valid, 326 SdHoareTripleChecker+Invalid, 133 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 7 IncrementalHoareTripleChecker+Valid, 126 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:42,823 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [51 Valid, 326 Invalid, 133 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [7 Valid, 126 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2024-11-14 04:57:42,824 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 110 states. [2024-11-14 04:57:42,840 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 110 to 110. [2024-11-14 04:57:42,841 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 110 states, 70 states have (on average 1.2571428571428571) internal successors, (88), 78 states have internal predecessors, (88), 24 states have call successors, (24), 17 states have call predecessors, (24), 15 states have return successors, (32), 20 states have call predecessors, (32), 22 states have call successors, (32) [2024-11-14 04:57:42,843 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 110 states to 110 states and 144 transitions. [2024-11-14 04:57:42,844 INFO L78 Accepts]: Start accepts. Automaton has 110 states and 144 transitions. Word has length 24 [2024-11-14 04:57:42,844 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:42,844 INFO L471 AbstractCegarLoop]: Abstraction has 110 states and 144 transitions. [2024-11-14 04:57:42,844 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 5 states have (on average 3.8) internal successors, (19), 5 states have internal predecessors, (19), 1 states have call successors, (3), 2 states have call predecessors, (3), 2 states have return successors, (2), 2 states have call predecessors, (2), 1 states have call successors, (2) [2024-11-14 04:57:42,845 INFO L276 IsEmpty]: Start isEmpty. Operand 110 states and 144 transitions. [2024-11-14 04:57:42,846 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 36 [2024-11-14 04:57:42,846 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:42,846 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:42,846 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable1 [2024-11-14 04:57:42,846 INFO L396 AbstractCegarLoop]: === Iteration 3 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:42,847 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:42,847 INFO L85 PathProgramCache]: Analyzing trace with hash 617696831, now seen corresponding path program 1 times [2024-11-14 04:57:42,847 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:42,847 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [393861705] [2024-11-14 04:57:42,847 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:42,848 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:42,863 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:42,961 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2024-11-14 04:57:42,962 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:42,962 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [393861705] [2024-11-14 04:57:42,962 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [393861705] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:42,962 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:42,962 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [3] imperfect sequences [] total 3 [2024-11-14 04:57:42,962 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [639726067] [2024-11-14 04:57:42,962 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:42,963 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 3 states [2024-11-14 04:57:42,963 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:42,963 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 3 interpolants. [2024-11-14 04:57:42,963 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-14 04:57:42,964 INFO L87 Difference]: Start difference. First operand 110 states and 144 transitions. Second operand has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 2 states have call successors, (6), 2 states have call predecessors, (6), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2024-11-14 04:57:43,035 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:43,035 INFO L93 Difference]: Finished difference Result 176 states and 226 transitions. [2024-11-14 04:57:43,040 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 3 states. [2024-11-14 04:57:43,040 INFO L78 Accepts]: Start accepts. Automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 2 states have call successors, (6), 2 states have call predecessors, (6), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) Word has length 35 [2024-11-14 04:57:43,040 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:43,041 INFO L225 Difference]: With dead ends: 176 [2024-11-14 04:57:43,042 INFO L226 Difference]: Without dead ends: 94 [2024-11-14 04:57:43,042 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 3 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 1 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=3, Invalid=3, Unknown=0, NotChecked=0, Total=6 [2024-11-14 04:57:43,047 INFO L432 NwaCegarLoop]: 57 mSDtfsCounter, 7 mSDsluCounter, 48 mSDsCounter, 0 mSdLazyCounter, 27 mSolverCounterSat, 0 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 10 SdHoareTripleChecker+Valid, 105 SdHoareTripleChecker+Invalid, 27 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Valid, 27 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:43,047 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [10 Valid, 105 Invalid, 27 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [0 Valid, 27 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2024-11-14 04:57:43,048 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 94 states. [2024-11-14 04:57:43,075 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 94 to 94. [2024-11-14 04:57:43,076 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 94 states, 60 states have (on average 1.2666666666666666) internal successors, (76), 68 states have internal predecessors, (76), 18 states have call successors, (18), 15 states have call predecessors, (18), 15 states have return successors, (24), 16 states have call predecessors, (24), 18 states have call successors, (24) [2024-11-14 04:57:43,077 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 94 states to 94 states and 118 transitions. [2024-11-14 04:57:43,078 INFO L78 Accepts]: Start accepts. Automaton has 94 states and 118 transitions. Word has length 35 [2024-11-14 04:57:43,078 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:43,078 INFO L471 AbstractCegarLoop]: Abstraction has 94 states and 118 transitions. [2024-11-14 04:57:43,078 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 3 states, 3 states have (on average 8.0) internal successors, (24), 3 states have internal predecessors, (24), 2 states have call successors, (6), 2 states have call predecessors, (6), 1 states have return successors, (4), 2 states have call predecessors, (4), 2 states have call successors, (4) [2024-11-14 04:57:43,078 INFO L276 IsEmpty]: Start isEmpty. Operand 94 states and 118 transitions. [2024-11-14 04:57:43,079 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 38 [2024-11-14 04:57:43,079 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:43,079 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:43,080 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable2 [2024-11-14 04:57:43,080 INFO L396 AbstractCegarLoop]: === Iteration 4 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:43,080 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:43,080 INFO L85 PathProgramCache]: Analyzing trace with hash -806558995, now seen corresponding path program 1 times [2024-11-14 04:57:43,080 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:43,080 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [792151093] [2024-11-14 04:57:43,081 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:43,081 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:43,114 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:43,619 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2024-11-14 04:57:43,619 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:43,619 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [792151093] [2024-11-14 04:57:43,619 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [792151093] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:43,619 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:43,619 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [6] imperfect sequences [] total 6 [2024-11-14 04:57:43,620 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1771475602] [2024-11-14 04:57:43,620 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:43,620 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 6 states [2024-11-14 04:57:43,620 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:43,621 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 6 interpolants. [2024-11-14 04:57:43,621 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=11, Invalid=19, Unknown=0, NotChecked=0, Total=30 [2024-11-14 04:57:43,623 INFO L87 Difference]: Start difference. First operand 94 states and 118 transitions. Second operand has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2024-11-14 04:57:43,869 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:43,869 INFO L93 Difference]: Finished difference Result 272 states and 341 transitions. [2024-11-14 04:57:43,870 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2024-11-14 04:57:43,870 INFO L78 Accepts]: Start accepts. Automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) Word has length 37 [2024-11-14 04:57:43,870 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:43,873 INFO L225 Difference]: With dead ends: 272 [2024-11-14 04:57:43,873 INFO L226 Difference]: Without dead ends: 180 [2024-11-14 04:57:43,874 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 9 GetRequests, 4 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=16, Invalid=26, Unknown=0, NotChecked=0, Total=42 [2024-11-14 04:57:43,875 INFO L432 NwaCegarLoop]: 86 mSDtfsCounter, 93 mSDsluCounter, 152 mSDsCounter, 0 mSdLazyCounter, 128 mSolverCounterSat, 18 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 93 SdHoareTripleChecker+Valid, 238 SdHoareTripleChecker+Invalid, 146 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 18 IncrementalHoareTripleChecker+Valid, 128 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:43,875 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [93 Valid, 238 Invalid, 146 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [18 Valid, 128 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2024-11-14 04:57:43,880 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 180 states. [2024-11-14 04:57:43,904 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 180 to 174. [2024-11-14 04:57:43,904 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 174 states, 111 states have (on average 1.2342342342342343) internal successors, (137), 123 states have internal predecessors, (137), 33 states have call successors, (33), 28 states have call predecessors, (33), 29 states have return successors, (45), 30 states have call predecessors, (45), 33 states have call successors, (45) [2024-11-14 04:57:43,906 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 174 states to 174 states and 215 transitions. [2024-11-14 04:57:43,907 INFO L78 Accepts]: Start accepts. Automaton has 174 states and 215 transitions. Word has length 37 [2024-11-14 04:57:43,907 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:43,907 INFO L471 AbstractCegarLoop]: Abstraction has 174 states and 215 transitions. [2024-11-14 04:57:43,907 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 6 states, 6 states have (on average 4.5) internal successors, (27), 6 states have internal predecessors, (27), 4 states have call successors, (5), 2 states have call predecessors, (5), 2 states have return successors, (4), 3 states have call predecessors, (4), 4 states have call successors, (4) [2024-11-14 04:57:43,907 INFO L276 IsEmpty]: Start isEmpty. Operand 174 states and 215 transitions. [2024-11-14 04:57:43,913 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 41 [2024-11-14 04:57:43,913 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:43,913 INFO L215 NwaCegarLoop]: trace histogram [2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:43,914 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable3 [2024-11-14 04:57:43,914 INFO L396 AbstractCegarLoop]: === Iteration 5 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:43,915 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:43,915 INFO L85 PathProgramCache]: Analyzing trace with hash -383403695, now seen corresponding path program 1 times [2024-11-14 04:57:43,916 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:43,916 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1242811573] [2024-11-14 04:57:43,916 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:43,916 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:43,947 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:44,286 INFO L134 CoverageAnalysis]: Checked inductivity of 2 backedges. 0 proven. 0 refuted. 0 times theorem prover too weak. 2 trivial. 0 not checked. [2024-11-14 04:57:44,286 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:44,286 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1242811573] [2024-11-14 04:57:44,286 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1242811573] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:44,286 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:44,287 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [8] imperfect sequences [] total 8 [2024-11-14 04:57:44,287 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1363655833] [2024-11-14 04:57:44,287 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:44,287 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 8 states [2024-11-14 04:57:44,287 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:44,288 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 8 interpolants. [2024-11-14 04:57:44,288 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=17, Invalid=39, Unknown=0, NotChecked=0, Total=56 [2024-11-14 04:57:44,289 INFO L87 Difference]: Start difference. First operand 174 states and 215 transitions. Second operand has 8 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2024-11-14 04:57:44,914 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:44,917 INFO L93 Difference]: Finished difference Result 404 states and 512 transitions. [2024-11-14 04:57:44,917 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 12 states. [2024-11-14 04:57:44,918 INFO L78 Accepts]: Start accepts. Automaton has has 8 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) Word has length 40 [2024-11-14 04:57:44,918 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:44,921 INFO L225 Difference]: With dead ends: 404 [2024-11-14 04:57:44,923 INFO L226 Difference]: Without dead ends: 285 [2024-11-14 04:57:44,924 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 16 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 11 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 18 ImplicationChecksByTransitivity, 0.1s TimeCoverageRelationStatistics Valid=54, Invalid=102, Unknown=0, NotChecked=0, Total=156 [2024-11-14 04:57:44,928 INFO L432 NwaCegarLoop]: 63 mSDtfsCounter, 243 mSDsluCounter, 136 mSDsCounter, 0 mSdLazyCounter, 274 mSolverCounterSat, 106 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 251 SdHoareTripleChecker+Valid, 199 SdHoareTripleChecker+Invalid, 380 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 106 IncrementalHoareTripleChecker+Valid, 274 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:44,928 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [251 Valid, 199 Invalid, 380 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [106 Valid, 274 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2024-11-14 04:57:44,930 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 285 states. [2024-11-14 04:57:45,005 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 285 to 258. [2024-11-14 04:57:45,007 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 258 states, 169 states have (on average 1.242603550295858) internal successors, (210), 186 states have internal predecessors, (210), 46 states have call successors, (46), 35 states have call predecessors, (46), 42 states have return successors, (65), 47 states have call predecessors, (65), 46 states have call successors, (65) [2024-11-14 04:57:45,010 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 258 states to 258 states and 321 transitions. [2024-11-14 04:57:45,011 INFO L78 Accepts]: Start accepts. Automaton has 258 states and 321 transitions. Word has length 40 [2024-11-14 04:57:45,012 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:45,012 INFO L471 AbstractCegarLoop]: Abstraction has 258 states and 321 transitions. [2024-11-14 04:57:45,012 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 8 states, 7 states have (on average 4.0) internal successors, (28), 7 states have internal predecessors, (28), 5 states have call successors, (6), 3 states have call predecessors, (6), 2 states have return successors, (5), 4 states have call predecessors, (5), 5 states have call successors, (5) [2024-11-14 04:57:45,012 INFO L276 IsEmpty]: Start isEmpty. Operand 258 states and 321 transitions. [2024-11-14 04:57:45,015 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 58 [2024-11-14 04:57:45,018 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:45,018 INFO L215 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:45,018 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable4 [2024-11-14 04:57:45,018 INFO L396 AbstractCegarLoop]: === Iteration 6 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:45,019 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:45,019 INFO L85 PathProgramCache]: Analyzing trace with hash -947674106, now seen corresponding path program 1 times [2024-11-14 04:57:45,019 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:45,020 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [567164221] [2024-11-14 04:57:45,022 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:45,022 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:45,064 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:45,259 INFO L134 CoverageAnalysis]: Checked inductivity of 19 backedges. 13 proven. 0 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2024-11-14 04:57:45,260 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:45,260 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [567164221] [2024-11-14 04:57:45,260 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [567164221] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:45,260 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:45,260 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [4] imperfect sequences [] total 4 [2024-11-14 04:57:45,261 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1547364237] [2024-11-14 04:57:45,261 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:45,261 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 4 states [2024-11-14 04:57:45,261 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:45,262 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 4 interpolants. [2024-11-14 04:57:45,263 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=5, Invalid=7, Unknown=0, NotChecked=0, Total=12 [2024-11-14 04:57:45,263 INFO L87 Difference]: Start difference. First operand 258 states and 321 transitions. Second operand has 4 states, 4 states have (on average 10.0) internal successors, (40), 4 states have internal predecessors, (40), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2024-11-14 04:57:45,402 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:45,403 INFO L93 Difference]: Finished difference Result 514 states and 646 transitions. [2024-11-14 04:57:45,404 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 4 states. [2024-11-14 04:57:45,404 INFO L78 Accepts]: Start accepts. Automaton has has 4 states, 4 states have (on average 10.0) internal successors, (40), 4 states have internal predecessors, (40), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) Word has length 57 [2024-11-14 04:57:45,406 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:45,409 INFO L225 Difference]: With dead ends: 514 [2024-11-14 04:57:45,409 INFO L226 Difference]: Without dead ends: 258 [2024-11-14 04:57:45,411 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 8 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 3 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 0 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=9, Invalid=11, Unknown=0, NotChecked=0, Total=20 [2024-11-14 04:57:45,413 INFO L432 NwaCegarLoop]: 54 mSDtfsCounter, 52 mSDsluCounter, 53 mSDsCounter, 0 mSdLazyCounter, 34 mSolverCounterSat, 1 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.0s Time, 0 mProtectedPredicate, 0 mProtectedAction, 52 SdHoareTripleChecker+Valid, 107 SdHoareTripleChecker+Invalid, 35 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 1 IncrementalHoareTripleChecker+Valid, 34 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.1s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:45,416 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [52 Valid, 107 Invalid, 35 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [1 Valid, 34 Invalid, 0 Unknown, 0 Unchecked, 0.1s Time] [2024-11-14 04:57:45,417 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 258 states. [2024-11-14 04:57:45,485 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 258 to 258. [2024-11-14 04:57:45,485 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 258 states, 169 states have (on average 1.21301775147929) internal successors, (205), 186 states have internal predecessors, (205), 46 states have call successors, (46), 35 states have call predecessors, (46), 42 states have return successors, (65), 47 states have call predecessors, (65), 46 states have call successors, (65) [2024-11-14 04:57:45,489 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 258 states to 258 states and 316 transitions. [2024-11-14 04:57:45,490 INFO L78 Accepts]: Start accepts. Automaton has 258 states and 316 transitions. Word has length 57 [2024-11-14 04:57:45,492 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:45,492 INFO L471 AbstractCegarLoop]: Abstraction has 258 states and 316 transitions. [2024-11-14 04:57:45,492 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 4 states, 4 states have (on average 10.0) internal successors, (40), 4 states have internal predecessors, (40), 3 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (7), 3 states have call predecessors, (7), 3 states have call successors, (7) [2024-11-14 04:57:45,492 INFO L276 IsEmpty]: Start isEmpty. Operand 258 states and 316 transitions. [2024-11-14 04:57:45,495 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 72 [2024-11-14 04:57:45,495 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:45,495 INFO L215 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:45,495 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable5 [2024-11-14 04:57:45,496 INFO L396 AbstractCegarLoop]: === Iteration 7 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:45,498 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:45,498 INFO L85 PathProgramCache]: Analyzing trace with hash -1479979777, now seen corresponding path program 1 times [2024-11-14 04:57:45,499 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:45,499 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [2113766869] [2024-11-14 04:57:45,499 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:45,499 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:45,537 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:45,651 INFO L134 CoverageAnalysis]: Checked inductivity of 31 backedges. 8 proven. 0 refuted. 0 times theorem prover too weak. 23 trivial. 0 not checked. [2024-11-14 04:57:45,652 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:45,652 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [2113766869] [2024-11-14 04:57:45,652 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [2113766869] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:57:45,652 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:57:45,652 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2024-11-14 04:57:45,652 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [739588984] [2024-11-14 04:57:45,652 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:57:45,653 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2024-11-14 04:57:45,653 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:57:45,653 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2024-11-14 04:57:45,654 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2024-11-14 04:57:45,654 INFO L87 Difference]: Start difference. First operand 258 states and 316 transitions. Second operand has 5 states, 5 states have (on average 7.6) internal successors, (38), 5 states have internal predecessors, (38), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2024-11-14 04:57:46,015 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:57:46,015 INFO L93 Difference]: Finished difference Result 401 states and 493 transitions. [2024-11-14 04:57:46,016 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 7 states. [2024-11-14 04:57:46,016 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 5 states have internal predecessors, (38), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) Word has length 71 [2024-11-14 04:57:46,016 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:57:46,019 INFO L225 Difference]: With dead ends: 401 [2024-11-14 04:57:46,019 INFO L226 Difference]: Without dead ends: 264 [2024-11-14 04:57:46,020 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 11 GetRequests, 5 SyntacticMatches, 0 SemanticMatches, 6 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 3 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=19, Invalid=37, Unknown=0, NotChecked=0, Total=56 [2024-11-14 04:57:46,021 INFO L432 NwaCegarLoop]: 80 mSDtfsCounter, 121 mSDsluCounter, 93 mSDsCounter, 0 mSdLazyCounter, 153 mSolverCounterSat, 53 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.2s Time, 0 mProtectedPredicate, 0 mProtectedAction, 124 SdHoareTripleChecker+Valid, 173 SdHoareTripleChecker+Invalid, 206 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 53 IncrementalHoareTripleChecker+Valid, 153 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.3s IncrementalHoareTripleChecker+Time [2024-11-14 04:57:46,021 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [124 Valid, 173 Invalid, 206 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [53 Valid, 153 Invalid, 0 Unknown, 0 Unchecked, 0.3s Time] [2024-11-14 04:57:46,022 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 264 states. [2024-11-14 04:57:46,080 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 264 to 262. [2024-11-14 04:57:46,081 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 262 states, 171 states have (on average 1.1754385964912282) internal successors, (201), 187 states have internal predecessors, (201), 45 states have call successors, (45), 37 states have call predecessors, (45), 45 states have return successors, (56), 48 states have call predecessors, (56), 45 states have call successors, (56) [2024-11-14 04:57:46,084 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 262 states to 262 states and 302 transitions. [2024-11-14 04:57:46,084 INFO L78 Accepts]: Start accepts. Automaton has 262 states and 302 transitions. Word has length 71 [2024-11-14 04:57:46,085 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:57:46,085 INFO L471 AbstractCegarLoop]: Abstraction has 262 states and 302 transitions. [2024-11-14 04:57:46,085 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 7.6) internal successors, (38), 5 states have internal predecessors, (38), 4 states have call successors, (8), 2 states have call predecessors, (8), 2 states have return successors, (8), 3 states have call predecessors, (8), 4 states have call successors, (8) [2024-11-14 04:57:46,085 INFO L276 IsEmpty]: Start isEmpty. Operand 262 states and 302 transitions. [2024-11-14 04:57:46,087 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 75 [2024-11-14 04:57:46,087 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:57:46,087 INFO L215 NwaCegarLoop]: trace histogram [3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:57:46,087 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable6 [2024-11-14 04:57:46,088 INFO L396 AbstractCegarLoop]: === Iteration 8 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:57:46,088 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:57:46,088 INFO L85 PathProgramCache]: Analyzing trace with hash -1220553049, now seen corresponding path program 1 times [2024-11-14 04:57:46,088 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:57:46,089 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1381778698] [2024-11-14 04:57:46,089 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:46,089 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:57:46,116 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:46,232 INFO L134 CoverageAnalysis]: Checked inductivity of 29 backedges. 7 proven. 1 refuted. 0 times theorem prover too weak. 21 trivial. 0 not checked. [2024-11-14 04:57:46,232 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:57:46,233 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1381778698] [2024-11-14 04:57:46,233 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1381778698] provided 0 perfect and 1 imperfect interpolant sequences [2024-11-14 04:57:46,233 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [853805662] [2024-11-14 04:57:46,233 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:57:46,233 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-14 04:57:46,233 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 [2024-11-14 04:57:46,236 INFO L229 MonitoredProcess]: Starting monitored process 2 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2024-11-14 04:57:46,239 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Waiting until timeout for monitored process [2024-11-14 04:57:46,387 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:57:46,390 INFO L255 TraceCheckSpWp]: Trace formula consists of 280 conjuncts, 7 conjuncts are in the unsatisfiable core [2024-11-14 04:57:46,400 INFO L278 TraceCheckSpWp]: Computing forward predicates... [2024-11-14 04:57:46,643 INFO L134 CoverageAnalysis]: Checked inductivity of 29 backedges. 20 proven. 9 refuted. 0 times theorem prover too weak. 0 trivial. 0 not checked. [2024-11-14 04:57:46,643 INFO L311 TraceCheckSpWp]: Computing backward predicates... [2024-11-14 04:57:46,944 INFO L134 CoverageAnalysis]: Checked inductivity of 29 backedges. 13 proven. 8 refuted. 0 times theorem prover too weak. 8 trivial. 0 not checked. [2024-11-14 04:57:46,944 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [853805662] provided 0 perfect and 2 imperfect interpolant sequences [2024-11-14 04:57:46,944 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [179559129] [2024-11-14 04:57:46,973 INFO L159 IcfgInterpreter]: Started Sifa with 48 locations of interest [2024-11-14 04:57:46,973 INFO L166 IcfgInterpreter]: Building call graph [2024-11-14 04:57:46,977 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2024-11-14 04:57:46,982 INFO L176 IcfgInterpreter]: Starting interpretation [2024-11-14 04:57:46,982 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2024-11-14 04:57:55,221 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 144 for LOIs [2024-11-14 04:57:55,329 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 174 for LOIs [2024-11-14 04:57:59,506 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 8 for LOIs [2024-11-14 04:57:59,540 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 21 for LOIs [2024-11-14 04:57:59,586 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 1 for LOIs [2024-11-14 04:57:59,590 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__base with input of size 13 for LOIs [2024-11-14 04:57:59,596 INFO L180 IcfgInterpreter]: Interpretation finished [2024-11-14 04:58:12,826 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '5590#(and (not (= ~pumpRunning~0 0)) (<= ~pumpRunning~0 2147483647) (not (= 2 ~waterLevel~0)) (<= 0 (+ ~waterLevel~0 2147483648)) (<= ~waterLevel~0 2147483647) (<= 0 (+ ~pumpRunning~0 2147483648)) (= ~switchedOnBeforeTS~0 0))' at error location [2024-11-14 04:58:12,826 WARN L311 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2024-11-14 04:58:12,826 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2024-11-14 04:58:12,827 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [6, 6, 6] total 11 [2024-11-14 04:58:12,827 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1939154376] [2024-11-14 04:58:12,827 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2024-11-14 04:58:12,827 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 11 states [2024-11-14 04:58:12,828 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:58:12,828 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 11 interpolants. [2024-11-14 04:58:12,829 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=177, Invalid=1629, Unknown=0, NotChecked=0, Total=1806 [2024-11-14 04:58:12,830 INFO L87 Difference]: Start difference. First operand 262 states and 302 transitions. Second operand has 11 states, 8 states have (on average 9.625) internal successors, (77), 9 states have internal predecessors, (77), 4 states have call successors, (18), 3 states have call predecessors, (18), 6 states have return successors, (21), 6 states have call predecessors, (21), 4 states have call successors, (21) [2024-11-14 04:58:13,797 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:58:13,798 INFO L93 Difference]: Finished difference Result 358 states and 418 transitions. [2024-11-14 04:58:13,798 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 22 states. [2024-11-14 04:58:13,799 INFO L78 Accepts]: Start accepts. Automaton has has 11 states, 8 states have (on average 9.625) internal successors, (77), 9 states have internal predecessors, (77), 4 states have call successors, (18), 3 states have call predecessors, (18), 6 states have return successors, (21), 6 states have call predecessors, (21), 4 states have call successors, (21) Word has length 74 [2024-11-14 04:58:13,799 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:58:13,803 INFO L225 Difference]: With dead ends: 358 [2024-11-14 04:58:13,804 INFO L226 Difference]: Without dead ends: 356 [2024-11-14 04:58:13,806 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 243 GetRequests, 184 SyntacticMatches, 4 SemanticMatches, 55 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 972 ImplicationChecksByTransitivity, 13.7s TimeCoverageRelationStatistics Valid=280, Invalid=2912, Unknown=0, NotChecked=0, Total=3192 [2024-11-14 04:58:13,807 INFO L432 NwaCegarLoop]: 142 mSDtfsCounter, 143 mSDsluCounter, 584 mSDsCounter, 0 mSdLazyCounter, 668 mSolverCounterSat, 55 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.4s Time, 0 mProtectedPredicate, 0 mProtectedAction, 149 SdHoareTripleChecker+Valid, 726 SdHoareTripleChecker+Invalid, 723 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 55 IncrementalHoareTripleChecker+Valid, 668 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.5s IncrementalHoareTripleChecker+Time [2024-11-14 04:58:13,808 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [149 Valid, 726 Invalid, 723 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [55 Valid, 668 Invalid, 0 Unknown, 0 Unchecked, 0.5s Time] [2024-11-14 04:58:13,809 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 356 states. [2024-11-14 04:58:13,853 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 356 to 298. [2024-11-14 04:58:13,854 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 298 states, 192 states have (on average 1.1666666666666667) internal successors, (224), 213 states have internal predecessors, (224), 53 states have call successors, (53), 45 states have call predecessors, (53), 52 states have return successors, (68), 54 states have call predecessors, (68), 53 states have call successors, (68) [2024-11-14 04:58:13,856 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 298 states to 298 states and 345 transitions. [2024-11-14 04:58:13,857 INFO L78 Accepts]: Start accepts. Automaton has 298 states and 345 transitions. Word has length 74 [2024-11-14 04:58:13,857 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:58:13,857 INFO L471 AbstractCegarLoop]: Abstraction has 298 states and 345 transitions. [2024-11-14 04:58:13,857 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 11 states, 8 states have (on average 9.625) internal successors, (77), 9 states have internal predecessors, (77), 4 states have call successors, (18), 3 states have call predecessors, (18), 6 states have return successors, (21), 6 states have call predecessors, (21), 4 states have call successors, (21) [2024-11-14 04:58:13,857 INFO L276 IsEmpty]: Start isEmpty. Operand 298 states and 345 transitions. [2024-11-14 04:58:13,859 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 94 [2024-11-14 04:58:13,859 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:58:13,859 INFO L215 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:58:13,878 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (2)] Ended with exit code 0 [2024-11-14 04:58:14,060 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable7,2 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-14 04:58:14,060 INFO L396 AbstractCegarLoop]: === Iteration 9 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:58:14,060 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:58:14,060 INFO L85 PathProgramCache]: Analyzing trace with hash 1709264277, now seen corresponding path program 1 times [2024-11-14 04:58:14,060 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:58:14,061 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [1523674511] [2024-11-14 04:58:14,061 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:58:14,061 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:58:14,089 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:58:14,194 INFO L134 CoverageAnalysis]: Checked inductivity of 70 backedges. 36 proven. 0 refuted. 0 times theorem prover too weak. 34 trivial. 0 not checked. [2024-11-14 04:58:14,194 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:58:14,194 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [1523674511] [2024-11-14 04:58:14,194 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [1523674511] provided 1 perfect and 0 imperfect interpolant sequences [2024-11-14 04:58:14,194 INFO L185 FreeRefinementEngine]: Found 1 perfect and 0 imperfect interpolant sequences. [2024-11-14 04:58:14,194 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [5] imperfect sequences [] total 5 [2024-11-14 04:58:14,195 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [300432390] [2024-11-14 04:58:14,195 INFO L85 oduleStraightlineAll]: Using 1 perfect interpolants to construct interpolant automaton [2024-11-14 04:58:14,195 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 5 states [2024-11-14 04:58:14,195 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:58:14,195 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 5 interpolants. [2024-11-14 04:58:14,196 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=7, Invalid=13, Unknown=0, NotChecked=0, Total=20 [2024-11-14 04:58:14,196 INFO L87 Difference]: Start difference. First operand 298 states and 345 transitions. Second operand has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (10), 4 states have call predecessors, (10), 4 states have call successors, (10) [2024-11-14 04:58:14,450 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:58:14,451 INFO L93 Difference]: Finished difference Result 768 states and 896 transitions. [2024-11-14 04:58:14,451 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 6 states. [2024-11-14 04:58:14,451 INFO L78 Accepts]: Start accepts. Automaton has has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (10), 4 states have call predecessors, (10), 4 states have call successors, (10) Word has length 93 [2024-11-14 04:58:14,452 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:58:14,456 INFO L225 Difference]: With dead ends: 768 [2024-11-14 04:58:14,456 INFO L226 Difference]: Without dead ends: 592 [2024-11-14 04:58:14,457 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 7 GetRequests, 2 SyntacticMatches, 0 SemanticMatches, 5 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 1 ImplicationChecksByTransitivity, 0.0s TimeCoverageRelationStatistics Valid=15, Invalid=27, Unknown=0, NotChecked=0, Total=42 [2024-11-14 04:58:14,459 INFO L432 NwaCegarLoop]: 106 mSDtfsCounter, 118 mSDsluCounter, 108 mSDsCounter, 0 mSdLazyCounter, 195 mSolverCounterSat, 3 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.1s Time, 0 mProtectedPredicate, 0 mProtectedAction, 118 SdHoareTripleChecker+Valid, 214 SdHoareTripleChecker+Invalid, 198 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 3 IncrementalHoareTripleChecker+Valid, 195 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 0.2s IncrementalHoareTripleChecker+Time [2024-11-14 04:58:14,459 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [118 Valid, 214 Invalid, 198 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [3 Valid, 195 Invalid, 0 Unknown, 0 Unchecked, 0.2s Time] [2024-11-14 04:58:14,461 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 592 states. [2024-11-14 04:58:14,537 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 592 to 590. [2024-11-14 04:58:14,538 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 590 states, 381 states have (on average 1.162729658792651) internal successors, (443), 420 states have internal predecessors, (443), 104 states have call successors, (104), 90 states have call predecessors, (104), 104 states have return successors, (134), 108 states have call predecessors, (134), 104 states have call successors, (134) [2024-11-14 04:58:14,544 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 590 states to 590 states and 681 transitions. [2024-11-14 04:58:14,547 INFO L78 Accepts]: Start accepts. Automaton has 590 states and 681 transitions. Word has length 93 [2024-11-14 04:58:14,548 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:58:14,548 INFO L471 AbstractCegarLoop]: Abstraction has 590 states and 681 transitions. [2024-11-14 04:58:14,548 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 5 states, 5 states have (on average 10.0) internal successors, (50), 5 states have internal predecessors, (50), 4 states have call successors, (10), 2 states have call predecessors, (10), 2 states have return successors, (10), 4 states have call predecessors, (10), 4 states have call successors, (10) [2024-11-14 04:58:14,548 INFO L276 IsEmpty]: Start isEmpty. Operand 590 states and 681 transitions. [2024-11-14 04:58:14,550 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 97 [2024-11-14 04:58:14,551 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:58:14,552 INFO L215 NwaCegarLoop]: trace histogram [4, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:58:14,552 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: SelfDestructingSolverStorable8 [2024-11-14 04:58:14,552 INFO L396 AbstractCegarLoop]: === Iteration 10 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:58:14,552 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:58:14,552 INFO L85 PathProgramCache]: Analyzing trace with hash 53788931, now seen corresponding path program 1 times [2024-11-14 04:58:14,553 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:58:14,553 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [283011432] [2024-11-14 04:58:14,553 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:58:14,553 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:58:14,575 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:58:14,832 INFO L134 CoverageAnalysis]: Checked inductivity of 70 backedges. 33 proven. 3 refuted. 0 times theorem prover too weak. 34 trivial. 0 not checked. [2024-11-14 04:58:14,832 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:58:14,832 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [283011432] [2024-11-14 04:58:14,832 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [283011432] provided 0 perfect and 1 imperfect interpolant sequences [2024-11-14 04:58:14,832 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [13997781] [2024-11-14 04:58:14,832 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:58:14,833 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-14 04:58:14,833 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 [2024-11-14 04:58:14,835 INFO L229 MonitoredProcess]: Starting monitored process 3 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2024-11-14 04:58:14,839 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Waiting until timeout for monitored process [2024-11-14 04:58:14,970 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:58:14,972 INFO L255 TraceCheckSpWp]: Trace formula consists of 343 conjuncts, 12 conjuncts are in the unsatisfiable core [2024-11-14 04:58:14,976 INFO L278 TraceCheckSpWp]: Computing forward predicates... [2024-11-14 04:58:15,226 INFO L134 CoverageAnalysis]: Checked inductivity of 70 backedges. 63 proven. 3 refuted. 0 times theorem prover too weak. 4 trivial. 0 not checked. [2024-11-14 04:58:15,226 INFO L311 TraceCheckSpWp]: Computing backward predicates... [2024-11-14 04:58:15,539 INFO L134 CoverageAnalysis]: Checked inductivity of 70 backedges. 45 proven. 3 refuted. 0 times theorem prover too weak. 22 trivial. 0 not checked. [2024-11-14 04:58:15,539 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [13997781] provided 0 perfect and 2 imperfect interpolant sequences [2024-11-14 04:58:15,539 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [50255928] [2024-11-14 04:58:15,542 INFO L159 IcfgInterpreter]: Started Sifa with 48 locations of interest [2024-11-14 04:58:15,542 INFO L166 IcfgInterpreter]: Building call graph [2024-11-14 04:58:15,543 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2024-11-14 04:58:15,543 INFO L176 IcfgInterpreter]: Starting interpretation [2024-11-14 04:58:15,543 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2024-11-14 04:58:17,770 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 172 for LOIs [2024-11-14 04:58:17,887 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 42 for LOIs [2024-11-14 04:58:18,105 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 41 for LOIs [2024-11-14 04:58:18,152 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 41 for LOIs [2024-11-14 04:58:18,179 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2024-11-14 04:58:18,188 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 3 for LOIs [2024-11-14 04:58:18,190 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 47 for LOIs [2024-11-14 04:58:18,197 INFO L180 IcfgInterpreter]: Interpretation finished [2024-11-14 04:58:25,584 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '9345#(and (<= ~methaneLevelCritical~0 1) (not (= ~pumpRunning~0 0)) (<= ~pumpRunning~0 1) (not (= 2 ~waterLevel~0)) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (<= |old(~pumpRunning~0)| 2147483647) (<= 0 (+ ~waterLevel~0 2147483648)) (<= 0 ~methaneLevelCritical~0) (<= ~waterLevel~0 2147483647) (<= 0 ~pumpRunning~0) (= ~switchedOnBeforeTS~0 0))' at error location [2024-11-14 04:58:25,584 WARN L311 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2024-11-14 04:58:25,584 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2024-11-14 04:58:25,584 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [7, 9, 9] total 20 [2024-11-14 04:58:25,584 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1373762955] [2024-11-14 04:58:25,585 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2024-11-14 04:58:25,585 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 20 states [2024-11-14 04:58:25,585 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:58:25,586 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 20 interpolants. [2024-11-14 04:58:25,587 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=273, Invalid=2379, Unknown=0, NotChecked=0, Total=2652 [2024-11-14 04:58:25,588 INFO L87 Difference]: Start difference. First operand 590 states and 681 transitions. Second operand has 20 states, 20 states have (on average 5.5) internal successors, (110), 20 states have internal predecessors, (110), 9 states have call successors, (24), 5 states have call predecessors, (24), 8 states have return successors, (25), 10 states have call predecessors, (25), 9 states have call successors, (25) [2024-11-14 04:58:27,207 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:58:27,207 INFO L93 Difference]: Finished difference Result 1716 states and 2176 transitions. [2024-11-14 04:58:27,208 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 30 states. [2024-11-14 04:58:27,208 INFO L78 Accepts]: Start accepts. Automaton has has 20 states, 20 states have (on average 5.5) internal successors, (110), 20 states have internal predecessors, (110), 9 states have call successors, (24), 5 states have call predecessors, (24), 8 states have return successors, (25), 10 states have call predecessors, (25), 9 states have call successors, (25) Word has length 96 [2024-11-14 04:58:27,208 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:58:27,218 INFO L225 Difference]: With dead ends: 1716 [2024-11-14 04:58:27,218 INFO L226 Difference]: Without dead ends: 1112 [2024-11-14 04:58:27,222 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 327 GetRequests, 247 SyntacticMatches, 5 SemanticMatches, 75 ConstructedPredicates, 0 IntricatePredicates, 0 DeprecatedPredicates, 2094 ImplicationChecksByTransitivity, 8.1s TimeCoverageRelationStatistics Valid=597, Invalid=5255, Unknown=0, NotChecked=0, Total=5852 [2024-11-14 04:58:27,223 INFO L432 NwaCegarLoop]: 58 mSDtfsCounter, 338 mSDsluCounter, 446 mSDsCounter, 0 mSdLazyCounter, 1246 mSolverCounterSat, 257 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 0.8s Time, 0 mProtectedPredicate, 0 mProtectedAction, 341 SdHoareTripleChecker+Valid, 504 SdHoareTripleChecker+Invalid, 1503 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 257 IncrementalHoareTripleChecker+Valid, 1246 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.0s IncrementalHoareTripleChecker+Time [2024-11-14 04:58:27,223 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [341 Valid, 504 Invalid, 1503 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [257 Valid, 1246 Invalid, 0 Unknown, 0 Unchecked, 1.0s Time] [2024-11-14 04:58:27,225 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 1112 states. [2024-11-14 04:58:27,364 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 1112 to 730. [2024-11-14 04:58:27,365 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 730 states, 473 states have (on average 1.1268498942917549) internal successors, (533), 516 states have internal predecessors, (533), 124 states have call successors, (124), 112 states have call predecessors, (124), 132 states have return successors, (164), 134 states have call predecessors, (164), 124 states have call successors, (164) [2024-11-14 04:58:27,372 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 730 states to 730 states and 821 transitions. [2024-11-14 04:58:27,374 INFO L78 Accepts]: Start accepts. Automaton has 730 states and 821 transitions. Word has length 96 [2024-11-14 04:58:27,374 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:58:27,374 INFO L471 AbstractCegarLoop]: Abstraction has 730 states and 821 transitions. [2024-11-14 04:58:27,375 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 20 states, 20 states have (on average 5.5) internal successors, (110), 20 states have internal predecessors, (110), 9 states have call successors, (24), 5 states have call predecessors, (24), 8 states have return successors, (25), 10 states have call predecessors, (25), 9 states have call successors, (25) [2024-11-14 04:58:27,377 INFO L276 IsEmpty]: Start isEmpty. Operand 730 states and 821 transitions. [2024-11-14 04:58:27,379 INFO L282 IsEmpty]: Finished isEmpty. Found accepting run of length 102 [2024-11-14 04:58:27,383 INFO L207 NwaCegarLoop]: Found error trace [2024-11-14 04:58:27,383 INFO L215 NwaCegarLoop]: trace histogram [5, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 3, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 2, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:58:27,411 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (3)] Ended with exit code 0 [2024-11-14 04:58:27,584 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 3 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable9 [2024-11-14 04:58:27,584 INFO L396 AbstractCegarLoop]: === Iteration 11 === Targeting timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION === [timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION] === [2024-11-14 04:58:27,584 INFO L157 PredicateUnifier]: Initialized classic predicate unifier [2024-11-14 04:58:27,585 INFO L85 PathProgramCache]: Analyzing trace with hash 63169998, now seen corresponding path program 1 times [2024-11-14 04:58:27,585 INFO L118 FreeRefinementEngine]: Executing refinement strategy SIFA_TAIPAN [2024-11-14 04:58:27,585 INFO L334 FreeRefinementEngine]: Using trace check IpTcStrategyModuleSmtInterpolCraig [936619524] [2024-11-14 04:58:27,585 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:58:27,585 INFO L127 SolverBuilder]: Constructing new instance of SMTInterpol with explicit timeout -1 ms and remaining time -1 ms [2024-11-14 04:58:27,617 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:58:28,767 INFO L134 CoverageAnalysis]: Checked inductivity of 81 backedges. 14 proven. 42 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2024-11-14 04:58:28,768 INFO L136 FreeRefinementEngine]: Strategy SIFA_TAIPAN found an infeasible trace [2024-11-14 04:58:28,768 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSmtInterpolCraig [936619524] [2024-11-14 04:58:28,768 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleSmtInterpolCraig [936619524] provided 0 perfect and 1 imperfect interpolant sequences [2024-11-14 04:58:28,768 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleZ3 [411204688] [2024-11-14 04:58:28,768 INFO L95 rtionOrderModulation]: Keeping assertion order NOT_INCREMENTALLY [2024-11-14 04:58:28,768 INFO L173 SolverBuilder]: Constructing external solver with command: z3 -smt2 -in SMTLIB2_COMPLIANT=true [2024-11-14 04:58:28,768 INFO L189 MonitoredProcess]: No working directory specified, using /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 [2024-11-14 04:58:28,771 INFO L229 MonitoredProcess]: Starting monitored process 4 with /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (exit command is (exit), workingDir is null) [2024-11-14 04:58:28,773 INFO L327 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Waiting until timeout for monitored process [2024-11-14 04:58:28,906 INFO L136 AnnotateAndAsserter]: Conjunction of SSA is unsat [2024-11-14 04:58:28,908 INFO L255 TraceCheckSpWp]: Trace formula consists of 355 conjuncts, 18 conjuncts are in the unsatisfiable core [2024-11-14 04:58:28,915 INFO L278 TraceCheckSpWp]: Computing forward predicates... [2024-11-14 04:58:29,298 INFO L134 CoverageAnalysis]: Checked inductivity of 81 backedges. 60 proven. 15 refuted. 0 times theorem prover too weak. 6 trivial. 0 not checked. [2024-11-14 04:58:29,299 INFO L311 TraceCheckSpWp]: Computing backward predicates... [2024-11-14 04:58:29,801 INFO L134 CoverageAnalysis]: Checked inductivity of 81 backedges. 51 proven. 5 refuted. 0 times theorem prover too weak. 25 trivial. 0 not checked. [2024-11-14 04:58:29,801 INFO L158 FreeRefinementEngine]: IpTcStrategyModuleZ3 [411204688] provided 0 perfect and 2 imperfect interpolant sequences [2024-11-14 04:58:29,802 INFO L334 FreeRefinementEngine]: Using interpolant generator IpTcStrategyModuleSifa [991532328] [2024-11-14 04:58:29,804 INFO L159 IcfgInterpreter]: Started Sifa with 48 locations of interest [2024-11-14 04:58:29,806 INFO L166 IcfgInterpreter]: Building call graph [2024-11-14 04:58:29,806 INFO L171 IcfgInterpreter]: Initial procedures are [ULTIMATE.start] [2024-11-14 04:58:29,807 INFO L176 IcfgInterpreter]: Starting interpretation [2024-11-14 04:58:29,807 INFO L197 IcfgInterpreter]: Interpreting procedure ULTIMATE.start with input of size 1 for LOIs [2024-11-14 04:58:31,652 INFO L197 IcfgInterpreter]: Interpreting procedure waterRise with input of size 151 for LOIs [2024-11-14 04:58:31,721 INFO L197 IcfgInterpreter]: Interpreting procedure timeShift with input of size 42 for LOIs [2024-11-14 04:58:31,944 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__lowWaterSensor with input of size 41 for LOIs [2024-11-14 04:58:32,016 INFO L197 IcfgInterpreter]: Interpreting procedure processEnvironment__wrappee__highWaterSensor with input of size 41 for LOIs [2024-11-14 04:58:32,058 INFO L197 IcfgInterpreter]: Interpreting procedure isPumpRunning with input of size 53 for LOIs [2024-11-14 04:58:32,072 INFO L197 IcfgInterpreter]: Interpreting procedure changeMethaneLevel with input of size 17 for LOIs [2024-11-14 04:58:32,076 INFO L197 IcfgInterpreter]: Interpreting procedure deactivatePump with input of size 47 for LOIs [2024-11-14 04:58:32,086 INFO L180 IcfgInterpreter]: Interpretation finished [2024-11-14 04:58:37,848 INFO L133 SifaRunner]: Sifa could not show that error location is unreachable, found '13799#(and (<= ~methaneLevelCritical~0 1) (not (= ~pumpRunning~0 0)) (<= ~pumpRunning~0 1) (not (= 2 ~waterLevel~0)) (<= 0 (+ 2147483648 |old(~pumpRunning~0)|)) (<= |old(~pumpRunning~0)| 2147483647) (<= 0 (+ ~waterLevel~0 2147483648)) (<= 0 ~methaneLevelCritical~0) (<= ~waterLevel~0 2147483647) (<= 0 ~pumpRunning~0) (= ~switchedOnBeforeTS~0 0))' at error location [2024-11-14 04:58:37,848 WARN L311 FreeRefinementEngine]: Interpolation failed due to KNOWN_IGNORE: ALGORITHM_FAILED [2024-11-14 04:58:37,848 INFO L185 FreeRefinementEngine]: Found 0 perfect and 3 imperfect interpolant sequences. [2024-11-14 04:58:37,849 INFO L198 FreeRefinementEngine]: Number of different interpolants: perfect sequences [] imperfect sequences [18, 11, 11] total 30 [2024-11-14 04:58:37,849 INFO L121 tionRefinementEngine]: Using interpolant automaton builder IpAbStrategyModuleStraightlineAll [1172028616] [2024-11-14 04:58:37,849 INFO L85 oduleStraightlineAll]: Using 3 imperfect interpolants to construct interpolant automaton [2024-11-14 04:58:37,849 INFO L548 AbstractCegarLoop]: INTERPOLANT automaton has 30 states [2024-11-14 04:58:37,849 INFO L100 FreeRefinementEngine]: Using predicate unifier PredicateUnifier provided by strategy SIFA_TAIPAN [2024-11-14 04:58:37,850 INFO L143 InterpolantAutomaton]: Constructing interpolant automaton starting with 30 interpolants. [2024-11-14 04:58:37,852 INFO L145 InterpolantAutomaton]: CoverageRelationStatistics Valid=395, Invalid=3637, Unknown=0, NotChecked=0, Total=4032 [2024-11-14 04:58:37,852 INFO L87 Difference]: Start difference. First operand 730 states and 821 transitions. Second operand has 30 states, 28 states have (on average 5.035714285714286) internal successors, (141), 29 states have internal predecessors, (141), 17 states have call successors, (32), 8 states have call predecessors, (32), 12 states have return successors, (32), 16 states have call predecessors, (32), 16 states have call successors, (32) [2024-11-14 04:58:41,897 INFO L144 Difference]: Subtrahend was deterministic. Have not used determinization. [2024-11-14 04:58:41,897 INFO L93 Difference]: Finished difference Result 2046 states and 2403 transitions. [2024-11-14 04:58:41,898 INFO L141 InterpolantAutomaton]: Switched to read-only mode: deterministic interpolant automaton has 66 states. [2024-11-14 04:58:41,899 INFO L78 Accepts]: Start accepts. Automaton has has 30 states, 28 states have (on average 5.035714285714286) internal successors, (141), 29 states have internal predecessors, (141), 17 states have call successors, (32), 8 states have call predecessors, (32), 12 states have return successors, (32), 16 states have call predecessors, (32), 16 states have call successors, (32) Word has length 101 [2024-11-14 04:58:41,900 INFO L84 Accepts]: Finished accepts. some prefix is accepted. [2024-11-14 04:58:41,902 INFO L225 Difference]: With dead ends: 2046 [2024-11-14 04:58:41,902 INFO L226 Difference]: Without dead ends: 0 [2024-11-14 04:58:41,913 INFO L431 NwaCegarLoop]: 0 DeclaredPredicates, 404 GetRequests, 274 SyntacticMatches, 11 SemanticMatches, 119 ConstructedPredicates, 0 IntricatePredicates, 1 DeprecatedPredicates, 6183 ImplicationChecksByTransitivity, 8.2s TimeCoverageRelationStatistics Valid=1713, Invalid=12807, Unknown=0, NotChecked=0, Total=14520 [2024-11-14 04:58:41,914 INFO L432 NwaCegarLoop]: 98 mSDtfsCounter, 1054 mSDsluCounter, 716 mSDsCounter, 0 mSdLazyCounter, 1831 mSolverCounterSat, 773 mSolverCounterUnsat, 0 mSolverCounterUnknown, 0 mSolverCounterNotChecked, 1.5s Time, 0 mProtectedPredicate, 0 mProtectedAction, 1060 SdHoareTripleChecker+Valid, 814 SdHoareTripleChecker+Invalid, 2604 SdHoareTripleChecker+Unknown, 0 SdHoareTripleChecker+Unchecked, 0.0s SdHoareTripleChecker+Time, 773 IncrementalHoareTripleChecker+Valid, 1831 IncrementalHoareTripleChecker+Invalid, 0 IncrementalHoareTripleChecker+Unknown, 0 IncrementalHoareTripleChecker+Unchecked, 1.8s IncrementalHoareTripleChecker+Time [2024-11-14 04:58:41,914 INFO L433 NwaCegarLoop]: SdHoareTripleChecker [1060 Valid, 814 Invalid, 2604 Unknown, 0 Unchecked, 0.0s Time], IncrementalHoareTripleChecker [773 Valid, 1831 Invalid, 0 Unknown, 0 Unchecked, 1.8s Time] [2024-11-14 04:58:41,915 INFO L82 GeneralOperation]: Start minimizeSevpa. Operand 0 states. [2024-11-14 04:58:41,915 INFO L88 GeneralOperation]: Finished minimizeSevpa. Reduced states from 0 to 0. [2024-11-14 04:58:41,915 INFO L82 GeneralOperation]: Start removeUnreachable. Operand has 0 states, 0 states have (on average 0.0) internal successors, (0), 0 states have internal predecessors, (0), 0 states have call successors, (0), 0 states have call predecessors, (0), 0 states have return successors, (0), 0 states have call predecessors, (0), 0 states have call successors, (0) [2024-11-14 04:58:41,915 INFO L88 GeneralOperation]: Finished removeUnreachable. Reduced from 0 states to 0 states and 0 transitions. [2024-11-14 04:58:41,917 INFO L78 Accepts]: Start accepts. Automaton has 0 states and 0 transitions. Word has length 101 [2024-11-14 04:58:41,917 INFO L84 Accepts]: Finished accepts. word is rejected. [2024-11-14 04:58:41,917 INFO L471 AbstractCegarLoop]: Abstraction has 0 states and 0 transitions. [2024-11-14 04:58:41,918 INFO L472 AbstractCegarLoop]: INTERPOLANT automaton has has 30 states, 28 states have (on average 5.035714285714286) internal successors, (141), 29 states have internal predecessors, (141), 17 states have call successors, (32), 8 states have call predecessors, (32), 12 states have return successors, (32), 16 states have call predecessors, (32), 16 states have call successors, (32) [2024-11-14 04:58:41,918 INFO L276 IsEmpty]: Start isEmpty. Operand 0 states and 0 transitions. [2024-11-14 04:58:41,918 INFO L282 IsEmpty]: Finished isEmpty. No accepting run. [2024-11-14 04:58:41,921 INFO L782 garLoopResultBuilder]: Registering result SAFE for location timeShiftErr0ASSERT_VIOLATIONERROR_FUNCTION (0 of 1 remaining) [2024-11-14 04:58:41,949 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true (4)] Ended with exit code 0 [2024-11-14 04:58:42,126 WARN L453 AbstractCegarLoop]: Destroyed unattended storables created during the last iteration: 4 /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 -smt2 -in SMTLIB2_COMPLIANT=true,SelfDestructingSolverStorable10 [2024-11-14 04:58:42,130 INFO L407 BasicCegarLoop]: Path program histogram: [1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1] [2024-11-14 04:58:42,133 INFO L343 DoubleDeckerVisitor]: Before removal of dead ends 0 states and 0 transitions. [2024-11-14 04:59:00,403 INFO L173 ceAbstractionStarter]: Computing trace abstraction results [2024-11-14 04:59:00,434 WARN L162 FloydHoareUtils]: Requires clause for deactivatePump contained old-variable. Original clause: (and (<= ~waterLevel~0 2) (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (<= 1 |old(~pumpRunning~0)|) (not (= 0 ~systemActive~0))) Eliminated clause: (and (<= ~waterLevel~0 2) (<= 1 ~switchedOnBeforeTS~0) (= ~pumpRunning~0 ~switchedOnBeforeTS~0) (not (= 0 ~systemActive~0))) [2024-11-14 04:59:00,457 WARN L162 FloydHoareUtils]: Requires clause for changeMethaneLevel contained old-variable. Original clause: (let ((.cse0 (= |old(~methaneLevelCritical~0)| 0)) (.cse1 (= ~methaneLevelCritical~0 0))) (and (or .cse0 (not .cse1)) (let ((.cse5 (= 2 ~waterLevel~0)) (.cse2 (= ~pumpRunning~0 0)) (.cse4 (<= 1 ~pumpRunning~0)) (.cse6 (<= ~waterLevel~0 2)) (.cse7 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse3 (not (= 0 ~systemActive~0)))) (or (and .cse2 (= ~waterLevel~0 1) .cse3) (and .cse4 .cse5 .cse3) (and .cse2 .cse5 .cse3) (and .cse2 .cse6 .cse7 .cse3) (and .cse2 .cse6 (<= 1 ~switchedOnBeforeTS~0) .cse3) (and .cse4 .cse6 .cse7 .cse3))) (or (not .cse0) .cse1))) Eliminated clause: (and (let ((.cse3 (= 2 ~waterLevel~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse2 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 2)) (.cse1 (not (= 0 ~systemActive~0)))) (or (and .cse0 (= ~waterLevel~0 1) .cse1) (and .cse2 .cse3 .cse1) (and .cse0 .cse3 .cse1) (and .cse0 .cse4 (= ~switchedOnBeforeTS~0 0) .cse1) (and .cse0 .cse4 (<= 1 ~switchedOnBeforeTS~0) .cse1) (and .cse2 .cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse1))) (exists ((|old(~methaneLevelCritical~0)| Int)) (let ((.cse5 (= |old(~methaneLevelCritical~0)| 0)) (.cse6 (= ~methaneLevelCritical~0 0))) (and (or .cse5 (not .cse6)) (or (not .cse5) .cse6))))) [2024-11-14 04:59:00,467 WARN L976 BoogieBacktranslator]: Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression [2024-11-14 04:59:00,484 WARN L162 FloydHoareUtils]: Requires clause for timeShift contained old-variable. Original clause: (let ((.cse4 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse4)) (.cse1 (= ~pumpRunning~0 0)) (.cse3 (= |old(~waterLevel~0)| 1)) (.cse6 (= |old(~waterLevel~0)| 2)) (.cse9 (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (.cse10 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (< |old(~switchedOnBeforeTS~0)| 1) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 (not .cse3) (and .cse1 (= ~waterLevel~0 1))) (let ((.cse8 (<= 1 |old(~pumpRunning~0)|)) (.cse7 (<= |old(~waterLevel~0)| 2)) (.cse5 (not (= 0 ~systemActive~0)))) (or (and .cse4 .cse5 .cse6) (and .cse4 (<= 1 |old(~switchedOnBeforeTS~0)|) .cse7 .cse5) (and .cse8 .cse5 .cse6) (and .cse9 .cse7 .cse8 .cse5) (and .cse3 .cse4 .cse5) (and .cse4 .cse9 .cse7 .cse5))) (or (and .cse10 (= 2 ~waterLevel~0)) (not .cse6)) (or (not .cse9) (and .cse10 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)))))) Eliminated clause: (exists ((|old(~pumpRunning~0)| Int) (|old(~switchedOnBeforeTS~0)| Int) (|old(~waterLevel~0)| Int)) (let ((.cse6 (= |old(~pumpRunning~0)| 0))) (let ((.cse0 (not .cse6)) (.cse1 (= ~pumpRunning~0 0)) (.cse5 (= |old(~waterLevel~0)| 2)) (.cse3 (= |old(~waterLevel~0)| 1)) (.cse10 (= |old(~switchedOnBeforeTS~0)| |old(~pumpRunning~0)|)) (.cse4 (= ~pumpRunning~0 |old(~pumpRunning~0)|)) (.cse2 (= |old(~waterLevel~0)| ~waterLevel~0))) (and (or .cse0 (< |old(~switchedOnBeforeTS~0)| 1) (and .cse1 .cse2 (<= 1 ~switchedOnBeforeTS~0))) (or .cse0 (not .cse3) (and .cse1 (= ~waterLevel~0 1))) (or (and .cse4 (= 2 ~waterLevel~0)) (not .cse5)) (let ((.cse9 (<= 1 |old(~pumpRunning~0)|)) (.cse8 (<= |old(~waterLevel~0)| 2)) (.cse7 (not (= 0 ~systemActive~0)))) (or (and .cse6 .cse7 .cse5) (and .cse6 (<= 1 |old(~switchedOnBeforeTS~0)|) .cse8 .cse7) (and .cse9 .cse7 .cse5) (and .cse10 .cse8 .cse9 .cse7) (and .cse3 .cse6 .cse7) (and .cse6 .cse8 .cse7 (= |old(~switchedOnBeforeTS~0)| 0)))) (or (not .cse10) (and .cse4 .cse2 (= ~pumpRunning~0 ~switchedOnBeforeTS~0))))))) [2024-11-14 04:59:00,496 WARN L976 BoogieBacktranslator]: Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression [2024-11-14 04:59:00,503 WARN L162 FloydHoareUtils]: Requires clause for processEnvironment__wrappee__highWaterSensor contained old-variable. Original clause: (let ((.cse0 (= |old(~pumpRunning~0)| 0))) (and (or (not .cse0) (= ~pumpRunning~0 0)) (let ((.cse1 (<= ~waterLevel~0 2)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse1 (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (<= 1 |old(~pumpRunning~0)|) .cse2))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) Eliminated clause: (and (exists ((|old(~pumpRunning~0)| Int)) (let ((.cse0 (= |old(~pumpRunning~0)| 0))) (and (or (not .cse0) (= ~pumpRunning~0 0)) (let ((.cse1 (<= ~waterLevel~0 2)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse1 (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (<= 1 |old(~pumpRunning~0)|) .cse2)))))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2024-11-14 04:59:00,507 WARN L976 BoogieBacktranslator]: Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression [2024-11-14 04:59:00,515 WARN L162 FloydHoareUtils]: Requires clause for waterRise contained old-variable. Original clause: (and (let ((.cse1 (= |old(~waterLevel~0)| 2)) (.cse3 (<= 1 ~pumpRunning~0)) (.cse0 (= ~pumpRunning~0 0)) (.cse4 (<= |old(~waterLevel~0)| 2)) (.cse5 (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and (or (and .cse0 .cse1) (and .cse0 (= |old(~waterLevel~0)| 1))) .cse2) (and .cse3 .cse2 .cse1) (and .cse0 (<= 1 ~switchedOnBeforeTS~0) .cse4 .cse2) (and .cse3 .cse4 .cse5 .cse2) (and .cse0 .cse4 .cse5 .cse2))) (= |old(~waterLevel~0)| ~waterLevel~0)) Eliminated clause: (let ((.cse0 (<= 1 ~pumpRunning~0)) (.cse4 (<= ~waterLevel~0 2)) (.cse1 (= 2 ~waterLevel~0)) (.cse3 (= ~pumpRunning~0 0)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse3 .cse4 (= ~switchedOnBeforeTS~0 0) .cse2) (and .cse3 .cse4 (<= 1 ~switchedOnBeforeTS~0) .cse2) (and .cse0 .cse4 (= ~pumpRunning~0 ~switchedOnBeforeTS~0) .cse2) (and (or (and .cse3 .cse1) (and .cse3 (= ~waterLevel~0 1))) .cse2))) [2024-11-14 04:59:00,558 WARN L162 FloydHoareUtils]: Requires clause for processEnvironment__wrappee__lowWaterSensor contained old-variable. Original clause: (let ((.cse0 (= |old(~pumpRunning~0)| 0))) (and (or (not .cse0) (= ~pumpRunning~0 0)) (let ((.cse1 (<= ~waterLevel~0 2)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse1 (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (<= 1 |old(~pumpRunning~0)|) .cse2))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0))) Eliminated clause: (and (exists ((|old(~pumpRunning~0)| Int)) (let ((.cse0 (= |old(~pumpRunning~0)| 0))) (and (or (not .cse0) (= ~pumpRunning~0 0)) (let ((.cse1 (<= ~waterLevel~0 2)) (.cse2 (not (= 0 ~systemActive~0)))) (or (and .cse0 .cse1 .cse2) (and .cse1 (= ~switchedOnBeforeTS~0 |old(~pumpRunning~0)|) (<= 1 |old(~pumpRunning~0)|) .cse2)))))) (= ~pumpRunning~0 ~switchedOnBeforeTS~0)) [2024-11-14 04:59:00,562 WARN L976 BoogieBacktranslator]: Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression [2024-11-14 04:59:00,575 INFO L201 PluginConnector]: Adding new model de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction CFG 14.11 04:59:00 BoogieIcfgContainer [2024-11-14 04:59:00,575 INFO L131 PluginConnector]: ------------------------ END TraceAbstraction---------------------------- [2024-11-14 04:59:00,576 INFO L112 PluginConnector]: ------------------------Witness Printer---------------------------- [2024-11-14 04:59:00,576 INFO L270 PluginConnector]: Initializing Witness Printer... [2024-11-14 04:59:00,576 INFO L274 PluginConnector]: Witness Printer initialized [2024-11-14 04:59:00,577 INFO L184 PluginConnector]: Executing the observer RCFGCatcher from plugin Witness Printer for "de.uni_freiburg.informatik.ultimate.plugins.generator.rcfgbuilder CFG 14.11 04:57:41" (3/4) ... [2024-11-14 04:59:00,580 INFO L142 WitnessPrinter]: Generating witness for correct program [2024-11-14 04:59:00,583 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure deactivatePump [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__base [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure changeMethaneLevel [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure timeShift [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure cleanup [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__highWaterSensor [2024-11-14 04:59:00,584 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure waterRise [2024-11-14 04:59:00,585 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure processEnvironment__wrappee__lowWaterSensor [2024-11-14 04:59:00,585 INFO L361 RCFGBacktranslator]: Ignoring RootEdge to procedure isPumpRunning [2024-11-14 04:59:00,592 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 50 nodes and edges [2024-11-14 04:59:00,593 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 12 nodes and edges [2024-11-14 04:59:00,593 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 5 nodes and edges [2024-11-14 04:59:00,594 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2024-11-14 04:59:00,594 INFO L925 BoogieBacktranslator]: Reduced CFG by removing 1 nodes and edges [2024-11-14 04:59:00,727 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/witness.graphml [2024-11-14 04:59:00,727 INFO L149 WitnessManager]: Wrote witness to /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/witness.yml [2024-11-14 04:59:00,727 INFO L131 PluginConnector]: ------------------------ END Witness Printer---------------------------- [2024-11-14 04:59:00,728 INFO L158 Benchmark]: Toolchain (without parser) took 80610.42ms. Allocated memory was 142.6MB in the beginning and 1.5GB in the end (delta: 1.4GB). Free memory was 118.5MB in the beginning and 1.5GB in the end (delta: -1.3GB). Peak memory consumption was 32.3MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,729 INFO L158 Benchmark]: CDTParser took 0.50ms. Allocated memory is still 142.6MB. Free memory is still 80.3MB. There was no memory consumed. Max. memory is 16.1GB. [2024-11-14 04:59:00,729 INFO L158 Benchmark]: CACSL2BoogieTranslator took 565.04ms. Allocated memory is still 142.6MB. Free memory was 118.3MB in the beginning and 99.4MB in the end (delta: 18.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,729 INFO L158 Benchmark]: Boogie Procedure Inliner took 61.44ms. Allocated memory is still 142.6MB. Free memory was 99.2MB in the beginning and 97.4MB in the end (delta: 1.8MB). There was no memory consumed. Max. memory is 16.1GB. [2024-11-14 04:59:00,730 INFO L158 Benchmark]: Boogie Preprocessor took 44.02ms. Allocated memory is still 142.6MB. Free memory was 97.4MB in the beginning and 96.0MB in the end (delta: 1.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,730 INFO L158 Benchmark]: RCFGBuilder took 855.03ms. Allocated memory is still 142.6MB. Free memory was 96.0MB in the beginning and 66.2MB in the end (delta: 29.7MB). Peak memory consumption was 25.2MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,731 INFO L158 Benchmark]: TraceAbstraction took 78923.57ms. Allocated memory was 142.6MB in the beginning and 1.5GB in the end (delta: 1.4GB). Free memory was 65.8MB in the beginning and 1.5GB in the end (delta: -1.4GB). Peak memory consumption was 873.4MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,731 INFO L158 Benchmark]: Witness Printer took 151.64ms. Allocated memory is still 1.5GB. Free memory was 1.5GB in the beginning and 1.5GB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. [2024-11-14 04:59:00,734 INFO L338 ainManager$Toolchain]: ####################### End [Toolchain 1] ####################### --- Results --- * Results from de.uni_freiburg.informatik.ultimate.core: - StatisticsResult: Toolchain Benchmarks Benchmark results are: * CDTParser took 0.50ms. Allocated memory is still 142.6MB. Free memory is still 80.3MB. There was no memory consumed. Max. memory is 16.1GB. * CACSL2BoogieTranslator took 565.04ms. Allocated memory is still 142.6MB. Free memory was 118.3MB in the beginning and 99.4MB in the end (delta: 18.9MB). Peak memory consumption was 16.8MB. Max. memory is 16.1GB. * Boogie Procedure Inliner took 61.44ms. Allocated memory is still 142.6MB. Free memory was 99.2MB in the beginning and 97.4MB in the end (delta: 1.8MB). There was no memory consumed. Max. memory is 16.1GB. * Boogie Preprocessor took 44.02ms. Allocated memory is still 142.6MB. Free memory was 97.4MB in the beginning and 96.0MB in the end (delta: 1.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * RCFGBuilder took 855.03ms. Allocated memory is still 142.6MB. Free memory was 96.0MB in the beginning and 66.2MB in the end (delta: 29.7MB). Peak memory consumption was 25.2MB. Max. memory is 16.1GB. * TraceAbstraction took 78923.57ms. Allocated memory was 142.6MB in the beginning and 1.5GB in the end (delta: 1.4GB). Free memory was 65.8MB in the beginning and 1.5GB in the end (delta: -1.4GB). Peak memory consumption was 873.4MB. Max. memory is 16.1GB. * Witness Printer took 151.64ms. Allocated memory is still 1.5GB. Free memory was 1.5GB in the beginning and 1.5GB in the end (delta: 8.4MB). Peak memory consumption was 8.4MB. Max. memory is 16.1GB. * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.cacsl2boogietranslator: - GenericResultAtLocation [Line: 49]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Specification5_spec.i","") [49] - GenericResultAtLocation [Line: 101]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Environment.i","") [101] - GenericResultAtLocation [Line: 211]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"wsllib_check.i","") [211] - GenericResultAtLocation [Line: 220]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"Test.i","") [220] - GenericResultAtLocation [Line: 323]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"MinePump.i","") [323] - GenericResultAtLocation [Line: 560]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"scenario.i","") [560] - GenericResultAtLocation [Line: 627]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"featureselect.i","") [627] - GenericResultAtLocation [Line: 662]: Unsoundness Warning Ignoring preprocessor pragma C: #pragma merger(0,"libacc.i","") [662] - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression - GenericResult: Unfinished Backtranslation Unfinished Backtranslation: Expression type not yet supported in backtranslation: QuantifierExpression * Results from de.uni_freiburg.informatik.ultimate.plugins.generator.traceabstraction: - StatisticsResult: ErrorAutomatonStatistics NumberErrorTraces: 0, NumberStatementsAllTraces: 0, NumberRelevantStatements: 0, 0.0s ErrorAutomatonConstructionTimeTotal, 0.0s FaulLocalizationTime, NumberStatementsFirstTrace: -1, TraceLengthAvg: 0, 0.0s ErrorAutomatonConstructionTimeAvg, 0.0s ErrorAutomatonDifferenceTimeAvg, 0.0s ErrorAutomatonDifferenceTimeTotal, NumberOfNoEnhancement: 0, NumberOfFiniteEnhancement: 0, NumberOfInfiniteEnhancement: 0 - PositiveResult [Line: 216]: a call to reach_error is unreachable For all program executions holds that a call to reach_error is unreachable at this location - StatisticsResult: Ultimate Automizer benchmark data CFG has 10 procedures, 69 locations, 1 error locations. Started 1 CEGAR loops. OverallTime: 60.4s, OverallIterations: 11, TraceHistogramMax: 5, PathProgramHistogramMax: 1, EmptinessCheckTime: 0.0s, AutomataDifference: 9.0s, DeadEndRemovalTime: 0.0s, HoareAnnotationTime: 0.0s, InitialAbstractionConstructionTime: 0.0s, HoareTripleCheckerStatistics: 0 mSolverCounterUnknown, 2249 SdHoareTripleChecker+Valid, 4.7s IncrementalHoareTripleChecker+Time, 0 mSdLazyCounter, 2219 mSDsluCounter, 3477 SdHoareTripleChecker+Invalid, 3.9s Time, 0 mProtectedAction, 0 SdHoareTripleChecker+Unchecked, 0 IncrementalHoareTripleChecker+Unchecked, 2586 mSDsCounter, 1274 IncrementalHoareTripleChecker+Valid, 0 mProtectedPredicate, 4700 IncrementalHoareTripleChecker+Invalid, 5974 SdHoareTripleChecker+Unknown, 0 mSolverCounterNotChecked, 1274 mSolverCounterUnsat, 891 mSDtfsCounter, 4700 mSolverCounterSat, 0.1s SdHoareTripleChecker+Time, 0 IncrementalHoareTripleChecker+Unknown, PredicateUnifierStatistics: 0 DeclaredPredicates, 1040 GetRequests, 733 SyntacticMatches, 20 SemanticMatches, 287 ConstructedPredicates, 0 IntricatePredicates, 1 DeprecatedPredicates, 9276 ImplicationChecksByTransitivity, 30.3s Time, 0.0s BasicInterpolantAutomatonTime, BiggestAbstraction: size=730occurred in iteration=10, InterpolantAutomatonStates: 165, traceCheckStatistics: No data available, InterpolantConsolidationStatistics: No data available, PathInvariantsStatistics: No data available, 0/0 InterpolantCoveringCapability, TotalInterpolationStatistics: No data available, 0.0s DumpTime, AutomataMinimizationStatistics: 0.6s AutomataMinimizationTime, 11 MinimizatonAttempts, 477 StatesRemovedByMinimization, 6 NontrivialMinimizations, HoareAnnotationStatistics: No data available, RefinementEngineStatistics: TRACE_CHECK: 0.1s SsaConstructionTime, 0.4s SatisfiabilityAnalysisTime, 5.2s InterpolantComputationTime, 920 NumberOfCodeBlocks, 920 NumberOfCodeBlocksAsserted, 14 NumberOfCheckSat, 1174 ConstructedInterpolants, 0 QuantifiedInterpolants, 2944 SizeOfPredicates, 9 NumberOfNonLiveVariables, 978 ConjunctsInSsa, 37 ConjunctsInUnsatCore, 17 InterpolantComputations, 8 PerfectInterpolantSequences, 581/670 InterpolantCoveringCapability, INVARIANT_SYNTHESIS: No data available, INTERPOLANT_CONSOLIDATION: No data available, ABSTRACT_INTERPRETATION: No data available, PDR: No data available, ACCELERATED_INTERPOLATION: No data available, SIFA: No data available, ReuseStatistics: No data available - AllSpecificationsHoldResult: All specifications hold 1 specifications checked. All of them hold - InvariantResult [Line: 571]: Loop Invariant Derived loop invariant: (((((((((((((pumpRunning == 0) && (2 == waterLevel)) && (methaneLevelCritical == 0)) && (splverifierCounter == 0)) && (switchedOnBeforeTS == 0)) && (0 != systemActive)) || ((((((pumpRunning == 0) && (waterLevel <= 1)) && (methaneLevelCritical != 0)) && (splverifierCounter == 0)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || (((((1 <= pumpRunning) && (waterLevel <= 1)) && (splverifierCounter == 0)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) || ((((((pumpRunning == 0) && (2 == waterLevel)) && (methaneLevelCritical != 0)) && (splverifierCounter == 0)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((pumpRunning == 0) && (splverifierCounter == 0)) && (waterLevel == 1)) && (0 != systemActive))) || ((((((pumpRunning == 0) && (methaneLevelCritical == 0)) && (waterLevel <= 1)) && (splverifierCounter == 0)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || (((((pumpRunning == 0) && (waterLevel <= 1)) && (splverifierCounter == 0)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (2 == waterLevel)) && (splverifierCounter == 0)) && (0 != systemActive))) - InvariantResult [Line: 570]: Location Invariant Derived location invariant: 0 - InvariantResult [Line: 233]: Loop Invariant Derived loop invariant: 0 - ProcedureContractResult [Line: 450]: Procedure Contract for deactivatePump Derived contract for procedure deactivatePump. Requires: ((((waterLevel <= 2) && (1 <= switchedOnBeforeTS)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive)) Ensures: ((((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == \old(pumpRunning))) && (1 <= \old(pumpRunning))) && (0 != systemActive)) && ((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 357]: Procedure Contract for processEnvironment__wrappee__base Derived contract for procedure processEnvironment__wrappee__base. Requires: (((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive)) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) Ensures: ((((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive)) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) && (((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 135]: Procedure Contract for changeMethaneLevel Derived contract for procedure changeMethaneLevel. Requires: ((((((((pumpRunning == 0) && (waterLevel == 1)) && (0 != systemActive)) || (((1 <= pumpRunning) && (2 == waterLevel)) && (0 != systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) Ensures: (((((((((((pumpRunning == 0) && (waterLevel == 1)) && (0 != systemActive)) || (((1 <= pumpRunning) && (2 == waterLevel)) && (0 != systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) && ((methaneLevelCritical == 0) || (\old(methaneLevelCritical) == 0))) && ((\old(methaneLevelCritical) != 0) || (methaneLevelCritical != 0))) && ((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 330]: Procedure Contract for timeShift Derived contract for procedure timeShift. Ensures: ((((((((\old(pumpRunning) != 0) || (((pumpRunning == 0) && (2 == waterLevel)) && (switchedOnBeforeTS == 0))) || ((1 <= pumpRunning) && (2 == waterLevel))) || (\old(waterLevel) != 2)) && ((((((((\old(pumpRunning) == 0) && (0 != systemActive)) && (\old(waterLevel) == 2)) || ((((\old(pumpRunning) == 0) && (1 <= \old(switchedOnBeforeTS))) && (\old(waterLevel) <= 2)) && (0 != systemActive))) || (((1 <= \old(pumpRunning)) && (0 != systemActive)) && (\old(waterLevel) == 2))) || ((((\old(switchedOnBeforeTS) == \old(pumpRunning)) && (\old(waterLevel) <= 2)) && (1 <= \old(pumpRunning))) && (0 != systemActive))) || (((\old(waterLevel) == 1) && (\old(pumpRunning) == 0)) && (0 != systemActive))) || ((((\old(pumpRunning) == 0) && (\old(waterLevel) <= 2)) && (0 != systemActive)) && (\old(switchedOnBeforeTS) == 0)))) && (((1 < \old(waterLevel)) || (\old(pumpRunning) != 0)) || (((pumpRunning == 0) && (\old(waterLevel) == waterLevel)) && (switchedOnBeforeTS == 0)))) && (((((pumpRunning == \old(pumpRunning)) && (((\old(waterLevel) == ((long long) waterLevel + 1)) && (1 <= \old(waterLevel))) || ((\old(waterLevel) <= 0) && (\old(waterLevel) == waterLevel)))) && (pumpRunning == switchedOnBeforeTS)) || (\old(pumpRunning) < 1)) || (((pumpRunning == 0) && (((\old(waterLevel) == ((long long) waterLevel + 1)) && (1 <= \old(waterLevel))) || ((\old(waterLevel) <= 0) && (\old(waterLevel) == waterLevel)))) && (1 <= switchedOnBeforeTS)))) && ((((methaneLevelCritical == \old(methaneLevelCritical)) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 223]: Procedure Contract for cleanup Derived contract for procedure cleanup. Requires: 0 Ensures: (0 && ((((methaneLevelCritical == \old(methaneLevelCritical)) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 365]: Procedure Contract for processEnvironment__wrappee__highWaterSensor Derived contract for procedure processEnvironment__wrappee__highWaterSensor. Requires: (pumpRunning == switchedOnBeforeTS) Ensures: ((((((\old(pumpRunning) != 0) || (pumpRunning == 0)) || ((1 <= pumpRunning) && (2 == waterLevel))) && ((\old(pumpRunning) < 1) || (pumpRunning == switchedOnBeforeTS))) && (((((\old(pumpRunning) == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive)) || ((((waterLevel <= 2) && (switchedOnBeforeTS == \old(pumpRunning))) && (1 <= \old(pumpRunning))) && (0 != systemActive)))) && ((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 123]: Procedure Contract for waterRise Derived contract for procedure waterRise. Requires: (((((((1 <= pumpRunning) && (2 == waterLevel)) && (0 != systemActive)) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) || ((((pumpRunning == 0) && (2 == waterLevel)) || ((pumpRunning == 0) && (waterLevel == 1))) && (0 != systemActive))) Ensures: ((((((((pumpRunning == 0) || (0 < \old(waterLevel))) || (waterLevel < 2)) && ((2 == waterLevel) || (\old(waterLevel) != 2))) && ((2 == waterLevel) || (\old(waterLevel) != 1))) && ((((((((pumpRunning == 0) && (\old(waterLevel) == 2)) || ((pumpRunning == 0) && (\old(waterLevel) == 1))) && (0 != systemActive)) || ((((pumpRunning == 0) && (\old(waterLevel) <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || (((1 <= pumpRunning) && (0 != systemActive)) && (\old(waterLevel) == 2))) || ((((pumpRunning == 0) && (1 <= switchedOnBeforeTS)) && (\old(waterLevel) <= 2)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (\old(waterLevel) <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive)))) && (waterLevel <= 2)) && ((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 391]: Procedure Contract for processEnvironment__wrappee__lowWaterSensor Derived contract for procedure processEnvironment__wrappee__lowWaterSensor. Requires: (pumpRunning == switchedOnBeforeTS) Ensures: ((((((\old(pumpRunning) != 0) || (pumpRunning == 0)) || ((1 <= pumpRunning) && (2 == waterLevel))) && (((pumpRunning == 0) || (\old(pumpRunning) < 1)) || (pumpRunning == switchedOnBeforeTS))) && (((((\old(pumpRunning) == 0) && (waterLevel <= 2)) && (switchedOnBeforeTS == 0)) && (0 != systemActive)) || ((((waterLevel <= 2) && (switchedOnBeforeTS == \old(pumpRunning))) && (1 <= \old(pumpRunning))) && (0 != systemActive)))) && ((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (systemActive == \old(systemActive))) && (head == \old(head)))) - ProcedureContractResult [Line: 469]: Procedure Contract for isPumpRunning Derived contract for procedure isPumpRunning. Requires: ((((((((pumpRunning == 0) && (waterLevel == 1)) && (0 != systemActive)) || (((1 <= pumpRunning) && (2 == waterLevel)) && (0 != systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 1)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) Ensures: ((((((((((pumpRunning == 0) && (waterLevel == 1)) && (0 != systemActive)) || (((1 <= pumpRunning) && (2 == waterLevel)) && (0 != systemActive))) || (((pumpRunning == 0) && (2 == waterLevel)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 2)) && (1 <= switchedOnBeforeTS)) && (0 != systemActive))) || ((((pumpRunning == 0) && (waterLevel <= 1)) && (switchedOnBeforeTS == 0)) && (0 != systemActive))) || ((((1 <= pumpRunning) && (waterLevel <= 2)) && (pumpRunning == switchedOnBeforeTS)) && (0 != systemActive))) && (pumpRunning == \result)) && (((((((switchedOnBeforeTS == \old(switchedOnBeforeTS)) && (waterLevel == \old(waterLevel))) && (methaneLevelCritical == \old(methaneLevelCritical))) && (cleanupTimeShifts == \old(cleanupTimeShifts))) && (pumpRunning == \old(pumpRunning))) && (systemActive == \old(systemActive))) && (head == \old(head)))) RESULT: Ultimate proved your program to be correct! [2024-11-14 04:59:00,786 INFO L552 MonitoredProcess]: [MP /tmp/vcloud_worker_vcloud-master_on_vcloud-master/run_dir_ab0f445e-6dd1-4883-8928-4f866125d258/bin/utaipan-verify-sOmjnqqW8E/z3 SMTLIB2_COMPLIANT=true -memory:2024 -smt2 -in -t:2000 (1)] Ended with exit code 0 Received shutdown request... --- End real Ultimate output --- Execution finished normally Writing output log to file Ultimate.log Result: TRUE