Hi, I found a false positive in SonarQube 26.7.0 with sonar-java 8.34 when contradictory instanceof checks make a null branch infeasible.
Affected tool
SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)
Affected checker
SonarQube java:S2259
Minimal reproducer
class S2259ContradictoryInstanceof {
void test(Object value) {
if (value instanceof String && !(value instanceof Object)) {
Object object = null;
object.toString();
}
}
}
Reproduction command
sonar-scanner --version
sonar-scanner -Dsonar.projectKey=s2259-reproducer -Dsonar.sources=sonarqube-s2259-fp-contradictory-instanceof.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"
Current behavior
SonarQube reports sonarqube-s2259-fp-contradictory-instanceof.java:5: java:S2259: A NullPointerException could be thrown; object is nullable here.
Expected behavior
S2259 should not report this dereference. A String is always an Object, so the conjunction guarding the dereference cannot be true.