FALSE POSITIVE: `java:S3046` treats reentrant acquisition of the same monitor as multiple locks

Hi, I found a false positive in SonarQube 26.7.0 with sonar-java 8.34 when a synchronized method enters another synchronized block on the same object.

Affected tool

SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)

Affected checker

SonarQube java:S3046

Minimal reproducer

class SpotbugsSonarqubeS3046ReentrantMonitor {
  synchronized void test() throws InterruptedException {
    synchronized (this) {
      wait();
    }
  }
}

Reproduction command

sonar-scanner --version
sonar-scanner -Dsonar.projectKey=spotbugs-sonarqube-reproducer -Dsonar.sources=spotbugs-sonarqube-s3046-fp-reentrant-monitor.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"

Current behavior

SonarQube reports java:S3046 at line 4 and states that multiple locks are held.

Expected behavior

SonarQube should not report this wait because both synchronization constructs use the same reentrant monitor.

Hello @marktiwnzhao,

Thanks for your feedback. I’ve created this JIRA Ticket to implement the fix.