Hi, I found a false positive in SonarQube 26.7.0 with sonar-java 8.34 when a synchronized method enters another synchronized block on the same object.
Affected tool
SonarQube 26.7.0.124771; sonar-java 8.34 (build 44906)
Affected checker
SonarQube java:S3046
Minimal reproducer
class SpotbugsSonarqubeS3046ReentrantMonitor {
synchronized void test() throws InterruptedException {
synchronized (this) {
wait();
}
}
}
Reproduction command
sonar-scanner --version
sonar-scanner -Dsonar.projectKey=spotbugs-sonarqube-reproducer -Dsonar.sources=spotbugs-sonarqube-s3046-fp-reentrant-monitor.java -Dsonar.host.url="$SONAR_HOST_URL" -Dsonar.token="$SONAR_TOKEN"
Current behavior
SonarQube reports java:S3046 at line 4 and states that multiple locks are held.
Expected behavior
SonarQube should not report this wait because both synchronization constructs use the same reentrant monitor.