Scanner stuck when analysis invalid json in PHP code

I’ve got this little piece of php code:

<?php

class FailingTest {

    public static function encoding(): array {
        return [
            ["\xc3\x28", '"\ufffd("', 'invalid unicode sequence'],
            [
                [[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[33]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]]],
                'exception',
                'Maximum stack depth exceeded'
            ]
        ];
    }
}

It’s a testcase for invalid json format. Whenever this gets analysed through Sonarqube Cloud or sonar-scanner-cli. It gets stuck and never completes.

Here’s a snippet of the sonarscanner container log when analysing the code:

00:23:49.698 INFO  Load metrics repository
00:23:50.024 INFO  Load metrics repository (done) | time=328ms
00:23:50.030 INFO  Sensor cache enabled
00:23:50.032 INFO  Load sensor cache
00:23:51.502 INFO  Load sensor cache (4 KB) | time=1470ms
00:23:52.409 INFO  Sensor HTML [web]
00:23:52.437 INFO  Sensor HTML [web] (done) | time=28ms
00:23:52.438 INFO  Sensor JaCoCo XML Report Importer [jacoco]
00:23:52.440 INFO  'sonar.coverage.jacoco.xmlReportPaths' is not defined. Using default locations: target/site/jacoco/jacoco.xml,target/site/jacoco-it/jacoco.xml,build/reports/jacoco/test/jacocoTestReport.xml
00:23:52.441 INFO  No report imported, no coverage information will be imported by JaCoCo XML Report Importer
00:23:52.441 INFO  Sensor JaCoCo XML Report Importer [jacoco] (done) | time=3ms
00:23:52.441 INFO  Sensor PHP sensor [php]
00:23:52.493 INFO  Starting PHP symbol indexer
00:23:52.506 INFO  4 source files to be analyzed
00:24:02.545 INFO  3/4 files analyzed, current file: tests/FailingTest.php
00:24:12.545 INFO  3/4 files analyzed, current file: tests/FailingTest.php
00:24:22.545 INFO  3/4 files analyzed, current file: tests/FailingTest.php
00:24:32.547 INFO  3/4 files analyzed, current file: tests/FailingTest.php

To reproduce it:

  1. Create a php file with the code in it
  2. Run the sonnarscanner-cli container on file

Any help on what’s happening? can this be escalated to a bug ticket?

Hello @Kunleodusan , welcome to the community!

Thanks for your report. It’s good to know the limits of our parser, even though it’s clearly an edge case. FWIW, for 14 brackets parsing finishes in a reasonable amount of time (however, judging by your code, you are testing another system, so changing the example might not be an option).

If the failing analysis is disturbing your workflow, you can temporarily exclude the problematic file from the analysis by adding it to sonar.exclusions property, see more info here. Meanwhile, I’ve created a ticket SONARPHP-1687, but I can’t guarantee when it will be handled.

Hope that helps,

Peter

Thanks Peter,
Will exclude the file for now