SONARJAVA-6972 fix: clear safeSymbols to prevent memory leak - #6142
Conversation
…lived processes Move cache clearing (ifStatementCache, firstNullCheckCache, safeSymbols) from the start of scanFile to a finally block, so the last scanned file's AST is not retained for the lifetime of the plugin classloader in IDE sessions (SonarLint). Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
a482c8d to
3e44512
Compare
Code Review ✅ Approved 1 closed / 1 findingsClears the ✅ 1 closed✅ Performance: Caches cleared only before scan, so last file's AST stays retained
Review coverage🧪 Functional validation No results 📋 Rules No rules evaluated 🤖 Auto-approval Not enabled · Set up OptionsAuto-apply is off → Gitar will not commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|
|
The code looks fine. Did you manage to reproduce the leak and test locally that it doesn't occur anymore? You can run the analysis locally and connect to the process with VisualVM and get a heap dump before and after the fix. This way you'll be able to not just say that you fixed it but You could also estimate the impact on a real project. (You can try analyzing SonarJava itself at least) And another question, don't you need an approval from someone from the CQ team? do you think mine would be enough here? |
|
@leveretka |
|
@romainbrenguier I'm not sure I can answer the question about the leak based on the charts solely. Of course the retained memory highly depends on the actual usage of What I'd check is if 'safeSymbols' is growing till the end of analysis by generating heapdumps during the analysis. And see if it contains symbols from the old files and references old files ASTs. Of course at the end of the analysis everything is cleaned. Also, I believe it will more affect single huge modules. Another possible issur is that the source files are still there due to the other leak. But that requires looking at the heapdump between the files. |
Looking at the heap dump during the analizis of sonar-java, the |
|
I don't have a good example to reproduce the leak for now, but I'm going to merge anyway since it can only improve things. |






Problem
The
safeSymbolsfield inBoxedBooleanExpressionsCheckaccumulates symbols across file scans but is never cleared. This causes a memory leak when the analyzer processes multiple files, as the set continues to grow without bound.The two static caches (
ifStatementCacheandfirstNullCheckCache) are properly cleared at the start of each file scan, butsafeSymbolswas overlooked.Solution
Add
safeSymbols.clear()inscanFile()alongside the existing cache clear calls. This ensures the set is reset for each file while maintaining correct behavior within a single file.Verification