Fix infinite loop parsing errored SARIF security reports

What does this MR do and why?

Uploading a SARIF report whose rule help omits the schema-required text key crashes Sidekiq with an out-of-memory error. The crash is an infinite loop: a one-rule report reproduces it.

When a SARIF report fails schema validation, the parser returns the shared base report object carrying the schema errors. That same object then also appears in run_reports, so the error-propagation step iterates report.errors while add_error appends to that same array (errors << ...). The loop never terminates and grows the array until the worker OOMs.

The fix snapshots the base report's errors before propagating and skips the base report itself, so we never append to the array being iterated.

How it manifested

Reported via https://gitlab.com/gitlab-com/request-for-help/-/work_items/5235#note_3695947999: a customer's SonarQube SARIF upload (rules with markdown-only help, no text) exhausted Sidekiq memory, surfacing downstream as FailedToObtainLockError retry pile-ups.

Relates to https://gitlab.com/gitlab-com/request-for-help/-/work_items/5235

Edited by Lucas Charles

Merge request reports

Loading
Loading