spring-boot-demo-oom: five real memory-leak demos with captured OOM + MAT evidence

This commit is contained in:
2026-10-01 12:11:56 +00:00
commit fd035a79e8
41 changed files with 1317 additions and 0 deletions
@@ -0,0 +1,10 @@
$ java -Xmx160m -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=docs/output/heap.hprof -jar target/static-cache-leak.jar
static-cache-leak: entries=1400 approxRetainedMB=87
static-cache-leak: entries=1600 approxRetainedMB=100
static-cache-leak: entries=1800 approxRetainedMB=112
static-cache-leak: entries=2000 approxRetainedMB=125
static-cache-leak: entries=2200 approxRetainedMB=137
java.lang.OutOfMemoryError: Java heap space
Dumping heap to docs/output/heap.hprof ...
Heap dump file created [166360462 bytes in 0.172 secs]
@@ -0,0 +1,24 @@
Eclipse MAT 1.17.0 batch report (org.eclipse.mat.api:suspects) on heap.hprof -- Problem Suspect 1
================================================================================================
Problem Suspect 1 The class com.ankurm.oomdemo.StaticCacheLeakApplication , loaded by
org.springframework.boot.loader.launch.LaunchedClassLoader @ 0xf6067460 , occupies 150,878,464
(96.17%) bytes. The top consumers of its minimum retained heap are byte[] (4,607 instances
totaling 150,730,920), java.util.concurrent.ConcurrentHashMap$Node (2,298 instances totaling
73,536), and java.lang.String (2,309 instances totaling 55,416). The memory is accumulated in
one instance of java.util.concurrent.ConcurrentHashMap$Node[] , loaded by <system class loader>
, which occupies 150,875,504 (96.17%) bytes. Thread java.lang.Thread @ 0xf60af750 main has a
local variable or reference to class com.ankurm.oomdemo.StaticCacheLeakApplication @ 0xf6000000
which is on the shortest path to java.util.concurrent.ConcurrentHashMap$Node[4096] @ 0xfba808c8
. The thread java.lang.Thread @ 0xf60af750 main keeps local variables with total size 109,016
(0.07%) bytes. The top consumers of its minimum retained heap are byte[] (4,607 instances
totaling 150,730,920), java.util.concurrent.ConcurrentHashMap$Node (2,298 instances totaling
73,536), and java.lang.String (2,309 instances totaling 55,416). Significant stack frames and
local variables org.springframework.boot.SpringApplication.run(Ljava/lang/Class;[Ljava/lang/Stri
ng;)Lorg/springframework/context/ConfigurableApplicationContext; (SpringApplication.java:1354)
class com.ankurm.oomdemo.StaticCacheLeakApplication @ 0xf6000000 retains 150,878,464 (96.17%)
bytes org.springframework.boot.loader.launch.Launcher.launch(Ljava/lang/ClassLoader;Ljava/lang/S
tring;[Ljava/lang/String;)V (Launcher.java:106) class
com.ankurm.oomdemo.StaticCacheLeakApplication @ 0xf6000000 retains 150,878,464 (96.17%) bytes
The stacktrace of this Thread is available. See stacktrace . See stacktrace with involved local
variables .
+40
View File
@@ -0,0 +1,40 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
<modelVersion>4.0.0</modelVersion>
<parent>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-parent</artifactId>
<version>4.1.1</version>
<relativePath/>
</parent>
<groupId>com.ankurm</groupId>
<artifactId>static-cache-leak</artifactId>
<version>1.0.0</version>
<name>static-cache-leak</name>
<description>Leak pattern 1: a static cache that is never evicted</description>
<properties>
<java.version>25</java.version>
</properties>
<dependencies>
<dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter</artifactId>
</dependency>
</dependencies>
<build>
<finalName>static-cache-leak</finalName>
<plugins>
<plugin>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-maven-plugin</artifactId>
</plugin>
</plugins>
</build>
</project>
+23
View File
@@ -0,0 +1,23 @@
#!/usr/bin/env bash
# Runs docs/output/heap.hprof (produced by scripts/run.sh) through Eclipse Memory Analyzer's
# headless batch report generator -- MemoryAnalyzer's -application org.eclipse.mat.api.parse,
# invoked via the ParseHeapDump.sh wrapper MAT ships -- then re-extracts the Problem Suspect
# summary into docs/output/02-mat-leak-suspects.txt.
#
# No GUI is shown, but MAT's SWT runtime still needs an X display even in this mode, hence
# xvfb-run. Needs: MAT_HOME pointing at an extracted Memory Analyzer 1.17.0+ "rcp" distribution,
# and xvfb-run on PATH (package "xvfb" on Debian/Ubuntu).
set -eu
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
MODULE_DIR="$(cd "$SCRIPT_DIR/.." && pwd)"
ROOT_DIR="$(cd "$MODULE_DIR/.." && pwd)"
cd "$MODULE_DIR"
: "${MAT_HOME:?Set MAT_HOME to your Memory Analyzer install (e.g. /opt/mat)}"
if [ ! -f docs/output/heap.hprof ]; then
echo "docs/output/heap.hprof not found -- run scripts/run.sh first" >&2
exit 1
fi
rm -f docs/output/heap_Leak_Suspects.zip
xvfb-run -a "$MAT_HOME/ParseHeapDump.sh" "$MODULE_DIR/docs/output/heap.hprof" org.eclipse.mat.api:suspects
python3 "$ROOT_DIR/scripts/extract-mat-summary.py" "$MODULE_DIR"
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
# Drives static-cache-leak to a REAL java.lang.OutOfMemoryError under a constrained heap, with
# -XX:+HeapDumpOnOutOfMemoryError so the crash leaves a real .hprof behind. Also regenerates
# docs/output/01-oom-console.txt from the real run log.
#
# Needs JDK 25 (LTS) on PATH.
set -eu
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
MODULE_DIR="$(cd "$SCRIPT_DIR/.." && pwd)"
ROOT_DIR="$(cd "$MODULE_DIR/.." && pwd)"
cd "$MODULE_DIR"
mvn -q -B package -DskipTests
mkdir -p docs/output
rm -f docs/output/heap.hprof
CMD="java -Xmx160m -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=docs/output/heap.hprof -jar target/static-cache-leak.jar"
echo "== running: $CMD =="
LOG="$(mktemp)"
$CMD > "$LOG" 2>&1 || true
python3 "$ROOT_DIR/scripts/extract-oom-console.py" "$MODULE_DIR" "$LOG" "$CMD"
rm -f "$LOG"
echo "heap dump: docs/output/heap.hprof (not committed -- see .gitignore; regenerate it with this script)"
@@ -0,0 +1,58 @@
package com.ankurm.oomdemo;
import org.springframework.boot.SpringApplication;
import org.springframework.boot.autoconfigure.SpringBootApplication;
import org.springframework.boot.ApplicationArguments;
import org.springframework.boot.ApplicationRunner;
import org.springframework.context.annotation.Bean;
import java.time.Instant;
import java.util.Map;
import java.util.concurrent.ConcurrentHashMap;
/**
* Leak pattern 1 of 5: the static cache that nobody evicts.
*
* ResponseCache below is the kind of thing a real codebase grows by accident: a
* "let's cache this so we don't recompute it" field that is declared static (so it
* survives bean re-creation, scoped singletons, whatever) and never has an eviction
* policy added later because the person who wrote it assumed the key space was
* small. It is not. Every request here gets a unique id, so the map grows by one
* entry, forever, for the life of the JVM.
*
* See docs chapter: the post links the exact line this leak happens on.
*/
@SpringBootApplication
public class StaticCacheLeakApplication {
/**
* The leak. static + no eviction + an ever-growing key space is the whole bug.
* ConcurrentHashMap only makes it thread-safe to leak from multiple threads at once.
*/
static final Map<String, byte[]> RESPONSE_CACHE = new ConcurrentHashMap<>();
public static void main(String[] args) {
SpringApplication.run(StaticCacheLeakApplication.class, args);
}
@Bean
ApplicationRunner driveLeak() {
return (ApplicationArguments args) -> {
long payloadSize = 64 * 1024; // 64 KB "cached response" per unique request
long i = 0;
long started = System.nanoTime();
System.out.println("static-cache-leak: driving RESPONSE_CACHE to OOM, payload=" + payloadSize + " bytes/entry");
while (true) {
String key = "req-" + Instant.now().toEpochMilli() + "-" + i;
byte[] payload = new byte[(int) payloadSize];
payload[0] = (byte) (i % 128); // touch it so JIT can't dead-code it away
RESPONSE_CACHE.put(key, payload);
i++;
if (i % 200 == 0) {
long mb = (RESPONSE_CACHE.size() * payloadSize) / (1024 * 1024);
System.out.println("static-cache-leak: entries=" + RESPONSE_CACHE.size() + " approxRetainedMB=" + mb);
}
}
};
}
}