Repository navigation
Fix range() memory use, rand() and get_class() inference, and mt_rand(), rand() and round() signatures - #6531
Merged
Merged
Conversation
RangeFunctionReturnTypeExtension called range() for constant arguments and only then checked the length, so range(0, 100000000) allocated the whole array (1.7 GB) and a large enough range exhausted the memory. The length of a numeric range is now computed first, and a range longer than ConstantArrayTypeBuilder::ARRAY_COUNT_LIMIT gets the general list type right away. That also gives the list type to ranges range() itself refuses to create, like range(0, 2000000000), which lost the bounds before. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7
rand() swaps the arguments when $min is greater than $max, so rand(5, 1) returns an int between 1 and 5, but it was inferred as never like random_int() and mt_rand(), which throw ValueError for such arguments. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7
When no variant of a function accepts the number of arguments, the variants are combined into one whose parameters missing from some variant are optional. mt_rand() and rand() have the variants () and ($min, $max), so mt_rand(1) was accepted although it throws ArgumentCountError. Such a count is now checked against the variant closest to it. The functionMap was wrong for a few functions with such gaps: levenshtein() accepts each cost separately since PHP 8.0, and the $flags and $all parameters of uopz_add_function() and uopz_del_function() are optional. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7
get_class() without arguments outside of a class returns false on PHP 7, but PHP 8 throws Error instead. In a function it always throws, so it is never now. Top-level code might be included from a method and a closure bound to an object, where it returns the class name, so it is class-string there. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7
PHP 8.4 added four rounding modes, available as RoundingMode cases or as their int values 5-8, and throws ValueError for any other int. The signature still allowed only 1|2|3|4 besides RoundingMode, so round($f, 0, 5) was reported. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
These are bugs found while researching the throw type extensions for built-in functions. There is one commit per bug, and each adds a test that fails without it.
range()with a huge constant range allocated the whole arrayRangeFunctionReturnTypeExtensioncalledrange()for constant arguments and only then checked the length.range(0, 100000000)allocated 1.7 GB, and a large enough range exhausted the memory limit (the new test dies with a memory exhaustion fatal without the fix).ConstantArrayTypeBuilder::ARRAY_COUNT_LIMITgets the generalnon-empty-list<…>type straight away.range()itself refuses to create:range(0, 2000000000)wasnon-empty-list<int>, and is nownon-empty-list<int<0, 2000000000>>.range()throws before allocating anything, still go throughrange().rand(5, 1)was inferred asneverrand()swaps its arguments when$min > $max, unlikemt_rand()andrandom_int(), which throwValueError. It is now inferred asint<1, 5>.mt_rand(1)andrand(1)were not reportedParametersAcceptorSelectorcombines the variants into one whose parameters missing from some variant are optional. With the variants()and($min, $max), a single argument was therefore accepted, although it throwsArgumentCountError.CallToFunctionParametersRulenow checks such a call against the variant closest to its argument count:Function mt_rand invoked with 1 parameter, 2 required.mt_rand(1, 2, 3)keeps its0-2 requiredmessage.levenshtein()accepts each cost separately since PHP 8.0 (added tofunctionMap_php80delta.php);$flags/$allparameters ofuopz_add_function()anduopz_del_function()are optional.stream_context_set_option()with 3 arguments (ValueErroron PHP 8) andsession_set_save_handler()with 3–5 arguments.get_class()without arguments outside of a class wasfalseon PHP 8That's PHP 7 behaviour; PHP 8 throws
Error.never.class-string.false.round()rejected the modes 5–8 on PHP 8.4PHP 8.4 added four rounding modes:
RoundingModecases, or their int values 5–8. It throwsValueErrorfor any other int.functionMap_php84delta.phpnow types$modeasint<1, 8>|RoundingMode; before 8.4 it stays1|2|3|4.The full test suite and self-analysis pass. The version-dependent tests were also run locally on PHP 7.4.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Dhb4ssXuKVWcVBcNFpsdn7