Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused fix correctly handles both open bounds and includes comprehensive regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Fixes shift-left inference for open integer ranges by accounting for platform limits during overflow detection.
Changes:
- Checks unbounded range endpoints using
PHP_INT_MINandPHP_INT_MAX. - Updates affected shift-left expectations.
- Adds regression coverage for open ranges and the
u64()reader false positive.
| File | Description |
|---|---|
src/Reflection/InitializerExprTypeResolver.php |
Detects overflow at open integer-range bounds. |
tests/PHPStan/Analyser/nsrt/shift-left-unbounded-range.php |
Covers open bounds, zero/right shifts, and the reader regression. |
tests/PHPStan/Analyser/nsrt/integer-range-types.php |
Updates overflow-sensitive inferred types. |
tests/PHPStan/Rules/Comparison/NumberComparisonOperatorsConstantConditionRuleTest.php |
Verifies the false comparison warning is eliminated. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
The core unit-test matrix, self-analysis matrix, generated baselines, and coding standard have passed. I also downloaded the PHAR built by this PR and ran the full passkeys analysis with its original configuration: no errors. The broader PHAR integration matrix is not green, but its current failures also occur in the earlier run https://github.com/phpstan/phpstan-src/actions/runs/36867554483, before this PR:
I have not changed those unrelated checks or their baselines. This account has read-only access to the upstream repository, so I cannot rerun its jobs. |
|
Final CI update: the core unit tests, self-analysis, coding standard, and generated baselines pass, but not all remaining failures are pre-existing. PocketMine is affected by this fix. At The other newly completed failures are:
The earlier comment's pre-existing-failure evidence applies to the specific jobs listed there, not to every failure in the final matrix. |
Summary
Check open integer-range bounds for shift-left overflow, using
PHP_INT_MINandPHP_INT_MAXwhen a bound isnull.The existing overflow check only checks finite bounds. For
int<0, max> << 8, it checks zero but skips the maximum, so the result incorrectly remains non-negative. The same problem affects open lower bounds.This causes a false
smaller.alwaysFalseerror in a big-endianu64()reader:The false positive first appears in 2.2.9. Git bisect identifies 1081ec4, whose bitwise OR range inference exposes the shift-left problem. The more recent finite-bound overflow check does not cover this case.
Tests
Local validation on PHP 8.5:
Original failure: https://github.com/shipmonk-rnd/passkeys/actions/runs/36873090362/job/110405538537
Task: https://app.asana.com/0/0/1219068476946134