Skip to content

Report only the function's own flags for a parameter without an allowed constant list - #6660

Open
dylanpulver wants to merge 1 commit into
phpstan:2.2.xfrom
dylanpulver:fix/unmapped-int-constant
Open

dylanpulver wants to merge 1 commit into
phpstan:2.2.xfrom
dylanpulver:fix/unmapped-int-constant

Conversation

@dylanpulver

Copy link
Copy Markdown

Closes phpstan/phpstan#15308

str_pad() maps allowed constants for $pad_type but not for $length. Both are int, so the fallback branch in FunctionCallParametersCheck rejected every builtin constant passed as $length:

str_pad('bla', SODIUM_CRYPTO_PWHASH_SALTBYTES, 'bla'); // Constant ... is not allowed for parameter #2 $length
str_pad('bla', PHP_INT_SIZE, 'bla');                   // same

The branch guards on $allowedConstantsType->isSuperTypeOf($parameterType), which only asks whether the parameter could be confused with a mapped one by type. That is true of any unmapped int parameter, so a numeric constant used as a plain value is reported.

The case the branch exists for (#14079) is a flag of the same function in the wrong position, so it now also requires that some other parameter actually allows the constant. str_pad('bla', STR_PAD_LEFT, 'bla') is still reported; PHP_INT_SIZE is not.

Membership is read through the existing ExtendedParameterReflection::checkAllowedConstants(), so no getter is added to ParameterAllowedConstants, which is @api.

FunctionCallParametersCheck::check() is shared by the function, method, static method, instantiation, callable and attribute rules, so the fix covers all of them.

Test Plan

tests/PHPStan/Rules/Functions/data/bug-15308.php carries the reporter's snippet, a PHP_INT_SIZE variant that does not depend on the sodium extension, and the STR_PAD_LEFT case that must still be reported. Stashing the source change makes testBug15308 fail.

On the reproducer, bin/phpstan analyse -l 8 goes from 3 errors to the 1 correct one. The six rule test classes that use this check go from 620 to 621 tests with no other change, phpcs is clean, and bin/phpstan self-analysis reports no errors.

🤖 Generated with Claude Code

https://claude.ai/code/session_011M5uTyCU4WcNTsPvGrErDo

…ed constant list

The fallback branch rejected every builtin constant passed to a parameter whose
type matched the type of some mapped parameter of the same function. For
str_pad() that made $length, an unmapped int, reject any int constant, so
str_pad('bla', PHP_INT_SIZE, 'bla') was reported even though it is a valid
length. The branch now reports a constant only when some other parameter of the
function allows it, which is the misplaced-flag case it exists for.

Closes phpstan/phpstan#15308

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011M5uTyCU4WcNTsPvGrErDo
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant