Skip to content

Apply the effects of a closure's by-ref uses where it is invoked - #6610

Merged
ondrejmirtes merged 3 commits into
2.3.xfrom
closure-byref-uses-at-invocation
Sep 27, 2026
Merged

ondrejmirtes merged 3 commits into
2.3.xfrom
closure-byref-uses-at-invocation

Conversation

@ondrejmirtes

@ondrejmirtes ondrejmirtes commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

A closure with use (&$x) is analysed today once, at its creation, with a fixpoint entry: $x is the union of every state any number of runs could leave, both inside the body and outside from the creation on. The type inside the closure is therefore too wide when the closure runs once from a known state, and stale when $x changes between creation and invocation.

This PR reuses the two-pass observation from #6332 and #6604 (merged) to follow where the closure runs:

$x = 1;
$c = function () use (&$x): void {
	assertType('1', $x);      // was 1|'a'
	$x = 'a';
};
assertType('1', $x);          // was 1|'a'
$c();
assertType("'a'", $x);        // was 1|'a'

$y = 1;
$d = function () use (&$y): void {
	assertType("'b'", $y);    // was 1 - the body never saw 'b'
};
$y = 'b';
$d();

How it works

  • A closure written where nothing types it gets a marker per by-ref use (a new trailing byRefUseTypes on ClosureType). The observation classifies each closure:
    • Local: every invocation was seen.
      • At creation nothing runs; an undefined $x becomes null.
      • Each invocation walks the body from the state of $x there and writes back the exit types and the throw points.
      • The body's rules run in one deferred walk at the end of the enclosing body's second pass. That walk is entered with the union of $x at the invocations, or the creation state when there was none.
    • Escaped: the value went somewhere it can be invoked at any time (argument, return, yield, property, capture by another closure or arrow function). The creation-time fixpoint stays, seeded with the invocation states seen. Local invocations of an escaped closure run the fixpoint from the current state, which also fixes a soundness hole: a closure passed away and invoked locally now changes $x at the local call.
  • The first pass runs the fixpoint from the current state at each invocation, so it contains whatever the second pass computes. An invocation from within the creation's fixpoint skips the walk. That needs accepted arguments and a body with no throw points (a catch could see mid-run states).
  • Captured by-value uses, and the check that an invocation runs in the function-like that created the closure, come from the creation's stored expression result. The persistent fact tree is flattened only once, at the end of the body.
  • Not followed: generators, a closure invoking its own by-ref variable, closures with their own @template, top-level code and non-closed bodies (the two-pass driver doesn't run there).
  • Gated by featureToggles.closureSignaturesFromUsages. Native twins are ported in the same commit.

Verification

  • Tests: new NSRT fixture closure-byref-uses-at-invocation.php (inside and after the closure: once, twice, in loops, conditional, never invoked, modified in between, undefined, by-value captures, accumulators, catch, escapes, invocations before throw/return/break), a toggle-off fixture, and a rule test. Several existing fixtures pinned the old fixpoint types and got more precise.
  • Full suite passes with and without turbo, as do make phpstan and cs. Side-by-side, signature parity, smoke (with a new by-ref frame differential) pass; walk-trace is identical.
  • Slevomat (PHP mode): 125 = 125 errors. Two messages carry a more precise array shape; both are true positives.
  • Downstream, turbo phars, one ABBA pair each, user CPU vs Infer signatures of closures from where their values are sent #6604 (the machine was busy):
    • Slevomat: 369.5 s → 365.8 s (−1.0%, pairs −3.0% / +1.1%). The same 125 errors; two messages carry a more precise array shape (true positives).
    • ShipMonk: 857.1 s → 872.9 s (+1.8%, pairs +0.3% / +3.4%). The same 374 errors.
  • Pathological cases (PHP mode, analysis time vs Infer signatures of closures from where their values are sent #6604):
    • 150 by-ref closures in one body: +54%
    • one closure invoked 200 times: +27%
    • invocations in nested loops, escapes, invocations inside ifs: at most +18%
    • Nested by-ref closures, each invoked twice by its parent, stay exponential in depth with a larger base: 3^d body walks become ~5.5^d (depth 4 +100%, depth 6 +1000%). Every walk of a parent body re-runs the child's creation fixpoint and its invocations; caching that across parent walks would need state outside the walk.

Issues

Both reproducers are top-level code, where the two-pass observation doesn't run. The regression tests (nsrt/bug-7751.php, nsrt/bug-14248.php, StrictComparisonOfDifferentTypesRuleTest::testBug14248) wrap them in a function; they fail on #6604.

Closes phpstan/phpstan#7751
Closes phpstan/phpstan#14248

🤖 Generated with Claude Code

https://claude.ai/code/session_01VpbB99tJfUmeArX74xqvHv

A closure with by-ref uses is left out of #6604's per-invocation return types: what it returns depends on its by-ref variables where it runs, which the invocation walk here follows.

@ondrejmirtes
ondrejmirtes force-pushed the closure-signatures-from-usages branch 2 times, most recently from 02e504d to e31e14e Compare September 27, 2026 10:41
Base automatically changed from closure-signatures-from-usages to 2.3.x September 27, 2026 10:45
@ondrejmirtes
ondrejmirtes force-pushed the closure-byref-uses-at-invocation branch from 8176e9f to 3bd8a5e Compare September 27, 2026 10:53
@ondrejmirtes
ondrejmirtes marked this pull request as ready for review September 27, 2026 11:47
@phpstan-bot

Copy link
Copy Markdown
Collaborator

This pull request has been marked as ready for review.

ondrejmirtes and others added 3 commits September 27, 2026 13:48
A closure written where nothing types it gets a marker per by-ref use
(`use (&$x)`). The two-pass observation classifies each such closure:

- local: every invocation was seen. At creation nothing runs (an undefined
  `$x` becomes null), each invocation walks the body from the state of `$x`
  there and writes the exit types back. The body's rules are reported by one
  deferred walk at the end of the enclosing body's second pass, entered with
  the union of `$x` at the invocations (or at the creation when there was
  none) - so inside the closure `$x` is what it was where the closure ran.
- escaped: the value went where it can be invoked at any time (an argument,
  a return, a yield, a property, a capture by another function-like). The
  creation-time fixpoint stays, seeded with the invocation states seen, and
  local invocations run the fixpoint from the current state.

While observing, invocations run the fixpoint from the current state so the
first pass contains whatever the second one computes; one from within the
creation's fixpoint (no throw points, accepted arguments) adds nothing and
skips the walk. Captured by-value uses and the check that an invocation runs
where the closure was created come from the creation's stored expression
result; only the end-of-body collection of the invocation entries flattens
the facts.

Gated by featureToggles.closureSignaturesFromUsages.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VpbB99tJfUmeArX74xqvHv
… function

The reproducers of both issues are top-level code, where the two-pass
observation does not run; the tests wrap them in a function.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VpbB99tJfUmeArX74xqvHv
@ondrejmirtes
ondrejmirtes force-pushed the closure-byref-uses-at-invocation branch from 3bd8a5e to 6e1ba36 Compare September 27, 2026 11:48
@ondrejmirtes
ondrejmirtes merged commit 6e1ba36 into 2.3.x Sep 27, 2026
527 of 529 checks passed
@ondrejmirtes
ondrejmirtes deleted the closure-byref-uses-at-invocation branch September 27, 2026 11:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Variable is changing but PHPStan doesn't see that PHPStan insists a use variable by reference cannot change types

2 participants