PHP7 Gains Scalar Type Hints
wiki.php.net
wiki.php.net
Having an optional mode per file allows:
People who want to write code with strict types can do so. People who want to write code with weak types can do so. People who want to write code without these new fangled types can continue to do so.
All without any issues of compatibility between running code on the current version of PHP and what will be the next one, and without any compatibility issues for libraries that are solely written in one mode, being used in applications that are written in the other mode.
\o/
To be honest, I'm completely in the strict camp - but it's awesome that we've gotten a solution that should allow everyone to use the mode they want, without splitting the PHP ecosystem.
Can you explain why? Are you using PHP in a web context? Because everything from the web is a string.
So wouldn't it make the most sense to let the functions using the web data coerce to integer, and just work?
How does putting (int) before the arguments to function help anything?
I actually liked Ze'ev's proposal because it let you be weak while making sure you did not coerce obviously bad data.
Anyway, as a member of the strong camp, can you explain?
I would start by saying that everything, regardless of domain, is just a stream of bits. Which is completely useless, just like your assertion.
And I know what you meant, but you're also wrong. A JSON object is only a string before being interpreted. An x-www-form-urlencoded is actually a map in which values can be arrays instead of primitives. Such forms often correspond to domain models with a clear definition.
There's also no such thing as "obviously bad data". All data is good in the proper context, therefore automatic conversions that try to make this distinction do not make sense. I don't necessarily know how PHP behaves, but in another popular language there's a world of difference between "077" and "77". There's also a world of difference between integer, floating point and fixed point and the details are never irrelevant.
You have to convert it somewhere. I don't see how the caller converting it is any better than the recipient doing it. Having the caller do it seems quite pointless when the recipient is anyway doing it.
Your answer about how everything is bits was quite useless since you completely missed the point. Your input is a string, you have to convert it someplace. Weak mode has the recipient do it. Strict mode you have to do it yourself, and then the recipient double checks.
I see no value in the second option - the actual conversion in both cases is identical.
But Danack disagrees, so I asked him to explain. Your answer was not helpful at all.
77
077
77.0Why are you answering something I did not ask?
I am asking why does Danack prefer strict mode. There is absolutely nothing in my question that cares about the specific details how you convert bits to types, other than that you do.
My question is entirely about WHO does the conversion. NOT about the conversion itself.
(Oh, and the thing about bad-data has a defined meaning that went over your head because you are not familiar with the debate here. In this context bad-data means data loss on conversion. So "1" to 1 is fine, but "1 a" to 1 is not.)
And also in the conversion from "1.1" to 1.1 there is loss of information, because the two representations are not isomorphic. Care to guess why?
So the question he is asking is, if you have to do the check at runtime anyway, what is the benefit of the type hinting? Isn't it just belt and braces?
It seems like a perfectly legitimate question to me.
And by the way, to those downvoters who don't seem to be able to tell the difference between a comment you disagree with and spam, can you please contribute to the conversation by hitting the reply button or alternatively get lost? Only you're ruining it for the rest of us. Thanks
Actually, I disagree. The caller is the only one who has semantic information about what the variable (and hence its value) means. All the callee (recipient) can do is blind cast it. The caller on the other hand can interpret it because it knows the meaning (talking about the developer, not the engine).
Do you consider JSON a string? Would you manipulate it as a string or use a JSON parser?
> How does putting (int) before the arguments to function help anything?
It throws an error in case you receive bad input, and as we all know you will receive bad input.
Of course I manipulate the data - that's exactly what weak mode does, convert the strings into integers. I just don't see how doing the conversion myself manually helps anything.
> It throws an error in case you receive bad input, and as we all know you will receive bad input.
It does no such thing. (int) will simply turn bad input into a zero.
Yes.
I have no doubt you CAN do it, but most of the time you don't.
And since most of the time you are dealing with strings my question stands: Why do the conversion manually instead of letting the nice new feature do it for you.
If you did send everything as JSON you would be bypassing everything PHP does with form/url data to make things easier for you (for example arrays). That doesn't seem like a good engineering tradeoff.
And then you can't make a request to the server directly unless you format your data as JSON, which is a bit inconvenient, especially if you're debugging a problem.
So if using JSON as a container isn't gaining you some other benefit then it's probably best avoided.
That's how we've done it here and the modularization it has provided us has been incredible. PHP's json_encode and json_decode are also quite fast.
I'm not saying using JSON as an envelope won't work - it is clearly working for you - just that I wouldn't start there, and I can't see that you couldn't work with the request object directly.
In your preferred way, data is exchanged over HTTP which uses percent encoding to pass data. I'm stating that a serialized object, in this case JSON, provides more benefit.
Both require overhead to encode and decode, but I believe that serializing your data allows for a more consistent exchange that (provided I am understanding how you post and retrieve data) actually may reduce size, increase the variance of what can be transmitted, and remove specific limitations that HTTP may encounter.
I'm genuinely curious if I am missing something.
I'm sure I could find myself in a position where I would want to standardise on JSON as a container for requests/responses, though see my last paragraph about Atom.
That said, my instinctive reaction against using JSON as an envelope is that it adds a layer of abstraction (and potential obfuscation) that I don't see an immediate benefit for. It may hark back to my experiences with SOAP. My mantra is to exploit the existing protocol to its fullest before extending it, and to do the simplest thing before adding complexity.
Let's presuming we're still at a basic level of interaction through a website. Treating something as a form with fields such as name="user[email]", name="user[password]", name="user[telephone][mobile]" etc, seems more discoverable to me, as a developer at least.
For one thing, I know there is no JSON translation layer to go through. For another, I can get a server to generate a form that I can use to test the interface quickly and easily. To do the same with JSON would require me to have some JS intercepting the submit event so that it can convert the contents to JSON before posting. So now I can't use a terminal based browser to do my testing. Which means maybe I can't automate some testing strategy so easily.
If we're talking about a more sophisticated RESTful API, I would probably choose ATOM over JSON, because ATOM is built on XML and therefore is defined by a schema and can be interpreted by the browser. Specifically, it provides the rel attribute for discoverability. JSON payloads can implement this too, but you have to choose your extension.
In fairness, if I were doing a RESTful API, I'd probably be thinking about being able to implement interfaces for ATOM, JSON, and HTML, plus whatever cool new thing is just around the corner.
I'll agree that your way definitely provides less abstraction, and my viewpoint doesn't perceive jt in that way. That being said, I've made a similar case against ORMs, so I understand your position.
Over the years, we have refactored our PHP code base to something which is much more bug proof, and a lot of it is because we demand certain types to be passed to types. Currently we use doc types (for which the IDE helps us heaps) and type hinting for objects being passed as arguments.
For a given process (e.g. form submission) there will nevertheless be an entry point where strings from the web are passed in. But if you can minimize that area as much as possible, beyond that one place (a function or class) which understands the mapping from incoming string types to PHP types, you end up with a code base which behaves mostly like a statically type language.
This has reduced a huge subset of bugs which are caused by unexpected input being passed to a function. Having the language itself tell you when you made an error statically while writing is much better than having to wait until runtime.
A similar argument would stand for why we moved from dynamically created strings sent to the database, towards a database abstraction layer where we pick up syntax errors at time of writing.
Hopefully.
> How does putting (int) before the arguments to function help anything?
It wouldn't. Anyone who is casting from an unknown type to an int by using just `(int)` is doing something wrong in my opinion.
Even in web-based applications there are at least two layers of code: i) One where the type of the values are unknown and they are represented as strings. ii) One where the types of the values are known.
At the boundary between these two layers you should have code that inspects the strings that represent the input values, check that they are acceptable, and convert them to the desired type. If the input values cannot be converted to the desired type, the code needs to give an error that is both specific to the type of error so that a computer can understand it, as well as provide a human understandable explanation of why the conversion was not allowed.
The reason why I want strong types is that I never, ever want to blindly cast from one type to another. The decision about how to convert from one type to another, should always be made at a boundary between areas of the application where types are known, and the areas where the types are unknown. I always want to be forced to make that decision in the right place, using code that gives useful errors and messages, rather than having the value coerced into the desired type.
tl;dr I won't use (int) to cast, I will use something like the code below.
cheers Dan
function validateOrderAmount($value) : int {
$count = preg_match("/[^0-9]*/", $value);
if ($count) {
throw new InvalidOrderAmount("Order amount must contain only digits.");
}
$value = intval($value);
if ($value < 1) {
throw new InvalidOrderAmount("Order amount must be one or more.");
}
if ($value >= MAX_ORDER_AMOUNT) {
throw new InvalidOrderAmount("You can only order ".MAX_ORDER_AMOUNT." at a time.");
}
return $value;
}
function processOrderRequest() {
$orderAmount = validateOrderAmount($_REQUEST['orderAmount']);
//Yay, our IDE/static code analyzer can tell that $amount is an int if the code reached here.
placeOrder($orderAmount);
}So from your code it looks like the only benefit of strict mode is in case you forget to do the validation/conversion it will warn you? I guess that's reasonable. Is there any other benefit?
To me it seems that Ze'ev's proposal would be even better for you - it does the equivalent of the validation and conversion automatically including with an error if it doesn't validate.
You wrote "let's ignore that", but it really seems like to best of all worlds to me. Any idea why it was rejected so badly? Is it because the coercion rules are different from the rest of PHP?
Strict types make it easier to reason about code, that the tl;dr version.
> To me it seems that Ze'ev's proposal would be even better for you - > it does the equivalent of the validation and conversion automatically > including with an error if it doesn't validate.
Rather than having int 'types' which we can reason about, it has int 'values' which are harder to reason about. Types can be reasoned about just by looking at the code. Values can only be reasoned about when running code. A contrived example:
function foo(int $bar){...}
foo(36/$value);
In strict mode, this would be reported as an error by code analysis.For the coercive scalar type proposal, this code works - except when it doesn't. This code works when $value = 1, 2, 3, 4 and breaks when $value = 5.
This is the fundamental difference; whether conversions between types have to be explicitly done by code, and so any implicit or incorrect conversion can be detected by static code analysis tools, or whether the conversions are done at run time, and so cannot be analyzed fully.
This means most of these errors will be discovered by users on the production servers. Strict mode allows you to eliminate these types of errors.
Yes, this means I need to add a bit of code to do the explicit conversion, but I just don't convert between values that much. Once a value is loaded from a users request, config file or wherever, it is converted once into the type it needs to be. After that, any further change in type is far more likely to be me making a mistake, rather than an actual need to change the type.
> Any idea why it was rejected so badly? Is it because the coercion rules are different from the rest of PHP?
At least in part it was because the RFC was seen as a way to block strict types; about half of the RFC text is shitting on people desires for strict types, which did not make people who want strict types be very receptive. If it had been brought up 6 months ago, there is a good chance it would have passed, or at least would have been closer.
Some parts of the proposal were good - other parts were nuts that were pretty obvious the result of the RFC only being created once the dual mode RFC was announced and about to be put to the vote, with a very high chance of passing.
* Good - "7 dogs" not longer being converted to "7" if someone tries to use it as an int.
* Bad - Different mode for internal function vs userland functions e.g. "Unlike user-land scalar type hints, internal functions will accept nulls as valid scalars." and other small differences. This is even more nuts than you might realise as it means if you extend an internal class, and overload some of the methods on the class, those methods will behave differently to the non-overloaded methods.
* Bad - Subtle and hard to fix BC breaks in conversion which are probably not right anyway. e.g. false -> int # No more conversion from bool true -> string # No more conversion from bool
It is a shame that the discussion became so contentious. It would have been good if the conversion rules could have been tidied up, but all the time and energy had been used up the not particularly productive discussion.
I think of it as the English language of programming. Picking and choosing all of the best bits from every other language, and bastardizing them into it's own everyday use.
Also +1 to what @Padding says.
However, it gets the point across; taking a bunch of bits from disparate well-functioning systems and smashing them together doesn't guarantee that you'll get another well-functioning system.
While I understand the optional strict mode, I do find it quite confusing: it looks similar to javascript's 'use strict';, and at first glance it sounds like it should be similar to `error_reporting(E_STRICT)`, yet somehow scoped to the <?php ?>. Personally I like the `strict namespace` approach they proposed the most. The argument against is that it will read like everything in that namespace is strict, when it's actually limited to the file, but I think it's pretty clear if I read in a.php `strict namespace Qaribou;` and in b.php `namespace Qaribou;`, that a.php is strict and b.php is not. I really don't see the ambiguity there.
* People who have commit access to git/svn
* Documentation contributors
* Documentation translators
* PEAR package maintainers
* PECL package maintainers
* Very few "community representatives"
I haven't had a use for this yet, but I'm always amazed by how PHP manages to move forward without breaking BC.
This. If I were a Python developer (of the language itself), I would be paying very close attention to how PHP has handled deprecation and breaking changes.
And also the jump from 5.4+ to 7 is probably smaller than the jump from 5.2 to 5.3.
Although I think the PHP project does need to support versions for longer, the adoption rate of 7 is going to be quite rapid due to the low barrier of doing it, and the massive performance and language gains.
I understand why some people prefer that, and why it's the way most languages go (Java does the same thing, just with way less movement in general compared to PHP), but it means that the language gets worse over time. Eventually, if you don't do that breaking change, the language will get replaced by something that doesn't need all the cludge.
Bad analogy, but the point is that Python still worked for most people so the upgrade process was slow.
I think Go is going to have issues similar to Python when they make the jump to 2.0. The devs are already on record saying that BC will break.
I've had cases where I want to only allow certain values (most often int) into certain functions (usually __construct, when looking at a primary key in a database), but in these cases I prefer to cast values. (int)$foo hasn't failed me yet, and I've internalized it as much as I've internalized running application output through htmlentities.
I can see this being extremely useful if you plan on using PHP as a general purpose language, but I never have. I'd rather jump to Java/C++/Rust if I had to do numeric calculations (things like images, real time calculations, etc.)
You pull out a particular row from this library/extension, and it contains an empty string (or even null) as the value for the primary key field.
Using typecasting, you'd get a value of 0, which is wrong. It would fail silently, and you'd only discover the error when you realize you're working on a row with no data. You'd even be able to update the row silently, because "UPDATE whatever SET x = y WHERE id = 0" is valid SQL!
With primitive type hints, you'd know immediately that you're getting an empty value from your DB, and you could go straight to fixing that instead.
In the past, people have had to write a bunch of unit tests to avoid all these issues. With primitive type hints, you could just type the word "int" and be done with it.
All that said, I still say all the people that are excited about this are much better off switching to a strictly-typed language, because my example above is just the tip of the iceberg when it comes to juggling types.
Off the top of my head, here's a case where they changed the output of a hash function between 5.3 and 5.4, breaking it for all previous users. https://bugs.php.net/bug.php?id=60221
Well, at least you know what you're getting into. It's not like they promise otherwise anywhere.
Also, the moment I read declare(strict_types..., for some reason "use strict"; from ECMAScript flashed in front of me :D
php > use strict;
PHP Fatal error: You seem to be trying to use a different language... in php shell code on line 1
>>> from __future__ import braces
File "<stdin>", line 1
SyntaxError: not a chance "use strict";
(note 'use' is part of a string) should work in PHP for the same reason it does in ECMAScript -- it is a no-op at the language level (creating a string literal and doing nothing with it), that is unlikely to appear in old code, and can be given new meaning in the next-level language spec.I break down all of the proposed alternatives and the cases against them.
"Whether or not the function being called was declared in a file that uses strict or weak type checking is irrelevant. The type checking mode depends on the file where the function is called."
That means that my function can have a parameter defined as an int in its strict file, but if it's called from outside of it, anything can still be passed to that parameter, right?
I'm not sure how I like that. What if you're passing input from class A into class BStrict then using BStrict to call a function in CStrict? BStrict and CStrict are defined as strict, where A is not. Would BStrict then be the one throwing the error because the "caller" is the issue?
From the description it seems that the parameters are effectively ignored in BStrict when A calls it.
Am I missing something or does this sound iffy?
Edit: Link for quote - https://wiki.php.net/rfc/scalar_type_hints_v5#parameter_type...
Not at all. It's "weak" typing, not no typing.
A small set of convertible values can be passed and will be converted to the type you asked for, while other values error as usual.
See the rest of the RFC.
(imho, not only good, but awesome stuff, like XHP https://www.facebook.com/notes/facebook-engineering/xhp-a-ne... and async/await http://docs.hhvm.com/manual/en/hack.async.php)
And as a bonus, both HHVM.PHP and Hack and are well optimized to run at Facebook's scale... seriously, let's just leave Zend.PHP rot away in the trashcan of history and move the f on!
In fact, this kind of feature may make it easier to convert those applications to Hack in the future.
That's the huge point that nobody seems to see.
But then again, considering how many other huge points PHP developers seem to miss in general, maybe it's better to just let Node.js eat the world :)
PHP the language will always rely on PHP the brand being as ubiquitous as it is. The more that can be done to improve the language, the stronger the brand and the longer it will endure.
I once attended a mini-conference where he did a talk about PHP history. After the talk, someone asked a question about strict typing. Rasmus really hold on to the web not having types (just passing strings, as have been pointed out in other comments here). I remember him saying something like "when the web have strict types, PHP will have it too".
Other people would like to use PHP more as a general computing language.
Having optional types takes nothing away from using PHP for simple web pages, but does make it easier to right analyzably correct programs.
The fact that the founder of a language doesn't want to see it grow is quite depressing.
Do you need to run a pre-processor to strip them out of the code that runs on PHP5, while getting the benefit for testing on PHP7?
Trying it naively, PHP5 thinks you want to use a class called "int". And doesn't like the : for the return value.
function foobar(MyClass $foo) {
// do stuff
}
foobar(new NotMyClass()); // throws an error
This just adds type hints for the scalar types (integer, float, string and boolean).Since PHP has a long tradition of weak typing and this is what PHP's built-in and extension functions use, weak is the default behaviour, allowing some conversions:
function foo(int $x) {
var_dump($x);
}
foo("12"); // produces int(12)
foo(null); // throws an error
But, you can optionally turn on a strict type-checking mode for scalars on a per-file basis, which doesn't allow conversions: <?php
declare(strict_types=1);
function foo(int $x) {
var_dump($x);
}
foo("12"); // throws an error
foo(null); // throws an errorfunction foo(int $x) { // x is guaranteed to be an int. }
The type-hinting for scalars has two modes:
* strict - the parameter passed to the function must be of the exact* type. * weak - the parameter passed to the function will be converted to the correct type.
The strictness depends on what mode PHP was in when the function was called. This is the right choice as it:
* Allows library authors to write their code in either strict or weak mode.
* End-users to write their code in either strict or weak mode. Or even without using scalar type-hints.
* End-user to be able to choose when they are writing their code do they want their variables to be converted to the type expected by the library automatically, or do they want PHP to give them an error if they accidentally pass the wrong type of variable to a function that is expecting an int.
*except for some widening rules, e.g. you can pass an int where a float is expected, as ints can be converted into float without data loss (for ints less than 2^53).
But honestly, if you're using HHVM already, you should have as much tooling/documentation as you need to switch to Hack itself within the next year or so, so all this PHP discussion is moot.
Examples on Amazon: http://www.amazon.com/s/ref=nb_sb_noss_1?url=search-alias%3D...
The vote: https://wiki.php.net/rfc/php6
> The decimal system (or more accurately the infinite supply of numbers we have) makes it easy for us to skip a version, with plenty more left for future versions to come.
Hard to argue with that!
Since PHP6 died, it made sense to avoid confusion and not name the new major version 6, since we'd then have two different PHP 6es.
This is not unlike what happened with ECMAScript 4.
https://www.reddit.com/comments/2qyuhc/new_rfc_for_scalar_ty...