:mag_right: static analysis rules to prevent IEEE-754 floating point errors
This library is a PHPStan plugin
that disallows:
float
propertiesfloat
method parametersfloat
method return typesfloat
values to variables or propertiesThe reason for this restriction is that rounding errors coming
from floating point arithmetic operations are not acceptable in
certain business logic scenario, such as dealing with money,
evaluating exam results, rocket science, etc.
An example of such problems can be seen with the following typical
example:
var_dump((0.7 + 0.1) === 0.8); // output: bool(false)
This can mean no trouble at all, or a lot of trouble, depending
on how many numbers you are running through your system, so it
is advisable to avoid float
for domains where rounding can
potentially lead to trouble.
float
is still perfectly acceptable in many programming contexts,
and this ruleset should only be applied where it is critical not
to introduce rounding errors.
composer require --dev roave/no-floaters
In your phpstan.neon
configuration, add following section:
includes:
- vendor/roave/no-floaters/rules.neon
Optionally, you can configure the library to disallow any
float
-producing expression at all, by adding following to your
phpstan.neon
:
parameters:
disallowFloatsEverywhere: true
If the above is enabled, given the following example-file.php
contents:
<?php
$a = 1 / 3;
You should get something like following:
vendor/bin/phpstan analyse example-file.php -l 7
1/1 [▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓] 100%
------ -----------------------------------------------------
Line example-file.php
------ -----------------------------------------------------
3 Cannot assign float to $a - floats are not allowed.
------ -----------------------------------------------------
[ERROR] Found 1 error
Available as part of the Tidelift Subscription.
The maintainers of roave/no-floaters and thousands of other packages are working with Tidelift to deliver commercial support and maintenance for the open source dependencies you use to build your applications. Save time, reduce risk, and improve code health, while paying the maintainers of the exact dependencies you use. Learn more..
If you need help with setting up this library in your project,
you can contact us at [email protected] for consulting/support.