Tim Düsterhus
@heiglandreas@phpc.social @kleisli@mastodon.social @naderman@phpc.social @OndrejMirtes@phpc.social @markusstaab@phpc.social @toflar@phpc.social
And not to throw shade on them, since they already do SLSA attestations (https://github.com/PHPCSStandards/PHP_CodeSniffer/attestations) but I quite enjoyed that @phpcs@phpc.social apparently rotated their PGP key for their 4.0.2 security release: https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2
The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F778BF9BC4FB67AE511D96E91A992CF22FF4.
@nyamsprod@phpc.social Okay, the Overflow remark was ambiguous, I suppose:
- Negative inputs are a programmer error (thus ValueError) - for now at least.
- Out-of-range nanoseconds is also a programmer error.
The TimeException only applies to overflow of the entire range (i.e. an overflow in seconds).
I also suggest to test with fromHours(PHP_INT_MAX). This will likely throw a TypeError internally, because of the int->double overflow. This should also be TimeException.
@nyamsprod@phpc.social is_int() is probably fine.
The exception types are not quite correct, still: $seconds >= self::MAX_SECONDS must be a TimeException (overflow). $seconds < 0 must be a ValueError (programmer error). The handling for $nanoseconds is correct.
The error message for !is_int() should be consistent with $seconds >= self::MAX_SECONDS, because !is_int() effectively means that $seconds >= self::MAX_SECONDS.