Skip to content

fix(php): preserve known-self calls alongside construct filtering - #4119

Closed
xiehuanyi wants to merge 1 commit into
Graphify-Labs:v8from
xiehuanyi:test/php-construct-binding-boundaries
Closed

xiehuanyi wants to merge 1 commit into
Graphify-Labs:v8from
xiehuanyi:test/php-construct-binding-boundaries

fix(php): resolve builtin-named methods on known self receivers

aca5651
Select commit
Loading
Failed to load commit list.
Graphify Labs / Graphify succeeded Oct 5, 2026 in 1m 17s

Graphify — worth a look

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.

Details

Graphify reviewed this change.

Worth a look — the grounded gate found no coupling regressions or blocking issues, but 2 advisory finding(s) below merit a look before merge.


Graphify review — findings

Resolves PHP $this->name() calls whose method name collides with a language construct or builtin (list, die, open, …) to the caller's own class method through _self_call_target, matching PHP's case-insensitive method names. The new require_method_owner flag drops the bare-label fallback, so these calls never bind to a free function or another class's method. Without an enclosing class the call stays unresolved, and keyword uses like list($x) = … still produce no edge.

Worth a look

  • PHP owner-required self calls can still fall back to an unrelated class method — graphify/extractors/engine.py:1438 · Escalate · high
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
  • PHP method table is casefolded but non-builtin $this lookups are not — graphify/extractors/engine.py:7367 · Escalate · medium
    • agreed by 2 of 2 members but NOT verified (no proof, no reproducing execution) — consensus is not a verdict; needs human review
Analysis details — impact, health, verification

Impact & health

Graphify review

Impact — 812 functions depend on the 288 functions this change touches.

Health — this change adds coupling hotspots:

  • new: _extract_generic() — 18 callers, 31 callees
  • new: extract_js() — 87 callers, 4 callees
  • new: extract_xaml() — 19 callers, 17 callees
  • new: extract_objc() — 27 callers, 9 callees
  • new: extract_julia() — 19 callers, 7 callees
  • new: extract_svelte() — 14 callers, 7 callees
  • new: extract_cpp() — 32 callers, 3 callees
  • new: extract_vue() — 10 callers, 7 callees
  • …and 10 more — each is listed as a finding

Verification — 812 functions in the blast radius were not formally verified this run (proofs are advisory here).

Gate & verification

graphify gate

PASS — objectively clean (no health regressions, tests not run — proofs not run this pass (advisory)). Grounded, not self-assessed.

Advisory (not blocking):

  • verification_scope: 721 function(s) in the blast radius were not formally verified this run

Test selection

Test selection

30 of 329 test file(s) selected (9%) via static blast radius.

  • tests/test_astro_extraction.py — impact
  • tests/test_build.py — impact
  • tests/test_cjs_module_extension.py — impact
  • tests/test_cpp_nested_and_cli.py — impact
  • tests/test_dotnet.py — impact
  • tests/test_extract.py — impact
  • tests/test_extract_php_closures.py — impact
  • tests/test_import_extension_resolution.py — impact
  • tests/test_indirect_call_block_scoped_shadow.py — impact
  • tests/test_indirect_dispatch.py — impact
  • tests/test_indirect_dispatch_assign_return.py — impact
  • tests/test_indirect_dispatch_getattr.py — impact
  • tests/test_js_exported_scalar_bindings.py — impact
  • tests/test_languages.py — impact
  • tests/test_multilang.py — impact
  • tests/test_php_language_construct_calls.py — impact, changed-test
  • tests/test_python_underscore_resolution.py — impact
  • tests/test_rationale.py — impact
  • tests/test_ruby_resolution.py — impact
  • tests/test_scala_context_bounds.py — impact
  • tests/test_scala_self_type.py — impact
  • tests/test_scala_top_level_binding.py — impact
  • tests/test_scala_type_definition.py — impact
  • tests/test_svelte_extraction.py — impact
  • tests/test_swift_computed_properties.py — impact
  • tests/test_swift_protocol_requirements.py — impact
  • tests/test_trailing_newline_not_a_syntax_error.py — impact
  • tests/test_ts_new_expression_calls.py — impact
  • tests/test_typescript_module_extensions.py — impact
  • tests/test_vue_extraction.py — impact

Selection is safe under the controlled-regression assumption; always-run tests + a periodic full run are the backstops. Advisory — it never changes the check verdict.