Fix/caller import leak - #457
Open
arcticfulmar wants to merge 2 commits into
Open
arcticfulmar wants to merge 2 commits into
arcticfulmar wants to merge 2 commits into
Conversation
arcticfulmar
force-pushed
the
fix/caller-import-leak
branch
from
September 26, 2026 02:42
0925df7 to
bcd93a2
Compare
A native hint like `Event $event` was seeded into scope as the raw spelling, so the class it named depended on whoever read it later: a bare name reached a global class of that name before the file's own namespace. In `Illuminate\Console\Scheduling` that turned every use of `$event` into "not found on class 'Event'" and every hand-off into a type mismatch. Method and closure parameter hints are now qualified against the file's imports and namespace when they are seeded, as `@param` tags already were. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The argument check looked up the callee's parameter types through the calling file's class loader, which reads a bare name as one written in that file. A global function typed `context $context`, called from a file with `use App\context;` (or from a namespace declaring its own `context`), was checked against `App\context` and rejected a valid argument. The same applied to a value typed by another file, such as the global `context` returned from a global function. Parameter types and already-qualified argument types are now looked up by their fully-qualified names, so only the caller's own unresolved spellings go through its imports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
arcticfulmar
force-pushed
the
fix/caller-import-leak
branch
from
September 28, 2026 17:45
bcd93a2 to
bfa6e39
Compare
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Caller's imports no longer rename another file's types
A global function such as
is_enrolled(context $context)refers to the global\context. When the calling file imported an unrelated class with the same short name (e.g.use App\context;), or declared one in its own namespace, the argument check lookedcontextup through the caller's imports. This produces a falsetype_mismatch_argument.I found this when using phpantom on a Moodle codebase where namespaced plugin code sometimes imports its own
contextclass (e.g.local_plugin\context) and can also call the core Moodle class (\context).Commits
@paramtags already were. Before, a bare name could land on a global class of the same name. Inlaravel/framework'sConsole/Scheduling,Event $eventwas read as the globalEvent, which produced 48 false positives (unknown_memberandtype_mismatch_argument).usestatements and namespace no longer rename them. This also covers values returned from another file's functions. It depends on the first commit - on its own it would reject arguments whose native hint was still unresolved.As a side effect, passing an
App\contextwhere the globalcontextis expected is now reported. It was silently accepted before.Testing
diagnostics_unknown_members.rs(commit 1) and six indiagnostics_type_errors.rs(commit 2).semantic-export) and fmt pass on each commit.analyzeonexamples/phpandexamples/laravelgives the same output asmain.laravel/frameworkagainst a real Laravel 13 install, the only changes frommainare the 48 false positives removed and one message now naming the correct globalStringable.main, from 9% faster to 6% slower.Checklist
If applicable:
CHANGELOG.mdREADME.md,docs/,examples/)config-schema.json)how it works, how it's organized), including any code drafted by an LLM.
an eye towards deleting anything that is irrelevant, clarifying anything
that is confusing, and adding details that are relevant. This includes,
for example, commit descriptions, PR descriptions, and code comments.
🤖 Generated with Claude Code
🤓 Reviewed and tweaked by @arcticfulmar