Category
language | stdlib
Problem
ReflectionClass::getMethods() on a child class must not include private methods declared on the parent (php-src filters by declaring-class visibility rules). This compiler lists them today, breaking PHPUnit filters, DI scanners, and serialization metadata that rely on Zend-accurate method sets.
Umbrella/filter flags: #4480. This issue is the inheritance private-leak repro only — implement here or as first slice of #4480.
php-src reference
Repro (failure today — verified 2026-06-07)
<?php
declare(strict_types=1);
class A {
public function pubA(): void {}
protected function protA(): void {}
private function privA(): void {}
public static function statA(): void {}
}
class B extends A {
public function pubB(): void {}
private function privB(): void {}
}
$r = new ReflectionClass(B::class);
$names = array_map(fn ($m) => $m->getName(), $r->getMethods());
sort($names);
var_export($names);
echo "\n";
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh
php repro_reflection_getmethods_private.php > /tmp/zend.txt
php bin/vm.php repro_reflection_getmethods_private.php > /tmp/vm.txt
diff -u /tmp/zend.txt /tmp/vm.txt
'
| Runtime |
$names includes privA? |
| Zend PHP 8.x |
no (parent private hidden on child) |
bin/vm.php |
yes — ['privA','privB','protA','pubA','pubB','statA'] observed |
Scope (this repo)
| Layer |
Path |
| VM reflection |
ext/standard/VmReflection.php — skip parent-private entries when $ce !== declaring class |
| Class tables |
lib/VM/ClassEntry.php method metadata (declaring class + visibility) |
| Tests |
test/compliance/cases/stdlib/reflection_class_getmethods_private.phpt |
PHP-in-PHP: walk CE tables in PHP; no new C reflection shims (#5301).
Done when
Verification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter reflection_class_getmethods_private'
Links
Category
language|stdlibProblem
ReflectionClass::getMethods()on a child class must not include private methods declared on the parent (php-src filters by declaring-class visibility rules). This compiler lists them today, breaking PHPUnit filters, DI scanners, and serialization metadata that rely on Zend-accurate method sets.Umbrella/filter flags: #4480. This issue is the inheritance private-leak repro only — implement here or as first slice of #4480.
php-src reference
ext/reflection/php_reflection.c—zim_ReflectionClass_getMethods,add_reflection_method_subext/reflection/tests/ReflectionClass_getMethods_001.phptRepro (failure today — verified 2026-06-07)
$namesincludesprivA?bin/vm.php['privA','privB','protA','pubA','pubB','statA']observedScope (this repo)
ext/standard/VmReflection.php— skip parent-private entries when$ce !== declaring classlib/VM/ClassEntry.phpmethod metadata (declaring class + visibility)test/compliance/cases/stdlib/reflection_class_getmethods_private.phptPHP-in-PHP: walk CE tables in PHP; no new C reflection shims (#5301).
Done when
var_exportmatches Zend exactly (noprivAonReflectionClass(B::class))privBstill listed; protected/public inherited methods still listed./script/ci-fast.sh --filter reflection_class_getmethods_privategreenVerification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter reflection_class_getmethods_private'Links