feat(extraction): PHP string/array callables + Ruby lifecycle-hook symbols (#811)

The last two deferred callback-registration shapes from #756, each scoped
to positions where the reference is trustworthy:

PHP — a string is a callable ONLY in a known callable position:
  - string args of core HOFs (usort, array_map, array_filter,
    call_user_func*, preg_replace_callback, spl_autoload_register,
    set_error_handler, … — PHP_CALLABLE_HOFS): ungated (PHP globals are
    referenced cross-file without imports) + resolution unique-or-drop,
    function-kind only ('Cls::m' strings resolve qualified)
  - array callables anywhere in call args: [$this, 'method'] routes through
    the class-scoped this. resolver (parents included); [Foo::class,
    'method'] resolves qualified
  - strings to arbitrary functions: deliberately nothing

Ruby — hook-DSL symbols name a method of the enclosing class:
  (skip_)?(before|after|around)_* / validate / set_callback /
  helper_method / rescue_from(with:) symbols → class-scoped this.<sym>,
  riding the supertype pass so `before_action :authenticate` in a
  controller resolves to ApplicationController's method. `validates`
  (plural) excluded — its symbols name ATTRIBUTES. Class-body-level hooks
  attribute to the CLASS node (the scoped resolvers now accept class-like
  from-nodes).

Also hardened while validating: the this.X supertype pass is now
NODE-anchored — file-anchored class node → implements/extends edge targets
→ contains-anchored member lookup — replacing the name-keyed
getSupertypes walk, which unioned every same-named class's parents (rails
has a dozen `Engine`s) and produced a cross-class wrong edge.

A/B vs main: WordPress +556 (14/14 sampled genuine — [$this,'m'] wiring,
array_map('absint',…), sodium polyfill call_user_func_array dispatch);
rails/rails +385 after the node-anchored fix (16/16 sampled genuine, incl.
inherited hooks across real extends edges); controls byte-stable
(excalidraw 0-delta, redis identical, typeorm keeps its +4 inherited
getters). The only calls-edge deltas anywhere are pre-existing
minified-bundle resolution jitter (wp-tinymce.js single-letter symbols).

Full suite 1391 passed. EXTRACTION_VERSION 21 → 22 (re-index to benefit).

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Colby Mchenry
2026-06-11 15:30:29 -05:00
committed by GitHub
co-authored by Claude Opus 4.8
parent 38095aa95b
commit 1f15f93feb
8 changed files with 353 additions and 54 deletions
+9 -4
View File
@@ -454,15 +454,18 @@ export class TreeSitterExtractor {
// segment — the simple name Java/Kotlin code uses in `OtherClass::method`
// references.
const SIMPLE_NAME = /^[A-Za-z_$][A-Za-z0-9_$]*$/;
const DOTTED_NAME = /^[A-Za-z_$][A-Za-z0-9_$.]*\.([A-Za-z_$][A-Za-z0-9_$]*)$/;
// JVM imports are dotted (`com.example.OtherClass`); PHP `use` imports
// are backslashed (`App\Services\Mailer`). Both contribute their last
// segment — the simple name code uses to reference them.
const QUALIFIED_IMPORT = /^[A-Za-z_$][A-Za-z0-9_$.\\]*[.\\]([A-Za-z_$][A-Za-z0-9_$]*)$/;
const importedNames = new Set<string>();
for (const r of this.unresolvedReferences) {
if (r.referenceKind !== 'imports') continue;
if (SIMPLE_NAME.test(r.referenceName)) {
importedNames.add(r.referenceName);
} else {
const dotted = r.referenceName.match(DOTTED_NAME);
if (dotted) importedNames.add(dotted[1]!);
const qualified = r.referenceName.match(QUALIFIED_IMPORT);
if (qualified) importedNames.add(qualified[1]!);
}
}
@@ -497,7 +500,9 @@ export class TreeSitterExtractor {
// (constant-expression context — see FnRefSpec.ungatedModes).
// - everything else: name ∈ same-file functions/methods ∪ imports.
if (!c.name.startsWith('this.')) {
const skipGate = ungated?.has(c.mode) === true && atFileScope;
const skipGate =
(ungated?.has(c.mode) === true && atFileScope) ||
c.skipGate === true; // PHP HOF-position string callables (see FnRefCandidate.skipGate)
if (!skipGate) {
if (c.name.includes('::')) {
const scopeName = c.name.slice(0, c.name.indexOf('::'));