It might be worse (or equally bad) than symlink returning true dishonestly:
From:
http://www.hardened-php.net/suhosin/configuration.html
Quote:suhosin.executor.func.blacklist
Type: String
Default:
Comma separated blacklist of functions that are not allowed to be called. If no whitelist is given, calling a function within the blacklist will terminate the script and get logged.
It seems suhosin doesn't even provide a simple way to see if a function is blacklisted either. So basically if your app uses suhosin blacklisted functions, you could as well just not install the app rather than install suhosin, since suhosin's approach is basically just to break the app anyway.
Below is a link to some code to do the check but good grief, should every php script check every function before calling it? I would think suhosin should play nicer and/or people should use it at their own risk:
https://github.com/swznd/CodeIgniter/commit/c9da86f4c47e49a47df782455ef2c6118d1ba879
Edit:
and/but here is the security issue with symbolic links:
http://www.hardened-php.net/advisory_082006.132.html
I'm not sure but it seems to me that this exploit already assumes the attacker has taken (or been given) control of your php environment to some extent and this is an escalation.