A class `com.shop.Order` sits, correctly compiled, inside `out/com/shop/Order.class`, and `java -cp out com.shop.Order` runs it fine. The team then adds JPMS modules to the build, and the exact same class, at the exact same resolvable path, suddenly throws an `IllegalAccessError` from another module's code that references it. What changed, given that the classloader lookup mechanism itself didn't?
Two separate questions got conflated: can the class be found, and is the caller permitted to reference it. The classloader's job — turning com.shop.Order into the resource path com/shop/Order.class and searching for it on the classpath — didn't change and isn't what's failing; that lookup still succeeds exactly as before. What's new is JPMS's own separate gate: since Java 9, a module's module-info.java has to exports a package before another module's code is allowed to reference a class in it, and that's a permission check layered on top of the lookup, not a change to how the lookup itself works. The class is present and locatable; the module simply never declared that package as exported, so referencing it from outside the module is rejected even though finding it would have succeeded.