deprecated tag with an integer message emits invalid PHP
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
Research direction
Start with src/Node/DeprecatedNode.php:61-70 and reproduce the issue using {%deprecated 0%} through the Twig environment shown. Inspect the generated PHP and compare integer, float, and string messages with the behavior described in the issue. Done means integer messages produce valid compiled code or a compile error, without breaking the existing float and string cases.
Written by the indexing model from the issue text.
Description
deprecated tag with an integer message emits invalid PHP
Affected versions: twig/twig 1.36.0 through 3.30.0, and 4.0.0-alpha1. The tag has compiled its message this way since it was introduced in 1.36.0. Verified failing on 3.10.3, 3.11.0, 3.20.0, 3.21.0, 3.30.0, and the 3.x branch.
Verified on: 3.x branch, commit 4241bb73fee837a0afbba8c918a276a727fbfd74 (2026-09-26)
Summary
The deprecated tag compiles its message into a PHP string concatenation. When the message is a constant, the compiler writes the constant, a dot, and a double-quoted string. If the constant is an integer, PHP reads <integer>. as a float literal and the following string is a syntax error. The parser accepts the template, so the failure is a PHP ParseError while the compiled template loads.
Reproduction
Template:
{%deprecated 0%}
Program:
$env = new Twig\Environment(new Twig\Loader\ArrayLoader([]), ['cache' => false]);
$env->createTemplate('{%deprecated 0%}')->render([]);
Observed:
PHP ParseError: syntax error, unexpected double-quoted string " in \"...\", expecting ")"
Compiler output:
trigger_deprecation('', '', 0." in \"candidate\" at line 1.");
Expected vs Actual
| template | expected | actual |
|---|---|---|
{%deprecated 0%} |
valid compiled code, or a compile error for a non-string message | PHP ParseError in generated code |
{%deprecated 4%} |
valid compiled code, or a compile error for a non-string message | PHP ParseError in generated code |
{%deprecated 4.5%} |
valid compiled code for a float message | renders without error |
{%deprecated 'text'%} |
valid compiled code for a string message | renders without error |
Root cause
src/Node/DeprecatedNode.php:61-70 handles a ConstantExpression message by subcompiling the constant at line 62, then emitting ->raw('.') at line 68 and ->string(sprintf(' in "%s" at line %d.', ...)) at line 69. Nothing separates the constant from the dot. src/TokenParser/DeprecatedTokenParser.php:36 accepts any expression as the message. Integer constants fail because PHP lexes <integer>. as a float literal. Float constants, string constants, names, and computed expressions reach other compilation paths and do not fail.
Impact
The compiled template class fails to load on every render of the affected template. A PHP ParseError is not a Twig\Error\Error, so it bypasses Twig error handling and source line mapping. The generated code also embeds the internal template name in the error text. With the compilation cache enabled, Twig writes the invalid PHP before loading and evaluating it, so the failure repeats for that template until the cache is cleared or the source changes. Templates are trusted input by default; the failure affects template authors and applications that compile template source at runtime.
- Dominant language
- PHP
- Stars
- 8.4k
- Forks
- 1.3k
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 49
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from twigphp/Twig
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
twigphp/Twig#4746 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 45/100
twigphp/Twig#4868 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
twigphp/Twig#4788 · 5 reactions ·
Maintainers usually reply within 1 day
Similar issues
-
sync-en
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 2 days
-
P2 testing
Difficulty 1/5 Under an hour Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
1.severity: security
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Automattic/static-site-importer#1879 ·
Maintainers usually reply within 1 day
-
bug Installation / Upgrade
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day