Skip to content

Document the Twig conflict when an application loads its own Twig - #2688

Open
Sharawey74 wants to merge 2 commits into
simplesamlphp:masterfrom
Sharawey74:bug/release-deprecated-twig-includes
Open

Sharawey74 wants to merge 2 commits into
simplesamlphp:masterfrom
Sharawey74:bug/release-deprecated-twig-includes

Conversation

@Sharawey74

@Sharawey74 Sharawey74 commented Oct 2, 2026 •

Copy link
Copy Markdown

Fixes #2687

As discussed above, this PR no longer changes the release build or the vendor/ directory. It is now a documentation change only.

Change

A short section, "Applications that use Twig themselves", at the end of "Integrating authentication with your own application" in docs/simplesamlphp-sp.md, which is where an application loads SimpleSAMLphp's autoloader. It covers:

  • the symptom: PHP Fatal error: Cannot redeclare function twig_cycle();
  • the cause: the application loads its own copy of Twig and then the autoloader of a release archive, so two copies of Twig are in the same PHP process. Twig 3 declares a few deprecated global functions in each copy, so this happens even when both copies are the same version;
  • the two ways to avoid it, as suggested in the review:
    • install SimpleSAMLphp as a Composer dependency of the application (composer require simplesamlphp/simplesamlphp), so Composer installs one Twig for both;
    • run the application and SimpleSAMLphp in different PHP-FPM pools. The docs note that this only works when the application does not load SimpleSAMLphp's autoloader itself, since the example in that section does.

The release-workflow step from the first commit is reverted, so the diff against master is only the documentation (+29 lines in one file).

Checks

  • markdownlint with the repository's .markdownlintrc passes on the changed file.

Twig autoloads four files that only declare deprecated global functions such as twig_cycle(). SimpleSAMLphp does not use them, but when an application that embeds SimpleSAMLphp loads its own copy of Twig, the second copy fails with "Cannot redeclare function twig_cycle()".

Drop these includes from the generated Composer autoloader when the release tarballs are built, and fail the build if any are left.

Fixes simplesamlphp#2687
Copilot AI balanced review requested due to automatic review settings October 2, 2026 17:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@tvdijen

tvdijen commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

I'm not sure I follow.. Is the problem you're trying to fix here that SimpleSAMLphp and your application use different versions of Twig?
Messing with files in the vendor-directory is never the solution

@Sharawey74

Copy link
Copy Markdown
Author

I'm not sure I follow.. Is the problem you're trying to fix here that SimpleSAMLphp and your application use different versions of Twig? Messing with files in the vendor-directory is never the solution

Not quite, it's two copies of Twig in the same PHP process, even with the same version. In the issue, the application loads Debian's Twig from /usr/share/php/Twig and the tarball brings its own in vendor/. Twig's src/Resources/*.php files declare global functions such as twig_cycle() without a function_exists() guard, so the second autoloader to include them fails with "Cannot redeclare". Twig won't change that in 3.x (twigphp/Twig#4180 was closed; the functions are removed in Twig 4).

I agree that editing vendor/ is not nice; I followed the solution proposed in #2687. If you prefer, I can drop the build change and instead document that an application with its own Twig should install SimpleSAMLphp with Composer rather than use the tarball, so only one Twig is loaded. @jornane, does that work for your setup?

@tvdijen

tvdijen commented Oct 5, 2026

Copy link
Copy Markdown
Member

If you prefer, I can drop the build change and instead document that an application with its own Twig should install SimpleSAMLphp with Composer rather than use the tarball, so only one Twig is loaded. @jornane, does that work for your setup?

To me this would be the preferred solution, yes. Either this, or you could run your application and SimpleSAMLphp in different PHP-FPM pools so they don't interfere?
Jorn is familiar with this project, so we should be able to work something out together without dirty hacks.

As discussed in the PR, editing files in vendor/ is not the way to solve this.
Revert the release-workflow step and document the problem instead.

An application that loads its own copy of Twig and then the autoloader of a
SimpleSAMLphp release archive gets two copies of Twig in one PHP process, and
PHP stops with "Cannot redeclare function twig_cycle()". The SP integration
docs now explain the error and the two ways to avoid it: install SimpleSAMLphp
as a Composer dependency of the application, or run the application and
SimpleSAMLphp in different PHP-FPM pools.

Fixes simplesamlphp#2687
@Sharawey74 Sharawey74 changed the title Remove deprecated Twig includes from the release autoloader Document the Twig conflict when an application loads its own Twig Oct 8, 2026
@Sharawey74

Copy link
Copy Markdown
Author

If you prefer, I can drop the build change and instead document that an application with its own Twig should install SimpleSAMLphp with Composer rather than use the tarball, so only one Twig is loaded. @jornane, does that work for your setup?

To me this would be the preferred solution, yes. Either this, or you could run your application and SimpleSAMLphp in different PHP-FPM pools so they don't interfere? Jorn is familiar with this project, so we should be able to work something out together without dirty hacks.

As suggested, I've dropped the build change and turned this into a documentation update: a short section in the SP integration docs about the "Cannot redeclare twig_cycle()" error, with both options, installing SimpleSAMLphp with Composer or running it in a separate PHP-FPM pool. @jornane, happy to adjust if your setup needs more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release tarball contains deprecated Twig includes

3 participants