01 · Installer fails with Twig 3.30: EscaperRuntime::escape() receives null for $autoescape¶
| Project | Drupal core |
| Component | theme system |
| Category | Bug report |
| Priority | Critical |
| Status | Reported upstream as #3625969 and fixed in Drupal core 11.4.8 (not reproducible with Twig 3.30.0, tested 2026-09-28); do not file |
Already reported: Twig's 3.30 TypeError: Twig Runtime EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given (#3625969) describes the same error and cause. Nothing to file; this page documents what we saw.
Problem/Motivation¶
With Twig 3.30.0 (released 2026-09-25), the very first page of the Drupal installer fails:
TypeError: Twig\Runtime\EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given
Twig 3.30 calls the escaper runtime directly during auto-escaping ($this->escaper->escape(...)). Core redirects the escape filter to drupal_escape through a node visitor, which has a different signature, so the new call path passes null.
Every installation without a lock file is affected, because Composer resolves the newest Twig.
Steps to reproduce¶
composer create-project drupal/cms(or any Drupal 11.4 project) without a lock file, so Twig 3.30.0 is installed.- Open the site in a browser.
- The installer's first page shows the TypeError above.
Proposed resolution¶
Make core's escaping compatible with Twig 3.30's direct runtime call (accept/normalise the new arguments), or add a conflict with twig/twig >=3.30 until that is done.
Remaining tasks¶
- Confirm with Twig 3.30.x.
- Patch + test.
Additional information¶
Workaround used in the German Drupal CMS installer: Twig is constrained to >=3.28 <3.30.
Copy to drupal.org
Issue title:
Installer fails with Twig 3.30: EscaperRuntime::escape() receives null for $autoescape
Issue summary (paste it into the "Issue summary" field; project, component, category and priority are in the table above):
<blockquote>
<p>Already reported: <a href="https://www.drupal.org/node/3625969">Twig's 3.30 TypeError: Twig Runtime EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given</a> (#3625969) describes the same error and cause. Nothing to file; this page documents what we saw.</p>
</blockquote>
<h3 id="summary-problem-motivation">Problem/Motivation</h3>
<p>With Twig 3.30.0 (released 2026-09-25), the very first page of the Drupal installer fails:</p>
<code>TypeError: Twig\Runtime\EscaperRuntime::escape(): Argument #4 ($autoescape) must be of type bool, null given</code>
<p>Twig 3.30 calls the escaper runtime directly during auto-escaping (<code>$this->escaper->escape(...)</code>). Core redirects the <code>escape</code> filter to <code>drupal_escape</code> through a node visitor, which has a different signature, so the new call path passes <code>null</code>.</p>
<p>Every installation without a lock file is affected, because Composer resolves the newest Twig.</p>
<h3 id="summary-steps-reproduce">Steps to reproduce</h3>
<ol>
<li><code>composer create-project drupal/cms</code> (or any Drupal 11.4 project) without a lock file, so Twig 3.30.0 is installed.</li>
<li>Open the site in a browser.</li>
<li>The installer's first page shows the TypeError above.</li>
</ol>
<h3 id="summary-proposed-resolution">Proposed resolution</h3>
<p>Make core's escaping compatible with Twig 3.30's direct runtime call (accept/normalise the new arguments), or add a conflict with <code>twig/twig >=3.30</code> until that is done.</p>
<h3 id="summary-remaining-tasks">Remaining tasks</h3>
<ul>
<li>Confirm with Twig 3.30.x.</li>
<li>Patch + test.</li>
</ul>
<h3>Additional information</h3>
<p>Workaround used in the German Drupal CMS installer: Twig is constrained to <code>>=3.28 <3.30</code>.</p>