{"record":{"id":"0f5a9def078ce5cd","repo":"hashicorp/terraform","slug":"provider-mirror-returned-invalid-url-q-s","errorCode":null,"errorMessage":"provider mirror returned invalid URL %q: %s","messagePattern":"provider mirror returned invalid URL %q: (.+?)","errorType":"http","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/http_mirror_source.go","lineNumber":224,"sourceCode":"\tif err := dec.Decode(&bodyContent); err != nil {\n\t\treturn PackageMeta{}, s.errQueryFailed(provider, fmt.Errorf(\"invalid response content from mirror server: %s\", err))\n\t}\n\n\tarchiveMeta, ok := bodyContent.Archives[target.String()]\n\tif !ok {\n\t\treturn PackageMeta{}, ErrPlatformNotSupported{\n\t\t\tProvider:  provider,\n\t\t\tVersion:   version,\n\t\t\tPlatform:  target,\n\t\t\tMirrorURL: s.baseURL,\n\t\t}\n\t}\n\n\trelURL, err := url.Parse(archiveMeta.RelativeURL)\n\tif err != nil {\n\t\treturn PackageMeta{}, s.errQueryFailed(\n\t\t\tprovider,\n\t\t\tfmt.Errorf(\"provider mirror returned invalid URL %q: %s\", archiveMeta.RelativeURL, err),\n\t\t)\n\t}\n\tabsURL := finalURL.ResolveReference(relURL)\n\n\tret := PackageMeta{\n\t\tProvider:       provider,\n\t\tVersion:        version,\n\t\tTargetPlatform: target,\n\n\t\tLocation: PackageHTTPURL(absURL.String()),\n\t\tFilename: path.Base(absURL.Path),\n\t}\n\t// A network mirror might not provide any hashes at all, in which case\n\t// the package has no source-defined authentication whatsoever.\n\tif len(archiveMeta.Hashes) > 0 {\n\t\thashes := make([]Hash, 0, len(archiveMeta.Hashes))\n\t\tfor _, hashStr := range archiveMeta.Hashes {\n\t\t\thash, err := ParseHash(hashStr)","sourceCodeStart":206,"sourceCodeEnd":242,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/http_mirror_source.go#L206-L242","documentation":"From a 200 JSON response, the mirror's `archives[target].relative_url` is parsed with `url.Parse`. If parsing fails (control characters, invalid escapes, malformed URL), the error names the offending value and the parse error.","triggerScenarios":"`url.Parse(archiveMeta.RelativeURL)` returns a non-nil `err`; error wrapped at http_mirror_source.go:224.","commonSituations":"Mirror operator entered a bad `relative_url` (spaces, backslashes, control chars); encoding issue when serialising the JSON; mirror builds URLs by unescaped string concatenation.","solutions":["Inspect the `relative_url` value in the served JSON for illegal characters.","Publish corrected URLs in the mirror index.","Use absolute URLs if the mirror supports them, or ensure relative URLs are valid `path` references."],"exampleFix":"// before\n{\"url\":\"C:\\\\providers\\\\aws.zip\"}\n// after\n{\"url\":\"hashicorp/aws/terraform-provider-aws_4.50.0_linux_amd64.zip\"}","handlingStrategy":"validation","validationCode":"// Validate the URL field before consuming it\nu, err := url.Parse(archiveMeta.RelativeURL)\nif err != nil {\n    return fmt.Errorf(\"mirror served bad relative_url %q: %w\", archiveMeta.RelativeURL, err)\n}\nif !u.IsAbs() && !strings.HasPrefix(u.Path, \"/\") {\n    // ensure resolvable relative reference\n}","typeGuard":"// isValidRelativeURL narrows to parseable URL strings\nfunc isValidRelativeURL(s string) bool {\n    _, err := url.Parse(s)\n    return err == nil\n}","tryCatchPattern":"rel, err := url.Parse(archiveMeta.RelativeURL)\nif err != nil {\n    // fall back to constructing the URL from a known pattern\n    rel, _ = url.Parse(fmt.Sprintf(\"%s/%s/%s/%s.zip\", provider.Namespace, provider.Type, version, target))\n}","preventionTips":["Generate mirror URLs with a single template, not string concatenation.","URL-encode all components.","Test served URLs with `curl`.","Reject non-conformant URLs in mirror build tooling."],"tags":["network","mirror","url-parse","registry"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}