{"record":{"id":"a2f6e24f7a5f60cc","repo":"gofiber/fiber","slug":"boundary-generation-w","errorCode":null,"errorMessage":"boundary generation: %w","messagePattern":"boundary generation: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"client/hooks.go","lineNumber":153,"sourceCode":"\n\t// Set Content-Type and Accept headers based on the request body type.\n\tswitch req.bodyType {\n\tcase jsonBody:\n\t\treq.RawRequest.Header.SetContentType(applicationJSON)\n\t\treq.RawRequest.Header.Set(headerAccept, applicationJSON)\n\tcase xmlBody:\n\t\treq.RawRequest.Header.SetContentType(applicationXML)\n\tcase cborBody:\n\t\treq.RawRequest.Header.SetContentType(applicationCBOR)\n\tcase formBody:\n\t\treq.RawRequest.Header.SetContentType(applicationForm)\n\tcase filesBody:\n\t\treq.RawRequest.Header.SetContentType(multipartFormData)\n\t\t// If boundary is default, append a random string to it.\n\t\tif req.boundary == boundary {\n\t\t\trandStr, err := unsafeRandString(16)\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"boundary generation: %w\", err)\n\t\t\t}\n\t\t\treq.boundary += randStr\n\t\t}\n\t\treq.RawRequest.Header.SetMultipartFormBoundary(req.boundary)\n\tdefault:\n\t\t// noBody or rawBody do not require special handling here.\n\t}\n\n\t// Set User-Agent header.\n\treq.RawRequest.Header.SetUserAgent(defaultUserAgent)\n\tif c.userAgent != \"\" {\n\t\treq.RawRequest.Header.SetUserAgent(c.userAgent)\n\t}\n\tif req.userAgent != \"\" {\n\t\treq.RawRequest.Header.SetUserAgent(req.userAgent)\n\t}\n\n\t// Set Referer header.","sourceCodeStart":135,"sourceCodeEnd":171,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/client/hooks.go#L135-L171","documentation":"When the request body type is filesBody and the boundary is still the default, the client appends a 16-character random suffix to make it unique. This error wraps the unsafeRandString failure that produces that suffix — i.e. a rand.Read failure (see errors 85/86).","triggerScenarios":"Uploading files via the client when the OS random source is unavailable; the boundary could not be randomized, so the multipart writer cannot be safely configured for this request.","commonSituations":"Restricted sandboxes/containers without /dev/urandom; getrandom denied by seccomp; embedded early-boot scenarios.","solutions":["Restore access to the OS random source (mount /dev/urandom, allow getrandom).","If you supply your own RFC-compliant boundary (req.SetBoundary), the random-suffix step is skipped and this code path is avoided — but the underlying rand failure indicates a deeper host problem.","Treat as a host-level incident, not a request-level retry."],"exampleFix":"// avoid the random-suffix step by supplying your own boundary\nreq.SetBoundary(\"----GoFiberBoundaryABC123\")","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":["If you cannot rely on the host random source, supply a fixed RFC-compliant boundary via req.SetBoundary to skip the random-suffix path.","Expose /dev/urandom and permit getrandom in containers.","Treat boundary-generation errors as a deployment-blocking host issue."],"tags":["client","multipart","boundary","crypto-rand","upload"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}