{"record":{"id":"b9b59f4ac8bbc598","repo":"hashicorp/terraform","slug":"invalid-hostname-in-provider-matching-pattern-q","errorCode":null,"errorMessage":"invalid hostname in provider matching pattern %q: %s","messagePattern":"invalid hostname in provider matching pattern %q: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/multi_source.go","lineNumber":162,"sourceCode":"\t\treturn nil, nil\n\t}\n\n\tret := make(MultiSourceMatchingPatterns, len(strs))\n\tfor i, str := range strs {\n\t\tparts := strings.Split(str, \"/\")\n\t\tif len(parts) < 2 || len(parts) > 3 {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider matching pattern %q: must have either two or three slash-separated segments\", str)\n\t\t}\n\t\thost := defaultRegistryHost\n\t\texplicitHost := len(parts) == 3\n\t\tif explicitHost {\n\t\t\tgivenHost := parts[0]\n\t\t\tif givenHost == \"*\" {\n\t\t\t\thost = svchost.Hostname(Wildcard)\n\t\t\t} else {\n\t\t\t\tnormalHost, err := svchost.ForComparison(givenHost)\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn nil, fmt.Errorf(\"invalid hostname in provider matching pattern %q: %s\", str, err)\n\t\t\t\t}\n\n\t\t\t\t// The remaining code below deals only with the namespace/type portions.\n\t\t\t\thost = normalHost\n\t\t\t}\n\n\t\t\tparts = parts[1:]\n\t\t}\n\n\t\tpType, err := normalizeProviderNameOrWildcard(parts[1])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name\", parts[1], str)\n\t\t}\n\t\tnamespace, err := normalizeProviderNamespaceOrWildcard(parts[0])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace\", parts[1], str)\n\t\t}\n","sourceCodeStart":144,"sourceCodeEnd":180,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/multi_source.go#L144-L180","documentation":"Thrown when a 3-segment pattern has a host segment that is not '*' and fails svchost.ForComparison normalization. svchost.ForComparison applies IDNA/punycode normalization and rejects hostnames with invalid characters, bad punycode labels, or other RFC 1035 violations. The wrapped %s is the underlying svchost error.","triggerScenarios":"A 3-segment pattern whose first segment is not '*' and is malformed: e.g. 'exam_ple.com/hashicorp/aws', 'has space.com/hashicorp/aws', 'xn--invalid punycode/hashicorp/aws', or a host with an underscore label. Triggered at multi_source.go:160-162 when svchost.ForComparison(givenHost) returns err.","commonSituations":"Pointing a mirror/include pattern at a private registry hostname that contains underscores or other non-DNS characters; pasting a hostname with a trailing dot or port; copy-paste introducing a space or non-ASCII character; an internal registry whose DNS name uses characters svchost rejects.","solutions":["Correct the hostname to a valid DNS name (letters, digits, hyphens, dots) matching what svchost.ForComparison accepts.","Use '*' as the host segment if you want any host, but remember that forces '*/*' for namespace and type.","Test the host alone with svchost.ForComparison(host) to surface the exact normalization error before wiring it into a pattern.","Drop the host segment entirely (use a 2-segment pattern) if the default registry host is what you meant."],"exampleFix":"// before\ninclude = [\"artifacts_acme.corp/hashicorp/aws\"]\n\n// after\ninclude = [\"artifacts-acme.corp/hashicorp/aws\"]","handlingStrategy":"validation","validationCode":"import svchost \"github.com/hashicorp/terraform-svchost\"\n\nfunc validHostSegment(host string) error {\n    if host == \"*\" {\n        return nil\n    }\n    if _, err := svchost.ForComparison(host); err != nil {\n        return fmt.Errorf(\"invalid host %q: %w\", host, err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Pre-validate any explicit host segment with svchost.ForComparison before parsing patterns.","Restrict hostnames to DNS-legal characters (no underscores, spaces, ports).","Prefer naming concrete hosts over wildcarding."],"tags":["provider-config","hostname","svchost","validation","multi-source"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}