{"record":{"id":"f23c8a03a07096c9","repo":"hashicorp/terraform","slug":"invalid-registry-namespace-q-in-provider-matching","errorCode":null,"errorMessage":"invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace","messagePattern":"invalid registry namespace %q in provider matching pattern %q: must either be the wildcard \\* or a literal namespace","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/getproviders/multi_source.go","lineNumber":178,"sourceCode":"\t\t\t\tnormalHost, err := svchost.ForComparison(givenHost)\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn nil, fmt.Errorf(\"invalid hostname in provider matching pattern %q: %s\", str, err)\n\t\t\t\t}\n\n\t\t\t\t// The remaining code below deals only with the namespace/type portions.\n\t\t\t\thost = normalHost\n\t\t\t}\n\n\t\t\tparts = parts[1:]\n\t\t}\n\n\t\tpType, err := normalizeProviderNameOrWildcard(parts[1])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider type %q in provider matching pattern %q: must either be the wildcard * or a provider type name\", parts[1], str)\n\t\t}\n\t\tnamespace, err := normalizeProviderNamespaceOrWildcard(parts[0])\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid registry namespace %q in provider matching pattern %q: must either be the wildcard * or a literal namespace\", parts[1], str)\n\t\t}\n\n\t\tret[i] = addrs.Provider{\n\t\t\tHostname:  host,\n\t\t\tNamespace: namespace,\n\t\t\tType:      pType,\n\t\t}\n\n\t\tif ret[i].Hostname == svchost.Hostname(Wildcard) && !(ret[i].Namespace == Wildcard && ret[i].Type == Wildcard) {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider matching pattern %q: hostname can be a wildcard only if both namespace and provider type are also wildcards\", str)\n\t\t}\n\t\tif ret[i].Namespace == Wildcard && ret[i].Type != Wildcard {\n\t\t\treturn nil, fmt.Errorf(\"invalid provider matching pattern %q: namespace can be a wildcard only if the provider type is also a wildcard\", str)\n\t\t}\n\t}\n\treturn ret, nil\n}\n","sourceCodeStart":160,"sourceCodeEnd":196,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/getproviders/multi_source.go#L160-L196","documentation":"Thrown when the namespace segment (parts[0]) is neither '*' nor accepted by tfaddr.ParseProviderNamespace, which enforces registry namespace naming rules (lowercase, limited character set, length bounds). NOTE: the error message at multi_source.go:178 interpolates parts[1] (the type) into a message about the namespace — the printed %q is the wrong segment; the actual failing value is parts[0] (the namespace).","triggerScenarios":"Patterns like 'HashiCorp/aws' (uppercase namespace), 'my_namespace/aws' (underscore), 'hashi.corp/aws' (dot in namespace), or an empty namespace '*/aws' style misuse. Triggered at multi_source.go:176-178 via normalizeProviderNamespaceOrWildcard -> tfaddr.ParseProviderNamespace.","commonSituations":"Using a namespace with mixed case or punctuation (private registry namespaces sometimes differ from display names); relying on the misleading error text (which shows the type, not the namespace) and 'fixing' the wrong segment; namespaces copied from a URL that include a trailing path.","solutions":["Fix the NAMESPACE segment (parts[0], the segment before the type) to a lowercase registry-legal namespace — be aware the error text misleadingly shows the type.","If you want any namespace, use '*' as the namespace segment.","Re-read the pattern as host?/namespace/type and edit the first non-host segment, not the last.","File/track the message bug separately so future readers are not misled."],"exampleFix":"// before (error text points at 'aws', but the bad segment is the namespace)\ninclude = [\"HashiCorp/aws\"]\n\n// after\ninclude = [\"hashicorp/aws\"]","handlingStrategy":"validation","validationCode":"import tfaddr \"github.com/hashicorp/terraform-registry-address\"\n\nfunc validNamespaceSegment(ns string) error {\n    if ns == \"*\" {\n        return nil\n    }\n    return tfaddr.ParseProviderNamespace(ns)\n}\n\n// NOTE: the library's error message for error 903 prints parts[1] (the TYPE),\n// not the namespace. Validate the namespace (the first non-host segment)\n// yourself and do not trust the printed %q when diagnosing.","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Validate the namespace (segment before the type) with tfaddr.ParseProviderNamespace.","Remember the parser prints the wrong segment in this error — fix the namespace, not the type.","Keep namespaces lowercase and registry-legal."],"tags":["provider-config","pattern","namespace","validation","bug-in-message","multi-source"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}