gofiber/fiber · error
create file error
Error message
create file error: %w
What it means
addFormFile calls mw.CreateFormFile(fieldName, name) to obtain a part writer for the file content. This wraps a failure of that call, which happens when the multipart writer is already closed or the header cannot be constructed (invalid field/file name characters).
Solutions
- Sanitize fieldName and file name — strip CR/LF and other control characters.
- Do not call any multipart write method after mw.Close(); let parserRequestBodyFile manage the lifecycle.
- Use a deterministic, validated file name rather than raw user input.
Example fix
// before
f.SetName(userSuppliedName)
// after
safe := strings.Map(func(r rune) rune {
if r < 0x20 || r == 0x7f { return -1 }
return r
}, userSuppliedName)
f.SetName(safe) Defensive patterns
Strategy: validation
Validate before calling
func safeMultipartName(s string) string {
return strings.Map(func(r rune) rune {
if r < 0x20 || r == 0x7f { return -1 }
return r
}, s)
}
f.SetName(safeMultipartName(name)) Prevention
- Sanitize field and file names to remove CR/LF and control bytes (header-injection defense).
- Never reuse a multipart writer after Close.
- Avoid concurrent writes to the same multipart writer.
When it happens
Trigger: fieldName or name contains characters that break the Content-Disposition header (newline, control bytes); mw.Close() was already invoked on this writer; the writer's underlying stream errored.
Common situations: User-supplied filenames containing CR/LF (header injection); reusing a multipart writer after close; concurrency on the same writer.
Related errors
- failed to copy file data
- open file error
- boundary generation
- failed to close multipart writer
- rand.Read failed
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/053af4714dc58fe9.
Report an issue: GitHub.
Appendix: source
Thrown at client/hooks.go:318
}
func addFormFile(mw *multipart.Writer, f *File, fileBuf *[]byte) error {
// If reader is not set, open the file.
if f.reader == nil {
var err error
f.reader, err = os.Open(f.path)
if err != nil {
return fmt.Errorf("open file error: %w", err)
}
}
// Ensure the file reader is always closed after copying.
defer f.reader.Close() //nolint:errcheck // not needed
// Create form file and copy the content.
w, err := mw.CreateFormFile(f.fieldName, f.name)
if err != nil {
return fmt.Errorf("create file error: %w", err)
}
if _, err := io.CopyBuffer(w, f.reader, *fileBuf); err != nil {
return fmt.Errorf("failed to copy file data: %w", err)
}
return nil
}
// parserResponseCookie parses the Set-Cookie headers from the response and stores them.
func parserResponseCookie(c *Client, resp *Response, req *Request) error {
var err error
for key, value := range resp.RawResponse.Header.Cookies() {
cookie := fasthttp.AcquireCookie()
if err = cookie.ParseBytes(value); err != nil {
fasthttp.ReleaseCookie(cookie)
break
}View on GitHub (pinned to a105acad6c)