gofiber/fiber · error

fiber: failed to shared state value

Error message

fiber: failed to %s shared state %s value: %v

What it means

Sibling of error 240: sharedStateCodecPanicError fires when the codec panics, but the recovered value does NOT implement error (e.g. panic("boom") with a string, or panic(42)). Fiber formats it with %v because there is no error to wrap. This indicates a custom codec that panics with a non-error value, which is itself a code smell in the codec.

Solutions

  1. Find the codec registered for the failing format and convert every panic into a returned error.
  2. Search the codec source for bare panic(...) calls and replace them with fmt.Errorf returns.
  3. Run the codec under a fuzz test that feeds it malformed input to flush out remaining panic paths.

Example fix

// before: codec panics with a string
func decode(b []byte) (any, error) {
    if len(b) == 0 { panic("empty input") }
    ...
}

// after: return an error
func decode(b []byte) (any, error) {
    if len(b) == 0 { return nil, fmt.Errorf("empty input") }
    ...
}
Defensive patterns

Strategy: validation

Validate before calling

// Lint your codec for non-error panics before registering it
func auditCodec(c Codec) error {
    // run against a corpus of inputs under recover; flag any panic
    for _, in := range badInputs {
        func() {
            defer func() { _ = recover() }()
            _, _ = c.Encode(in)
        }()
    }
    return nil
}

Try / catch

// Always recover around third-party codec calls and normalize to error
func callCodec(fn func() error) (err error) {
    defer func() {
        if r := recover(); r != nil {
            if e, ok := r.(error); ok { err = e } else { err = fmt.Errorf("codec panic: %v", r) }
        }
    }()
    return fn()
}

Prevention

When it happens

Trigger: A user-supplied SharedState codec calls panic("something") or panic(someInt) instead of returning an error; the recover() in the encode/decode wrapper catches it and reformats it.

Common situations: Hand-written codec that uses panic for control flow; third-party codec that panics on internal assertion failures; porting a codec from another framework without converting panics to errors.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/717b6edac51f07bc. Report an issue: GitHub.

Appendix: source

Thrown at shared_state.go:413

		return sharedStateCodecPanicError("decode", format, recovered)
	}
	if err != nil {
		return fmt.Errorf("fiber: failed to decode shared state %s value: %w", format, err)
	}

	return nil
}

func sharedStateCodecNotConfiguredError(format, direction string) error {
	return fmt.Errorf("fiber: shared state %s %s is not configured", format, direction)
}

func sharedStateCodecPanicError(operation, format string, recovered any) error {
	if err, ok := recovered.(error); ok {
		return fmt.Errorf("fiber: failed to %s shared state %s value: %w", operation, format, err)
	}

	return fmt.Errorf("fiber: failed to %s shared state %s value: %v", operation, format, recovered)
}

func (s *SharedState) storageKey(key string) (string, bool) {
	if key == "" {
		return "", false
	}

	return s.prefix + hex.EncodeToString(utils.UnsafeBytes(key)), true
}

View on GitHub (pinned to a105acad6c)