hashicorp/terraform · error
detected subdirectory path
Error message
detected subdirectory path %q of %q leads outside of the module package
What it means
Returned by parseModuleSourceRemote after go-getter detection: the detector itself produced a subdir (moreSubDir) which, when combined with the user-supplied subdir, starts with '../'. The code notes this would indicate a bug in a go-getter detector; it is caught defensively to prevent confusing downstream behavior. The %q values are the combined subdir and the normalized source.
Solutions
- Drop the user-supplied subdir and let the detector handle it alone, or vice-versa.
- Upgrade go-getter / Terraform to a version with the detector bug fixed.
- Report the source string to the go-getter maintainers with the normalized form from the error.
- Switch to an explicit scheme prefix to bypass the buggy detector.
Example fix
# before (triggers detector subdir escape) source = "github.com/org/repo?ref=v1//../x" # after (no parent traversal) source = "github.com/org/repo//modules/x?ref=v1"
Defensive patterns
Strategy: validation
Validate before calling
// After detector normalization, re-check the combined subdir.
// if strings.HasPrefix(subDir, "../") {
// return fmt.Errorf("detected subdir escapes package; drop user subdir or upgrade go-getter")
// } Try / catch
// Catch detector-induced escapes and retry without the user subdir.
// src, err := parseModuleSourceRemote(raw)
// if err != nil && strings.Contains(err.Error(), "leads outside of the module package") {
// raw2 := raw[:strings.Index(raw, "//")] // strip user subdir
// src, err = parseModuleSourceRemote(raw2)
// } Prevention
- Keep go-getter and Terraform up to date to pick up detector fixes.
- Avoid combining a user subdir with sources whose detectors emit their own subdir.
- Report detector escape bugs upstream with the normalized source from the error.
When it happens
Trigger: A go-getter detector emits a subdir that, joined with the caller's subdir, escapes the package root — e.g. detector returns '..' or the join places a '../' prefix at the start.
Common situations: Bug in a custom or outdated go-getter detector; edge-case source format that triggers an unusual detector subdir; combined subdir logic producing an unexpected prefix.
Related errors
- subdirectory path leads outside of the module package
- Error parsing URL
- can't use local directory
- failed to create directory
- GitHub URLs should be github.com/username/repo
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/b9bb3444d3d32d1f.
Report an issue: GitHub.
Appendix: source
Thrown at internal/getmodules/moduleaddrs/source_parsing.go:209
// more helpful error message.
return addrs.ModuleSourceRemote{}, err
}
if moreSubDir != "" {
switch {
case subDir != "":
// The detector's own subdir goes first, because the
// subdir we were given is conceptually relative to
// the subdirectory that we just detected.
subDir = path.Join(moreSubDir, subDir)
default:
subDir = path.Clean(moreSubDir)
}
if strings.HasPrefix(subDir, "../") {
// This would suggest a bug in a go-getter detector, but
// we'll catch it anyway to avoid doing something confusing
// downstream.
return addrs.ModuleSourceRemote{}, fmt.Errorf("detected subdirectory path %q of %q leads outside of the module package", subDir, norm)
}
}
return addrs.ModuleSourceRemote{
Package: addrs.ModulePackage(norm),
Subdir: subDir,
}, nil
}
View on GitHub (pinned to d32a084675)