hashicorp/terraform · error

detected subdirectory path

Error message

detected subdirectory path %q of %q leads outside of the module package

What it means

Returned by parseModuleSourceRemote after go-getter detection: the detector itself produced a subdir (moreSubDir) which, when combined with the user-supplied subdir, starts with '../'. The code notes this would indicate a bug in a go-getter detector; it is caught defensively to prevent confusing downstream behavior. The %q values are the combined subdir and the normalized source.

Solutions

  1. Drop the user-supplied subdir and let the detector handle it alone, or vice-versa.
  2. Upgrade go-getter / Terraform to a version with the detector bug fixed.
  3. Report the source string to the go-getter maintainers with the normalized form from the error.
  4. Switch to an explicit scheme prefix to bypass the buggy detector.

Example fix

# before (triggers detector subdir escape)
source = "github.com/org/repo?ref=v1//../x"

# after (no parent traversal)
source = "github.com/org/repo//modules/x?ref=v1"
Defensive patterns

Strategy: validation

Validate before calling

// After detector normalization, re-check the combined subdir.
// if strings.HasPrefix(subDir, "../") {
//     return fmt.Errorf("detected subdir escapes package; drop user subdir or upgrade go-getter")
// }

Try / catch

// Catch detector-induced escapes and retry without the user subdir.
// src, err := parseModuleSourceRemote(raw)
// if err != nil && strings.Contains(err.Error(), "leads outside of the module package") {
//     raw2 := raw[:strings.Index(raw, "//")] // strip user subdir
//     src, err = parseModuleSourceRemote(raw2)
// }

Prevention

When it happens

Trigger: A go-getter detector emits a subdir that, joined with the caller's subdir, escapes the package root — e.g. detector returns '..' or the join places a '../' prefix at the start.

Common situations: Bug in a custom or outdated go-getter detector; edge-case source format that triggers an unusual detector subdir; combined subdir logic producing an unexpected prefix.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/b9bb3444d3d32d1f. Report an issue: GitHub.

Appendix: source

Thrown at internal/getmodules/moduleaddrs/source_parsing.go:209

		// more helpful error message.
		return addrs.ModuleSourceRemote{}, err
	}

	if moreSubDir != "" {
		switch {
		case subDir != "":
			// The detector's own subdir goes first, because the
			// subdir we were given is conceptually relative to
			// the subdirectory that we just detected.
			subDir = path.Join(moreSubDir, subDir)
		default:
			subDir = path.Clean(moreSubDir)
		}
		if strings.HasPrefix(subDir, "../") {
			// This would suggest a bug in a go-getter detector, but
			// we'll catch it anyway to avoid doing something confusing
			// downstream.
			return addrs.ModuleSourceRemote{}, fmt.Errorf("detected subdirectory path %q of %q leads outside of the module package", subDir, norm)
		}
	}

	return addrs.ModuleSourceRemote{
		Package: addrs.ModulePackage(norm),
		Subdir:  subDir,
	}, nil
}

View on GitHub (pinned to d32a084675)