hashicorp/terraform · error

error parsing Git SSH URL

Error message

error parsing Git SSH URL: %s

What it means

Returned when parsing an SCP-style Git SSH URL: after splitting host/user/path, url.ParseQuery fails on the substring after '?' in the path. The constructed url.URL already has scheme/user/host/path set; only the query fragment is invalid. The %s is the ParseQuery error.

Solutions

  1. Drop the query portion from SCP-style SSH addresses; use a branch/tag via the module source subdir or a separate ref mechanism instead.
  2. URL-encode the query string if a query is genuinely needed.
  3. Switch to the full ssh:// URL form which is parsed more predictably.

Example fix

# before (malformed query on SCP shorthand)
source = "git@github.com:org/repo?ref=fea ture"

# after
source = "git::ssh://git@github.com/org/repo.git?ref=feature"
Defensive patterns

Strategy: validation

Validate before calling

// Validate the query portion of an SCP-style SSH address before handing it off.
// func validSCPQuery(path string) error {
//     if i := strings.IndexByte(path, '?'); i >= 0 {
//         if _, err := url.ParseQuery(path[i+1:]); err != nil { return err }
//     }
//     return nil
// }

Prevention

When it happens

Trigger: A git SSH shorthand like 'git@host:path?bad=%%query' contains a malformed query string (unencoded characters, stray '?' or '&', bad percent-escapes).

Common situations: Manually appending a ref as a query without encoding; copy-paste introducing a second '?'; tools that inject broken query params into SCP-style addresses.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/3ecf51d6dead8a02. Report an issue: GitHub.

Appendix: source

Thrown at internal/getmodules/moduleaddrs/detect_git.go:131

	}

	user := matched[1]
	host := matched[2]
	path := matched[3]
	qidx := strings.Index(path, "?")
	if qidx == -1 {
		qidx = len(path)
	}

	var u url.URL
	u.Scheme = "ssh"
	u.User = url.User(user)
	u.Host = host
	u.Path = path[0:qidx]
	if qidx < len(path) {
		q, err := url.ParseQuery(path[qidx+1:])
		if err != nil {
			return nil, fmt.Errorf("error parsing Git SSH URL: %s", err)
		}
		u.RawQuery = q.Encode()
	}

	return &u, nil
}

View on GitHub (pinned to d32a084675)