Skip to content

fix: normalize StringToTimeLocationHookFunc error across platforms - #213

Open
flohoss wants to merge 1 commit into
go-viper:mainfrom
flohoss:fix-timelocation-error-leak
Open

flohoss wants to merge 1 commit into
go-viper:mainfrom
flohoss:fix-timelocation-error-leak

Conversation

@flohoss

@flohoss flohoss commented Oct 5, 2026

Copy link
Copy Markdown

Fixes #212

What changed

wrapTimeParseLocationError now always wraps errors from time.LoadLocation with a stable message (invalid time zone format: %w), instead of only when the error text contains "unknown time zone" / starts with "time: unknown format" and leaking everything else raw.

Why

Go stdlib's loadLocation returns the first non-ENOENT error from the platform zone sources (e.g. operation not permitted / EACCES on sandboxed darwin) before falling back to the embedded time/tzdata. Only when every source is ENOENT does it emit unknown time zone <name>. Depending on the host, the hook therefore leaked raw syscall errors into decoding errors, breaking portable error handling and user-facing messages.

Behavior change detail

The wrapped error keeps its invalid time zone format: prefix, but the trailing text is now whatever time.LoadLocation returned (e.g. unknown time zone Mars/Olympus_Mons on Linux, operation not permitted on sandboxed darwin). No existing test in this repo asserted the raw syscall text; regression tests added for the raw-error path, wrapping preservation (errors.Is), and the nil passthrough.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

StringToTimeLocationHookFunc leaks raw time.LoadLocation error text (platform-dependent)

1 participant