{"record":{"id":"0b74b3710531bcb3","repo":"hashicorp/terraform","slug":"unable-to-determine-credentials-file-path-s","errorCode":null,"errorMessage":"unable to determine credentials file path: %s","messagePattern":"unable to determine credentials file path: (.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/command/cliconfig/credentials.go","lineNumber":328,"sourceCode":"\t\t// Delegate entirely to the helper, then.\n\t\tif new == nil {\n\t\t\treturn s.helper.ForgetForHost(host)\n\t\t}\n\t\treturn s.helper.StoreForHost(host, new)\n\tdefault:\n\t\t// Should never happen because the above cases are exhaustive\n\t\treturn fmt.Errorf(\"invalid credentials location %#v\", loc)\n\t}\n}\n\nfunc (s *CredentialsSource) updateLocalHostCredentials(host svchost.Hostname, new svcauth.HostCredentialsWritable) error {\n\t// This function updates the local credentials file in particular,\n\t// regardless of whether a credentials helper is active. It should be\n\t// called only indirectly via updateHostCredentials.\n\n\tfilename, err := s.CredentialsFilePath()\n\tif err != nil {\n\t\treturn fmt.Errorf(\"unable to determine credentials file path: %s\", err)\n\t}\n\n\toldSrc, err := ioutil.ReadFile(filename)\n\tif err != nil && !os.IsNotExist(err) {\n\t\treturn fmt.Errorf(\"cannot read %s: %s\", filename, err)\n\t}\n\n\tvar raw map[string]interface{}\n\n\tif len(oldSrc) > 0 {\n\t\t// When decoding we use a custom decoder so we can decode any numbers as\n\t\t// json.Number and thus avoid losing any accuracy in our round-trip.\n\t\tdec := json.NewDecoder(bytes.NewReader(oldSrc))\n\t\tdec.UseNumber()\n\t\terr = dec.Decode(&raw)\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"cannot read %s: %s\", filename, err)\n\t\t}","sourceCodeStart":310,"sourceCodeEnd":346,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/cliconfig/credentials.go#L310-L346","documentation":"Thrown when s.CredentialsFilePath() returns an error during updateLocalHostCredentials, which writes credential updates to the local credentials file. Note: CredentialsFilePath() as implemented always returns (s.credentialsFilePath, nil) — it never produces an error — making this branch effectively unreachable defensive dead code. If it were ever triggered, it would mean the CredentialsSource was constructed without a valid credentials file path.","triggerScenarios":"s.CredentialsFilePath() returns a non-nil error when called from updateLocalHostCredentials. In the current implementation this cannot happen because CredentialsFilePath() unconditionally returns nil. It would require a future code change that makes path resolution fallible.","commonSituations":"Effectively unreachable in current Terraform. The defensive check exists to guard against a hypothetical future where CredentialsFilePath() becomes fallible. If encountered, it indicates an internal state corruption or a code regression.","solutions":["Report a bug to the Terraform project — this error path is not expected to be reachable","Verify the CredentialsSource was initialized through normal config loading, not constructed manually","Ensure HOME is set so the credentials file path can be resolved during initialization"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Verify the credentials file path can be resolved before operations\n// Note: CredentialsFilePath() currently always returns nil error, but guard anyway\nfunc checkCredentialsPath(source *CredentialsSource) error {\n    path, err := source.CredentialsFilePath()\n    if err != nil {\n        return fmt.Errorf(\"credentials file path error: %w\", err)\n    }\n    if path == \"\" {\n        return errors.New(\"credentials file path is empty\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// Guard credential updates; this error path is currently unreachable\n// but defensive handling protects against future code changes\nfunc safeUpdateCredentials(source *CredentialsSource, host svchost.Hostname, creds svcauth.HostCredentialsWritable) error {\n    if _, err := source.CredentialsFilePath(); err != nil {\n        return fmt.Errorf(\"cannot determine credentials path, skipping update: %w\", err)\n    }\n    return nil\n}","preventionTips":["Ensure HOME is set so credentials file path resolves during initialization","Use TF_CLI_CONFIG_FILE for deterministic config paths","Validate the environment before running terraform login","Treat this error as an internal bug if encountered — it should be unreachable"],"tags":["cli-config","credentials","unreachable","dead-code","defensive"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}