{"record":{"id":"0e1f2cf8385fb8c9","repo":"hashicorp/terraform","slug":"http-remote-state-already-locked-failed-to-unmars","errorCode":null,"errorMessage":"HTTP remote state already locked, failed to unmarshal body","messagePattern":"HTTP remote state already locked, failed to unmarshal body","errorType":"http","errorClass":"LockError","httpStatus":409,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":114,"sourceCode":"\t\tc.jsonLockInfo = jsonLockInfo\n\t\treturn info.ID, nil\n\tcase http.StatusUnauthorized:\n\t\treturn \"\", fmt.Errorf(\"HTTP remote state endpoint requires auth\")\n\tcase http.StatusForbidden:\n\t\treturn \"\", fmt.Errorf(\"HTTP remote state endpoint invalid auth\")\n\tcase http.StatusConflict, http.StatusLocked:\n\t\tdefer resp.Body.Close()\n\t\tbody, err := io.ReadAll(resp.Body)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to read body\"),\n\t\t\t}\n\t\t}\n\t\texisting := statemgr.LockInfo{}\n\t\terr = json.Unmarshal(body, &existing)\n\t\tif err != nil {\n\t\t\treturn \"\", &statemgr.LockError{\n\t\t\t\tErr: fmt.Errorf(\"HTTP remote state already locked, failed to unmarshal body\"),\n\t\t\t}\n\t\t}\n\t\treturn \"\", &statemgr.LockError{\n\t\t\tInfo: &existing,\n\t\t\tErr:  fmt.Errorf(\"HTTP remote state already locked: ID=%s\", existing.ID),\n\t\t}\n\tdefault:\n\t\treturn \"\", fmt.Errorf(\"Unexpected HTTP response code %d\", resp.StatusCode)\n\t}\n}\n\nfunc (c *httpClient) Unlock(id string) error {\n\tif c.UnlockURL == nil {\n\t\treturn nil\n\t}\n\n\tresp, err := c.httpRequest(c.UnlockMethod, c.UnlockURL, &c.jsonLockInfo, \"unlock\")\n\tif err != nil {","sourceCodeStart":96,"sourceCodeEnd":132,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L96-L132","documentation":"The lock endpoint returned 409 Conflict or 423 Locked and the body was read successfully, but json.Unmarshal into statemgr.LockInfo failed. The server returned a 409/423 body that is not the JSON lock-info document Terraform expects (fields: ID, Operation, Who, Created, Path, Info). Wrapped in a statemgr.LockError.","triggerScenarios":"Server returns an HTML error page, plain text, or a JSON envelope that does not match the LockInfo schema on 409/423; a reverse proxy serves a canned error page for conflict responses; the HTTP backend implementation does not follow Terraform's lock-info contract.","commonSituations":"Custom/3rd-party HTTP backend that signals 409 but returns its own error format; CDN/WAF replaces the body with a static page; server returns JSON like {\"error\":\"locked\"} without the ID field.","solutions":["Make the server return Terraform's LockInfo JSON shape (at minimum an 'ID' field) on 409/423 responses.","If you cannot change the server, disable HTTP locking by omitting lock_address/unlock_address.","Inspect the actual 409/423 body with curl -i -X <lock_method> <lock_address> to see what the server sends.","Switch to an HTTP backend implementation that conforms to the Terraform HTTP backend contract."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"# Inspect the actual body the server returns on a conflict, then decide whether to\n# fix the server or disable locking.\ncurl -sS -u \"$TF_HTTP_USERNAME:$TF_HTTP_PASSWORD\" -X \"${TF_HTTP_LOCK_METHOD:-LOCK}\" \\\n  -i \"${TF_HTTP_LOCK_ADDRESS:-$TF_HTTP_ADDRESS}\" | sed -n '1,40p'","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use an HTTP backend implementation that returns Terraform's LockInfo JSON on 409/423.","If you cannot change the server response, omit lock_address/unlock_address to disable locking.","Probe the conflict body shape before relying on locking in production."],"tags":["lock","json","http-backend","contract","lock-error"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}