{"record":{"id":"15303400eff2fbca","repo":"hashicorp/terraform","slug":"attempted-to-encode-a-malformed-backend-state-file","errorCode":null,"errorMessage":"attempted to encode a malformed backend state file; it contains state for both a 'backend' and a 'state_store' block. This is a bug in Terraform and should be reported.","messagePattern":"attempted to encode a malformed backend state file; it contains state for both a 'backend' and a 'state_store' block\\. This is a bug in Terraform and should be reported\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"internal/command/workdir/backend_state.go","lineNumber":128,"sourceCode":"\tif stateFile.Backend != nil && stateFile.StateStore != nil {\n\t\treturn nil, fmt.Errorf(\"encountered a malformed backend state file that contains state for both a 'backend' and a 'state_store' block\")\n\t}\n\tif stateFile.StateStore != nil && stateFile.StateStore.ProviderSupplyMode == \"\" {\n\t\t// Check for this, as lacking this data can cause problems later when an empty provider version\n\t\t// is encountered. This error will make debugging much easier.\n\t\treturn nil, fmt.Errorf(\"encountered a malformed backend state file with a 'state_store' block that is missing the required 'provider_supply_mode' property\")\n\t}\n\n\treturn &stateFile, nil\n}\n\nfunc EncodeBackendStateFile(f *BackendStateFile) ([]byte, error) {\n\tf.Version = 3 // we only support version 3\n\tf.TFVersion = version.SemVer.String()\n\n\tswitch {\n\tcase f.Backend != nil && f.StateStore != nil:\n\t\treturn nil, fmt.Errorf(\"attempted to encode a malformed backend state file; it contains state for both a 'backend' and a 'state_store' block. This is a bug in Terraform and should be reported.\")\n\tcase f.Backend == nil && f.StateStore == nil:\n\t\t// This is valid - if the user has a backend state file and an implied local backend in use\n\t\t// the backend state file exists but has no Backend data.\n\tcase f.Backend != nil:\n\t\t// Not implementing anything here - risk of breaking changes\n\tcase f.StateStore != nil:\n\t\terr := f.StateStore.Validate()\n\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\tdefault:\n\t\tpanic(\"error when determining whether backend state file was valid. This is a bug in Terraform and should be reported.\")\n\t}\n\n\treturn json.MarshalIndent(f, \"\", \"  \")\n}\n\nfunc (f *BackendStateFile) DeepCopy() *BackendStateFile {","sourceCodeStart":110,"sourceCodeEnd":146,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/command/workdir/backend_state.go#L110-L146","documentation":"EncodeBackendStateFile hit the case where the in-memory BackendStateFile has BOTH a non-nil Backend and a non-nil StateStore — an impossible state for any correctly-running Terraform. The message explicitly says 'This is a bug in Terraform and should be reported,' i.e. it is an internal invariant guard, not a user-config error.","triggerScenarios":"Code path that mutates BackendStateFile in memory sets both Backend and StateStore before calling EncodeBackendStateFile. Cannot be produced by config alone — requires a bug in init/plan/apply wiring.","commonSituations":"Almost never seen in released builds; surfaces during development of new backend/state-store code, with experimental/fork builds, or after a partial refactor.","solutions":["File a bug report against Terraform/OpenTofu with the steps to reproduce and the version.","Work around by clearing one of the two (delete .terraform/terraform.tfstate and re-init) to get back to a known-good state.","If running a fork/experimental build, audit the code that populates BackendStateFile to ensure it never sets both fields."],"exampleFix":"// code-level fix: enforce mutual exclusion at the source\nif f.Backend != nil && f.StateStore != nil {\n    f.Backend = nil // or f.StateStore = nil, depending on intended mode\n}\nreturn json.Marshal(f)","handlingStrategy":"validation","validationCode":"// encode-time invariant: enforce mutual exclusion before writing\nif f.Backend != nil && f.StateStore != nil {\n    return nil, errors.New(\"refusing to encode: both backend and state_store set (internal bug)\")\n}","typeGuard":"func backendStateIsConsistent(f *BackendStateFile) bool {\n    return !(f.Backend != nil && f.StateStore != nil)\n}","tryCatchPattern":null,"preventionTips":["In fork/experimental code, never set both Backend and StateStore on the same struct.","Add a unit test asserting mutual exclusion for every code path that writes BackendStateFile."],"tags":["backend","state-store","invariant","bug-in-terraform","encode"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}