{"record":{"id":"4ba763422d441f44","repo":"hashicorp/terraform","slug":"object-q-is-empty","errorCode":null,"errorMessage":"object %q is empty","messagePattern":"object %q is empty","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/client.go","lineNumber":123,"sourceCode":"\tcontentArray, err := io.ReadAll(getResponse.Content)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"unable to read 'content' from response: %w\", err)\n\t}\n\n\t// Compute MD5 hash\n\tmd5Hash := getResponse.ContentMd5\n\tif md5Hash == nil || len(*md5Hash) == 0 {\n\t\tmd5Hash = getResponse.OpcMultipartMd5\n\t}\n\t// Construct payload\n\tpayload := &remote.Payload{\n\t\tData: contentArray,\n\t\tMD5:  []byte(*md5Hash),\n\t}\n\n\t// Return an error instead of `nil, nil` if the object is empty\n\tif len(payload.Data) == 0 {\n\t\treturn nil, fmt.Errorf(\"object %q is empty\", c.path)\n\t}\n\n\treturn payload, nil\n}\n\nfunc (c *RemoteClient) Put(data []byte) tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\n\tlogger := logWithOperation(\"upload-state-file\").Named(c.path)\n\tctx := context.WithValue(context.Background(), \"logger\", logger)\n\tdataSize := int64(len(data))\n\tsum := md5.Sum(data)\n\tvar err error\n\tif dataSize > DefaultFilePartSize {\n\t\tlogger.Info(\"Using Multipart Feature\")\n\t\tvar multipartUploadData = MultipartUploadData{\n\t\t\tclient: c,\n\t\t\tData:   data,","sourceCodeStart":105,"sourceCodeEnd":141,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/client.go#L105-L141","documentation":"The state object exists (Head succeeded, Get succeeded, MD5 was computed) but its body is zero bytes. The backend refuses to return a nil/empty payload and instead surfaces this corruption error so that init does not silently treat the workspace as new.","triggerScenarios":"Someone manually created or truncated the object at the configured key; a previous interrupted write left a zero-byte object; bucket replication/lifecycle created an empty placeholder; an external process wrote an empty file to the same key.","commonSituations":"Manual bucket tampering; a failed migration from another backend that wrote the empty target object; cross-region replication in progress producing a placeholder; object versioning confusion where the 'current' version is empty.","solutions":["Restore the state from a backup or, if object versioning is enabled, promote a previous non-empty version.","If the state is genuinely meant to be empty/absent, delete the object so init recreates it as a proper empty state.","Enable Object Versioning on the bucket so future corruption is recoverable.","Audit who/what has OBJECT_OVERWRITE on the bucket and remove stray writers."],"exampleFix":"# before: someone truncated the state object\noci os object head --bucket-name tf-state --name prod.tfstate  # Content-Length: 0\n# after: restore from a prior version, then re-run init\noci os object-version copy-to ...   # or restore latest non-empty version\n# or, if state is intentionally empty, delete the object:\noci os object delete --bucket-name tf-state --name prod.tfstate","handlingStrategy":"validation","validationCode":"// Treat a zero-length object as corruption and refuse to proceed silently\nfunc assertNonEmpty(p *remote.Payload, path string) error {\n    if p != nil && len(p.Data) == 0 {\n        return fmt.Errorf(\"object %q is empty — restore from backup/versioning or delete and re-init\", path)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// On empty-object error, prompt recovery rather than silent retry\nif err != nil && strings.Contains(err.Error(), \"is empty\") {\n    // restore from object versioning or delete the object so init recreates it\n}","preventionTips":["Enable Object Versioning on the state bucket so corruption is recoverable.","Restrict OBJECT_OVERWRITE to the Terraform principal only — no stray writers.","Audit the bucket for zero-byte state objects periodically.","Back up state outside the bucket (e.g. scheduled object copy)."],"tags":["oci","object-storage","state-corruption","data-integrity"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}