{"record":{"id":"4eb641f1bcca5171","repo":"hashicorp/terraform","slug":"failed-to-generate-initial-lineage-v","errorCode":null,"errorMessage":"failed to generate initial lineage: %v","messagePattern":"failed to generate initial lineage: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"internal/cloud/state.go","lineNumber":194,"sourceCode":"\t\t\t// If the state, lineage or serial haven't changed at all then we have nothing to do.\n\t\t\treturn nil\n\t\t}\n\t\ts.serial++\n\t} else {\n\t\t// We might be writing a new state altogether, but before we do that\n\t\t// we'll check to make sure there isn't already a snapshot present\n\t\t// that we ought to be updating.\n\t\terr := s.refreshState()\n\t\tif err != nil {\n\t\t\treturn fmt.Errorf(\"failed checking for existing remote state: %s\", err)\n\t\t}\n\t\tlog.Printf(\"[DEBUG] cloud/state: after refresh, state read serial is: %d; serial is: %d\", s.readSerial, s.serial)\n\t\tlog.Printf(\"[DEBUG] cloud/state: after refresh, state read lineage is: %s; lineage is: %s\", s.readLineage, s.lineage)\n\n\t\tif s.lineage == \"\" { // indicates that no state snapshot is present yet\n\t\t\tlineage, err := uuid.GenerateUUID()\n\t\t\tif err != nil {\n\t\t\t\treturn fmt.Errorf(\"failed to generate initial lineage: %v\", err)\n\t\t\t}\n\t\t\ts.lineage = lineage\n\t\t\ts.serial++\n\t\t}\n\t}\n\n\tf := statefile.New(s.state, s.lineage, s.serial)\n\n\tvar buf bytes.Buffer\n\terr := statefile.Write(f, &buf)\n\tif err != nil {\n\t\treturn err\n\t}\n\n\tvar jsonState []byte\n\tif schemas != nil {\n\t\tjsonState, err = jsonstate.Marshal(f, schemas)\n\t\tif err != nil {","sourceCodeStart":176,"sourceCodeEnd":212,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/state.go#L176-L212","documentation":"Thrown by the cloud state writer when uuid.GenerateUUID() fails while seeding a new state's lineage. With no existing state snapshot (s.lineage == ''), the backend generates a fresh UUID as the lineage identifier; GenerateUUID reads from crypto/rand and only fails if the system's CSPRNG is unavailable. This is an extremely rare, environment-level failure.","triggerScenarios":"uuid.GenerateUUID fails when crypto/rand cannot read randomness — typically a broken /dev/urandom, an OS-level entropy source failure, or a sandboxed/containerized environment that blocks the random device. This is essentially a host/OS defect, not a Terraform logic bug.","commonSituations":"A locked-down container or seccomp profile denying /dev/urandom access; an OS in early boot before the CSPRNG is seeded; a virtualized environment with a misconfigured entropy device; extremely rare hardware/kernel fault.","solutions":["Verify /dev/urandom is readable inside the execution environment (`head -c 16 /dev/urandom` succeeds).","Relax the container/seccomp/AppArmor profile to allow the random device.","Use a host with a healthy entropy source (e.g. virtio-rng on VMs).","Retry after fixing the OS/entropy issue — once randomness is available, generation succeeds deterministically."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Verify the CSPRNG is available before state operations.\nfunc randAvailable() error {\n    f, err := os.Open(\"/dev/urandom\")\n    if err != nil { return err }\n    return f.Close()\n}","typeGuard":null,"tryCatchPattern":"lineage, err := uuid.GenerateUUID()\nif err != nil {\n    return fmt.Errorf(\"failed to generate initial lineage: %v\", err)\n}","preventionTips":["Allow /dev/urandom in container/seccomp/AppArmor profiles.","Use a host with a healthy entropy source (virtio-rng).","Add a startup self-test that reads randomness before running Terraform."],"tags":["terraform","state","uuid","crypto-rand","environment","container","os"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}