{"record":{"id":"72b9db4c25006026","repo":"hashicorp/terraform","slug":"unknown-or-unexpected-policy-state-s","errorCode":null,"errorMessage":"Unknown or unexpected policy state: %s","messagePattern":"Unknown or unexpected policy state: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_common.go","lineNumber":483,"sourceCode":"\t\t\t\tif err != nil && err != errRunOverridden {\n\t\t\t\t\treturn fmt.Errorf(\"Failed to override: %w\\n%s\\n\", err, runURL)\n\t\t\t\t}\n\n\t\t\t\tif err != errRunOverridden {\n\t\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\t\treturn generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t\t}\n\t\t\t\t} else {\n\t\t\t\t\trunURL := fmt.Sprintf(runHeader, b.hostname, b.organization, op.Workspace, r.ID)\n\t\t\t\t\tb.CLI.Output(fmt.Sprintf(\"The run needs to be manually overridden or discarded.\\n%s\\n\", runURL))\n\t\t\t\t}\n\t\t\t}\n\n\t\t\tif b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"------------------------------------------------------------------------\")\n\t\t\t}\n\t\tdefault:\n\t\t\treturn fmt.Errorf(\"Unknown or unexpected policy state: %s\", pc.Status)\n\t\t}\n\t}\n\n\treturn nil\n}\n\nfunc (b *Remote) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {\n\tdoneCtx, cancel := context.WithCancel(stopCtx)\n\tresult := make(chan error, 2)\n\n\tgo func() {\n\t\tdefer logging.PanicHandler()\n\n\t\t// Make sure we cancel doneCtx before we return\n\t\t// so the input command is also canceled.\n\t\tdefer cancel()\n\n\t\tfor {","sourceCodeStart":465,"sourceCodeEnd":501,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_common.go#L465-L501","documentation":"Default branch of the policy-check status switch in checkPolicy. pc.Status did not match any known tfe.Policy* constant (Passes/Errored/HardFailed/SoftFailed/...). Like the cost-estimate equivalent, this signals the server and client disagree on possible policy statuses - typically a version-skew issue.","triggerScenarios":"pc.Status is a value the running Terraform client's tfe package does not recognize. Happens when a newer TFE/TFC emits a new policy status (e.g. a new post-condition or override state) unknown to an older CLI.","commonSituations":"TFE/TFC upgraded ahead of the Terraform CLI; very old CLI against new TFC; preview policy features; custom build with a stale tfe dependency.","solutions":["Upgrade the Terraform CLI to match or exceed the TFE/TFC version.","Pin TFE to a version compatible with the installed CLI until you can upgrade.","Capture the unknown status string and report it upstream if it recurs on a current CLI."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Ensure CLI >= TFE version before running policy-backed plans.\nfunc versionsOK(cli, tfe string) bool { return !semverLessThan(cli, tfe) }","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Upgrade the Terraform CLI in lockstep with TFE/TFC upgrades.","Pin CLI/TFE versions together in CI.","Capture unknown status strings in logs to fast-track upstream reports."],"tags":["backend","remote-backend","policy","version-skew","unknown-state","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}