{"record":{"id":"7320662f1181f875","repo":"hashicorp/terraform","slug":"unknown-or-unexpected-policy-state-s-732066","errorCode":null,"errorMessage":"Unknown or unexpected policy state: %s","messagePattern":"Unknown or unexpected policy state: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/cloud/backend_common.go","lineNumber":435,"sourceCode":"\t\t\t\tif err != nil && err != errRunOverridden {\n\t\t\t\t\treturn fmt.Errorf(\"Failed to override: %w\\n%s\\n\", err, runURL)\n\t\t\t\t}\n\n\t\t\t\tif err != errRunOverridden {\n\t\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\t\treturn b.generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t\t}\n\t\t\t\t} else {\n\t\t\t\t\trunURL := fmt.Sprintf(runHeader, b.Hostname, b.Organization, op.Workspace, r.ID)\n\t\t\t\t\tb.CLI.Output(fmt.Sprintf(\"The run needs to be manually overridden or discarded.\\n%s\\n\", runURL))\n\t\t\t\t}\n\t\t\t}\n\n\t\t\tif b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"------------------------------------------------------------------------\")\n\t\t\t}\n\t\tdefault:\n\t\t\treturn fmt.Errorf(\"Unknown or unexpected policy state: %s\", pc.Status)\n\t\t}\n\t}\n\n\treturn nil\n}\n\nfunc (b *Cloud) confirm(stopCtx context.Context, op *backendrun.Operation, opts *terraform.InputOpts, r *tfe.Run, keyword string) error {\n\tdoneCtx, cancel := context.WithCancel(stopCtx)\n\tresult := make(chan error, 2)\n\n\tgo func() {\n\t\t// Make sure we cancel doneCtx before we return\n\t\t// so the input command is also canceled.\n\t\tdefer cancel()\n\n\t\tfor {\n\t\t\tselect {\n\t\t\tcase <-doneCtx.Done():","sourceCodeStart":417,"sourceCodeEnd":453,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/cloud/backend_common.go#L417-L453","documentation":"Policy state switch hit its default: pc.Status is a value not present in the enumerated tfe.Policy* constants this binary knows. Same shape as the cost-estimate unknown-state error—almost always a client/server version skew where the server introduced a new policy status.","triggerScenarios":"pc.Status is a value outside {Passes, Errored, HardFailed, SoftFailed, ...}. Typically a newer TFE server returning a status the client's tfe SDK does not enumerate.","commonSituations":"Older Terraform/OpenTofu binary running against an upgraded TFE that added a policy status (e.g. a new 'pending override' or 'escalated' state).","solutions":["Upgrade the Terraform/OpenTofo binary so its tfe SDK recognizes the new status.","Downgrade TFE to match the client if upgrade is blocked.","Capture the unknown status value from %s and report it to confirm enum vs corruption."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"func knownPolicyStatus(s tfe.PolicyStatus) bool {\n    switch s {\n    case tfe.PolicyPasses, tfe.PolicyErrored, tfe.PolicyHardFailed, tfe.PolicySoftFailed,\n         tfe.PolicyPending, tfe.PolicyQueued, tfe.PolicyRunning, tfe.PolicyUnreachable:\n        return true\n    }\n    return false\n}","typeGuard":"func isKnownPolicyStatus(s tfe.PolicyStatus) bool {\n    // bounded enum range check\n    return s >= tfe.PolicyPending && s <= tfe.PolicyUnreachable\n}","tryCatchPattern":null,"preventionTips":["Keep the binary's tfe SDK version compatible with the TFE server.","Log raw policy status values for diagnostics.","Upgrade the binary when TFE adds new policy states."],"tags":["tfe","hcp","cloud-backend","policy","version-compat"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}