{"record":{"id":"91a0f7ddf6824818","repo":"hashicorp/terraform","slug":"provider-s-version-constraints-q-don-t-match-th","errorCode":null,"errorMessage":"provider %s: version constraints %q don't match the locked version selection %s","messagePattern":"provider (.+?): version constraints %q don't match the locked version selection (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/configs/config.go","lineNumber":314,"sourceCode":"\n\t\tselectedVersion := lock.Version()\n\t\tallowedVersions := providerreqs.MeetingConstraints(constraints)\n\t\tlog.Printf(\"[TRACE] Config.VerifyDependencySelections: provider %s has %s to satisfy %q\", providerAddr, selectedVersion.String(), providerreqs.VersionConstraintsString(constraints))\n\t\tif !allowedVersions.Has(selectedVersion) {\n\t\t\t// The most likely cause of this is that the author of a module\n\t\t\t// has changed its constraints, but this could also happen in\n\t\t\t// some other unusual situations, such as the user directly\n\t\t\t// editing the lock file to record something invalid. We'll\n\t\t\t// distinguish those cases here in order to avoid the more\n\t\t\t// specific error message potentially being a red herring in\n\t\t\t// the edge-cases.\n\t\t\tcurrentConstraints := providerreqs.VersionConstraintsString(constraints)\n\t\t\tlockedConstraints := providerreqs.VersionConstraintsString(lock.VersionConstraints())\n\t\t\tswitch {\n\t\t\tcase currentConstraints != lockedConstraints:\n\t\t\t\terrs = append(errs, fmt.Errorf(\"provider %s: locked version selection %s doesn't match the updated version constraints %q\", providerAddr, selectedVersion.String(), currentConstraints))\n\t\t\tdefault:\n\t\t\t\terrs = append(errs, fmt.Errorf(\"provider %s: version constraints %q don't match the locked version selection %s\", providerAddr, currentConstraints, selectedVersion.String()))\n\t\t\t}\n\t\t}\n\t}\n\n\t// Return multiple errors in an arbitrary-but-deterministic order.\n\tsort.Slice(errs, func(i, j int) bool {\n\t\treturn errs[i].Error() < errs[j].Error()\n\t})\n\n\treturn errs\n}\n\n// ProviderRequirements searches the full tree of modules under the receiver\n// for both explicit and implicit dependencies on providers.\n//\n// The result is a full manifest of all of the providers that must be available\n// in order to work with the receiving configuration.\n//","sourceCodeStart":296,"sourceCodeEnd":332,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/configs/config.go#L296-L332","documentation":"The locked version does not satisfy the current version constraints, but the constraint strings in the config and lock file are identical (the default/else branch of the switch). This means the lock file records a version that violates the very constraints it claims to satisfy — typically caused by manual editing of the lock file, or by a lock file written by a buggy or older Terraform version.","triggerScenarios":"The lock file's provider version entry doesn't satisfy the constraints recorded alongside it in the same lock file, and the constraints haven't changed from config. Triggered by hand-editing .terraform.lock.hcl to pin an incompatible version, or by lock file corruption.","commonSituations":"Developer manually edits .terraform.lock.hcl to force a specific version that violates the constraints. Lock file generated by an older Terraform version with a resolver bug. Partial write or merge conflict left the lock file in an inconsistent state. Lock file was copied from another project with different constraints.","solutions":["Run terraform init --upgrade to regenerate a consistent lock file from scratch.","If the lock file was manually edited, revert it from version control and re-run terraform init.","Delete .terraform.lock.hcl and run terraform init to produce a fresh lock file.","Verify no merge conflict artifacts remain in the lock file."],"exampleFix":"# before — manually edited lock file with incompatible version\ngit checkout -- .terraform.lock.hcl  # if corrupted\nterraform plan  # → error\n\n# after — regenerate from clean state\nrm .terraform.lock.hcl\nterraform init\nterraform plan","handlingStrategy":"validation","validationCode":"// Detect lock file inconsistency before plan\n// Shell pre-check:\n//   terraform init -lockfile=readonly  # catches internal inconsistency\n// If corrupt:\n//   rm .terraform.lock.hcl && terraform init","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never hand-edit .terraform.lock.hcl — always use terraform init.","Add .terraform.lock.hcl to code review checks — reject manual modifications.","Run terraform init -lockfile=readonly in CI to detect corruption.","If merging branches, resolve lock file conflicts by deleting and re-initializing rather than hand-merging."],"tags":["config","providers","dependency-lock","lock-file","corruption"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}