{"record":{"id":"a45a6d2ccfecd330","repo":"hashicorp/terraform","slug":"using-the-c-windows-temp-folder-is-not-supported","errorCode":null,"errorMessage":"Using the C:\\Windows\\Temp folder is not supported. Please use a different 'script_path'.","messagePattern":"Using the C:\\\\Windows\\\\Temp folder is not supported\\. Please use a different 'script_path'\\.","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/communicator/winrm/provisioner.go","lineNumber":114,"sourceCode":"// a ConnectionInfo struct\nfunc parseConnectionInfo(v cty.Value) (*connectionInfo, error) {\n\tv, err := shared.ConnectionBlockSupersetSchema.CoerceValue(v)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\tconnInfo, err := decodeConnInfo(v)\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\t// Check on script paths which point to the default Windows TEMP folder because files\n\t// which are put in there very early in the boot process could get cleaned/deleted\n\t// before you had the change to execute them.\n\t//\n\t// TODO (SvH) Needs some more debugging to fully understand the exact sequence of events\n\t// causing this...\n\tif strings.HasPrefix(filepath.ToSlash(connInfo.ScriptPath), \"C:/Windows/Temp\") {\n\t\treturn nil, fmt.Errorf(\n\t\t\t`Using the C:\\Windows\\Temp folder is not supported. Please use a different 'script_path'.`)\n\t}\n\n\tif connInfo.User == \"\" {\n\t\tconnInfo.User = DefaultUser\n\t}\n\n\t// Format the host if needed.\n\t// Needed for IPv6 support.\n\tconnInfo.Host = shared.IpFormat(connInfo.Host)\n\n\tif connInfo.Port == 0 {\n\t\tif connInfo.HTTPS {\n\t\t\tconnInfo.Port = DefaultHTTPSPort\n\t\t} else {\n\t\t\tconnInfo.Port = DefaultPort\n\t\t}\n\t}","sourceCodeStart":96,"sourceCodeEnd":132,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/communicator/winrm/provisioner.go#L96-L132","documentation":"The WinRM communicator validates the script_path connection setting before connecting. Files placed in C:\\Windows\\Temp early during Windows boot can be deleted by the OS cleanup process before the provisioner gets to execute them, causing silent provisioning failures. This hard guard rejects any script_path that begins with C:/Windows/Temp (matched case-insensitively via filepath.ToSlash) to prevent that race condition.","triggerScenarios":"Setting script_path in a winrm connection block to a path under C:\\Windows\\Temp (or C:/Windows/Temp). The check normalizes backslashes to forward slashes via filepath.ToSlash and checks the prefix string, so any casing or slash variant of that path triggers it.","commonSituations":"User copies a connection block from a Linux example and leaves or sets the default Windows temp path. User explicitly sets script_path = \"C:\\\\Windows\\\\Temp\\\\terraform_%RAND%.cmd\" thinking it's a safe temp location. Default script_path was overridden to point to the system temp folder.","solutions":["Set script_path to a non-system temp location, e.g., script_path = \"C:\\\\Temp\\\\terraform_%RAND%.cmd\".","Use the user's temp directory instead: script_path = \"%TEMP%\\\\tf_%RAND%.cmd\" (typically C:\\Users\\<user>\\AppData\\Local\\Temp).","Create the target directory beforehand or ensure the WinRM user has write access to the chosen path.","Remove the script_path override entirely to use Terraform's safe default."],"exampleFix":"# before\nconnection {\n  type        = \"winrm\"\n  script_path = \"C:\\\\Windows\\\\Temp\\\\terraform_%RAND%.cmd\"\n}\n\n# after\nconnection {\n  type        = \"winrm\"\n  script_path = \"C:\\\\Terraform\\\\tf_%RAND%.cmd\"\n}","handlingStrategy":"validation","validationCode":"// Validate the script_path before passing it to the winrm connection\nimport (\n    \"path/filepath\"\n    \"strings\"\n)\n\nfunc validateWinRMScriptPath(scriptPath string) error {\n    normalized := filepath.ToSlash(scriptPath)\n    if strings.HasPrefix(strings.ToLower(normalized), \"c:/windows/temp\") {\n        return errors.New(\"script_path must not use C:\\\\Windows\\\\Temp; use a custom directory\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Set script_path to a dedicated directory like C:\\\\Terraform or the user's %TEMP%.","Avoid copying connection blocks from Linux-oriented examples for Windows hosts.","Document the Windows-safe script_path convention in your team's Terraform style guide."],"tags":["winrm","windows","script-path","provisioner","configuration"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}