{"record":{"id":"ade159f5c778d3b4","repo":"hashicorp/terraform","slug":"state-not-locked","errorCode":null,"errorMessage":"state not locked","messagePattern":"state not locked","errorType":"console","errorClass":"LockError","httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/inmem/backend.go","lineNumber":205,"sourceCode":"\t\t// make a copy of the lock info to avoid any testing shenanigans\n\t\t*lockErr.Info = *lockInfo\n\t\treturn \"\", lockErr\n\t}\n\n\tinfo.Created = time.Now().UTC()\n\tl.m[name] = info\n\n\treturn info.ID, nil\n}\n\nfunc (l *lockMap) unlock(name, id string) error {\n\tl.Lock()\n\tdefer l.Unlock()\n\n\tlockInfo := l.m[name]\n\n\tif lockInfo == nil {\n\t\treturn errors.New(\"state not locked\")\n\t}\n\n\tlockErr := &statemgr.LockError{\n\t\tInfo: &statemgr.LockInfo{},\n\t}\n\n\tif id != lockInfo.ID {\n\t\tlockErr.Err = errors.New(\"invalid lock id\")\n\t\t*lockErr.Info = *lockInfo\n\t\treturn lockErr\n\t}\n\n\tdelete(l.m, name)\n\treturn nil\n}\n","sourceCodeStart":187,"sourceCodeEnd":221,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/inmem/backend.go#L187-L221","documentation":"A NestingSet block may not contain WriteOnly attributes. cty hoists value marks (including WriteOnly marks) up to the outer set value, so per-element WriteOnly cannot be tracked — only the whole set could be WriteOnly, which is not the intent. The validator calls blockS.Block.ContainsWriteOnly() and rejects.","triggerScenarios":"NestingSet block with any attribute having WriteOnly: true. Guard at internal_validate.go:100 is `blockS.Block.ContainsWriteOnly()`.","commonSituations":"Adding a secret WriteOnly attribute inside a set of credential blocks; reusing a NestingList-with-WriteOnly schema under a NestingSet.","solutions":["Move the WriteOnly attribute to the outer (non-set) block so the mark applies there.","Change the block from NestingSet to NestingList if per-element WriteOnly is required.","Drop WriteOnly from the set's child attributes."],"exampleFix":"// before\n\"secrets\": {\n  Nesting: configschema.NestingSet,\n  Block: configschema.Block{Attributes: map[string]*configschema.Attribute{\n    \"token\": { Type: cty.String, Optional: true, WriteOnly: true },\n  }},\n},\n// after\n\"secrets\": {\n  Nesting: configschema.NestingList,\n  Block: configschema.Block{Attributes: map[string]*configschema.Attribute{\n    \"token\": { Type: cty.String, Optional: true, WriteOnly: true },\n  }},\n},","handlingStrategy":"validation","validationCode":"// Reject NestingSet blocks that contain any WriteOnly attribute.\nfunc setHasWriteOnly(nb *configschema.NestedBlock) bool {\n    if nb.Nesting != configschema.NestingSet { return false }\n    return nb.Block.ContainsWriteOnly()\n}","typeGuard":"func setFreeOfWriteOnly(nb *configschema.NestedBlock) bool {\n    return nb.Nesting != configschema.NestingSet || !nb.Block.ContainsWriteOnly()\n}","tryCatchPattern":null,"preventionTips":["Keep WriteOnly attributes out of NestingSet blocks.","Move secrets to the outer non-set block, or switch to NestingList.","Audit schemas when introducing WriteOnly fields."],"tags":["schema-validation","configschema","nestingset","write-only","provider-schema"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}