{"record":{"id":"b2f382c1720897a2","repo":"hashicorp/terraform","slug":"invalid-tfvars-syntax-s","errorCode":null,"errorMessage":"invalid tfvars syntax: %s","messagePattern":"invalid tfvars syntax: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/builtin/providers/terraform/functions.go","lineNumber":121,"sourceCode":"\t\t// type, since it will be an object type decided based on which\n\t\t// arguments and values we find in the string.\n\t\treturn cty.DynamicVal, nil\n\t}\n\n\t// If we get here then we know that:\n\t// - there's exactly one element in args\n\t// - it's a string\n\t// - it is known and non-null\n\t// So therefore the following is guaranteed to succeed.\n\tsrc := []byte(args[0].AsString())\n\n\t// As usual when we wrap HCL stuff up in functions, we end up needing to\n\t// stuff HCL diagnostics into plain string error messages. This produces\n\t// a non-ideal result but is still better than hiding the HCL-provided\n\t// diagnosis altogether.\n\tf, hclDiags := hclsyntax.ParseConfig(src, \"<decode_tfvars argument>\", hcl.InitialPos)\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars syntax: %s\", hclDiags.Error())\n\t}\n\tattrs, hclDiags := f.Body.JustAttributes()\n\tif hclDiags.HasErrors() {\n\t\treturn cty.NilVal, fmt.Errorf(\"invalid tfvars content: %s\", hclDiags.Error())\n\t}\n\tretAttrs := make(map[string]cty.Value, len(attrs))\n\tfor name, attr := range attrs {\n\t\t// Evaluating the expression with no EvalContext achieves the same\n\t\t// interpretation as Terraform CLI makes of .tfvars files, rejecting\n\t\t// any function calls or references to symbols.\n\t\tv, hclDiags := attr.Expr.Value(nil)\n\t\tif hclDiags.HasErrors() {\n\t\t\treturn cty.NilVal, fmt.Errorf(\"invalid expression for variable %q: %s\", name, hclDiags.Error())\n\t\t}\n\t\tretAttrs[name] = v\n\t}\n\n\treturn cty.ObjectVal(retAttrs), nil","sourceCodeStart":103,"sourceCodeEnd":139,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/builtin/providers/terraform/functions.go#L103-L139","documentation":"decode_tfvars feeds the input string to hclsyntax.ParseConfig. If the HCL parser reports errors (unterminated strings, invalid tokens, malformed expressions), they are wrapped into this message. This is a genuine user-facing error: the supplied string is not valid HCL/terraform-tfvars syntax.","triggerScenarios":"decode_tfvars(\"name = 'broken\") with an unterminated string; decode_tfvars(\"a = =\") with an invalid expression token; any malformed tfvars content passed as the single argument.","commonSituations":"Reading a .tfvars file with file() that contains a typo or unbalanced quotes; programmatically building a tfvars string without escaping embedded quotes; copy-pasting partial config into decode_tfvars.","solutions":["Read the wrapped HCL diagnostic to locate the exact offset/token causing the parse failure and fix it","Validate the string parses as HCL before calling (run it through hclsyntax.ParseConfig, or terraform fmt -check)","If the input is a file, run terraform fmt on it first to surface and auto-fix common syntax issues"],"exampleFix":"// before\ndecode_tfvars(\"name = 'broken\")\n// after\ndecode_tfvars(\"name = \\\"fixed\\\"\")","handlingStrategy":"validation","validationCode":"// Pre-parse the tfvars string with HCL before handing it to decode_tfvars.\n// In Go:\nf, diags := hclsyntax.ParseConfig([]byte(src), \"check.tfvars\", hcl.InitialPos)\nif diags.HasErrors() {\n    // surface diags to the user instead of calling decode_tfvars\n    return diags\n}\n// In HCL, validate the source file first:\n// validate that file(var.path) is non-empty and well-formed via a fmt check in CI","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Run terraform fmt -check on any .tfvars file whose contents you feed to decode_tfvars","When constructing tfvars strings programmatically, escape embedded quotes and avoid unterminated tokens","Add a CI lint step that parses tfvars inputs through hclsyntax before deployment"],"tags":["terraform","hcl","decode-tfvars","syntax","user-input"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}