{"record":{"id":"b6e2f769cf8d6e89","repo":"hashicorp/terraform","slug":"invalid-cidr-expression-s","errorCode":null,"errorMessage":"invalid CIDR expression: %s","messagePattern":"invalid CIDR expression: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/lang/funcs/cidr.go","lineNumber":40,"sourceCode":"\t\t{\n\t\t\tName: \"prefix\",\n\t\t\tType: cty.String,\n\t\t},\n\t\t{\n\t\t\tName: \"hostnum\",\n\t\t\tType: cty.Number,\n\t\t},\n\t},\n\tType:         function.StaticReturnType(cty.String),\n\tRefineResult: refineNotNull,\n\tImpl: func(args []cty.Value, retType cty.Type) (ret cty.Value, err error) {\n\t\tvar hostNum *big.Int\n\t\tif err := gocty.FromCtyValue(args[1], &hostNum); err != nil {\n\t\t\treturn cty.UnknownVal(cty.String), err\n\t\t}\n\t\t_, network, err := ipaddr.ParseCIDR(args[0].AsString())\n\t\tif err != nil {\n\t\t\treturn cty.UnknownVal(cty.String), fmt.Errorf(\"invalid CIDR expression: %s\", err)\n\t\t}\n\n\t\tip, err := cidr.HostBig(network, hostNum)\n\t\tif err != nil {\n\t\t\treturn cty.UnknownVal(cty.String), err\n\t\t}\n\n\t\treturn cty.StringVal(ip.String()), nil\n\t},\n})\n\n// CidrNetmaskFunc contructs a function that converts an IPv4 address prefix given\n// in CIDR notation into a subnet mask address.\nvar CidrNetmaskFunc = function.New(&function.Spec{\n\tParams: []function.Parameter{\n\t\t{\n\t\t\tName: \"prefix\",\n\t\t\tType: cty.String,","sourceCodeStart":22,"sourceCodeEnd":58,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/lang/funcs/cidr.go#L22-L58","documentation":"cidrhost() function error: the first argument (prefix) could not be parsed as a CIDR by ipaddr.ParseCIDR. The function builds a host IP inside a given network and needs a valid IPv4/IPv6 CIDR string as its first parameter; anything that fails CIDR parsing yields this wrapped parse error.","triggerScenarios":"Calling cidrhost(prefix, hostNum) where prefix is not a valid CIDR, e.g. \"10.0.0.5\" (host with no /prefix), \"10.0.0.0/33\" (out-of-range mask), \"not-an-ip\", or an empty string.","commonSituations":"Variable computed from another resource without a netmask, user supplies a bare IP instead of a network, trailing whitespace/newline in a variable, or a misformatted locals value.","solutions":["Provide a full CIDR string including the prefix length, e.g. \"10.0.0.0/24\".","Validate the variable with a regex or cidrblock validation rule before passing to cidrhost.","If only a host IP is known, derive the network with cidrnetmask/cidrsubnet or compute the /prefix from the resource."],"exampleFix":"// before\nlocals { ip = cidrhost(\"10.0.0.5\", 4) }\n\n// after\nlocals { ip = cidrhost(\"10.0.0.0/24\", 4) }","handlingStrategy":"validation","validationCode":"// HCL variable validation block\nvariable \"cidr\" {\n  type    = string\n  validation {\n    condition     = can(regex(\"^([0-9]{1,3}\\\\.){3}[0-9]{1,3}/[0-9]{1,2}$\", var.cidr))\n    error_message = \"cidr must be a valid CIDR like 10.0.0.0/24.\"\n  }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always include the /prefix length in CIDR variables.","Use a cidrblock or regex validation block on any variable passed to cidrhost.","Source CIDRs from resources that emit a network address, not a host IP."],"tags":["terraform","hcl-functions","cidr","networking","validation"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}