{"record":{"id":"c3904c65a18ff44e","repo":"hashicorp/terraform","slug":"s-errored","errorCode":null,"errorMessage":"%s errored.","messagePattern":"(.+?) errored\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote/backend_common.go","lineNumber":443,"sourceCode":"\t\t\t\t\t\tnext = false\n\t\t\t\t\t}\n\t\t\t\t\tline = append(line, l...)\n\t\t\t\t}\n\n\t\t\t\tif next || len(line) > 0 {\n\t\t\t\t\tb.CLI.Output(b.Colorize().Color(string(line)))\n\t\t\t\t}\n\t\t\t}\n\t\t}\n\n\t\tswitch pc.Status {\n\t\tcase tfe.PolicyPasses:\n\t\t\tif (r.HasChanges && op.Type == backendrun.OperationTypeApply || i < len(r.PolicyChecks)-1) && b.CLI != nil {\n\t\t\t\tb.CLI.Output(\"\\n------------------------------------------------------------------------\")\n\t\t\t}\n\t\t\tcontinue\n\t\tcase tfe.PolicyErrored:\n\t\t\treturn fmt.Errorf(\"%s errored.\", msgPrefix)\n\t\tcase tfe.PolicyHardFailed:\n\t\t\treturn fmt.Errorf(\"%s hard failed.\", msgPrefix)\n\t\tcase tfe.PolicySoftFailed:\n\t\t\trunURL := fmt.Sprintf(runHeaderErr, b.hostname, b.organization, op.Workspace, r.ID)\n\n\t\t\tif op.Type == backendrun.OperationTypePlan || op.UIOut == nil || op.UIIn == nil ||\n\t\t\t\t!pc.Actions.IsOverridable || !pc.Permissions.CanOverride {\n\t\t\t\treturn fmt.Errorf(\"%s soft failed.\\n%s\", msgPrefix, runURL)\n\t\t\t}\n\n\t\t\tif op.AutoApprove {\n\t\t\t\tif _, err = b.client.PolicyChecks.Override(stopCtx, pc.ID); err != nil {\n\t\t\t\t\treturn generalError(fmt.Sprintf(\"Failed to override policy check.\\n%s\", runURL), err)\n\t\t\t\t}\n\t\t\t} else {\n\t\t\t\topts := &terraform.InputOpts{\n\t\t\t\t\tId:          \"override\",\n\t\t\t\t\tQuery:       \"\\nDo you want to override the soft failed policy check?\",","sourceCodeStart":425,"sourceCodeEnd":461,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote/backend_common.go#L425-L461","documentation":"Returned by the policy-check watcher when a policy check's status is tfe.PolicyErrored. 'Errored' is distinct from failed: the policy engine could not complete evaluation (runtime/Sentinel error), so the result is indeterminate rather than a clear pass/fail.","triggerScenarios":"pc.Status == tfe.PolicyErrored during checkPolicy. Caused by malformed Sentinel policy source, a runtime exception during evaluation, the policy engine being unavailable, or a referenced data source failing to load.","commonSituations":"Recently pushed broken Sentinel policy; policy referencing an undefined function/module; TFE policy service degraded; policy using language features unsupported by the TFE Sentinel version.","solutions":["Open the run in the TFC/TFE UI and read the policy check logs for the exact Sentinel error.","Fix the policy syntax/runtime error and publish a new policy version.","Re-run the Terraform plan once the corrected policy is active.","If the engine itself is at fault, check TFE admin/health and the policy-set repository."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// On PolicyErrored, fetch logs and surface a clear remediation path.\nif pc.Status == tfe.PolicyErrored {\n    logs, _ := b.client.PolicyChecks.Logs(ctx, pc.ID)\n    return fmt.Errorf(\"policy %s errored; review logs:\\n%s\", pc.ID, logs)\n}","preventionTips":["Lint/test Sentinel policies in CI (sentinel apply/eval) before publishing to TFC.","Keep policy sets versioned and roll back on error instead of editing live.","Monitor policy-error rates and alert the policy owners."],"tags":["backend","remote-backend","policy","sentinel","errored","go"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}