{"record":{"id":"c3ad5fbbb2030af6","repo":"hashicorp/terraform","slug":"estimating-object-s-is-exist-got-an-error-v","errorCode":null,"errorMessage":"estimating object %s is exist got an error: %#v","messagePattern":"estimating object (.+?) is exist got an error: %#v","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/client.go","lineNumber":420,"sourceCode":"\t\tlockErr.Err = err\n\t\treturn lockErr\n\t}\n\n\treturn nil\n}\n\nfunc (c *RemoteClient) lockPath() string {\n\treturn fmt.Sprintf(\"%s/%s\", c.bucketName, c.stateFile)\n}\n\nfunc (c *RemoteClient) getObj() (*remote.Payload, error) {\n\tbucket, err := c.ossClient.Bucket(c.bucketName)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"error getting bucket %s: %#v\", c.bucketName, err)\n\t}\n\n\tif exist, err := bucket.IsObjectExist(c.stateFile); err != nil {\n\t\treturn nil, fmt.Errorf(\"estimating object %s is exist got an error: %#v\", c.stateFile, err)\n\t} else if !exist {\n\t\treturn nil, nil\n\t}\n\n\tvar options []oss.Option\n\toutput, err := bucket.GetObject(c.stateFile, options...)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"error getting object: %#v\", err)\n\t}\n\n\tbuf := bytes.NewBuffer(nil)\n\tif _, err := io.Copy(buf, output); err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to read remote state: %s\", err)\n\t}\n\tsum := md5.Sum(buf.Bytes())\n\tpayload := &remote.Payload{\n\t\tData: buf.Bytes(),\n\t\tMD5:  sum[:],","sourceCodeStart":402,"sourceCodeEnd":438,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/client.go#L402-L438","documentation":"Thrown by RemoteClient.getObj in the OSS backend when bucket.IsObjectExist(stateFile) returns an error (not the false 'absent' result). IsObjectExist issues a HEAD-style request; a transport/permission/SDK failure surfaces here before the code can decide whether the state object exists. The %#v dump exposes the SDK error shape.","triggerScenarios":"bucket.IsObjectExist(c.stateFile) returns err != nil in the getObj flow. Causes: insufficient RAM/STS permissions for HeadObject on the state key, transient network error to OSS, signature mismatch, or the bucket being deleted between Bucket() and this call.","commonSituations":"STS token granted Object Read but not HeadObject; VPC endpoint routing broken; state key path prefix wrong so the SDK hits a denied prefix; intermittent DNS failure against the OSS endpoint.","solutions":["Grant the RAM/STS principal `oss:HeadObject` and `oss:GetObject` on the state key ARN.","Retry `tofu init` - transient network errors to OSS are common and usually clear.","Verify network reachability of the OSS endpoint (VPC endpoints, proxy, DNS).","Confirm c.stateFile path spelling and prefix match the bucket layout."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// preflight: principal should have HeadObject on the state key; verify with a HEAD\nctx, cancel := context.WithTimeout(context.Background(), 10*time.Second)\ndefer cancel()\n// (SDK equivalent: bucket.GetObjectMeta with a short timeout to fail fast)","typeGuard":null,"tryCatchPattern":"var lastErr error\nfor i := 0; i < 3; i++ {\n    exist, err := bucket.IsObjectExist(c.stateFile)\n    if err == nil {\n        break\n    }\n    lastErr = err\ntime.Sleep(backoff)\n}\nif lastErr != nil { return lastErr }","preventionTips":["Grant HeadObject + GetObject on the state key to the principal.","Use a VPC endpoint for OSS to avoid transient public-internet failures.","Retry transient IsObjectExist failures before failing the run."],"tags":["oss","alibaba","permissions","network","head-object"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}