{"record":{"id":"f9b968d29348d949","repo":"hashicorp/terraform","slug":"invalid-md5-f9b968","errorCode":null,"errorMessage":"invalid md5","messagePattern":"invalid md5","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/s3/client.go","lineNumber":621,"sourceCode":"\t\tTableName:            aws.String(c.ddbTable),\n\t\tConsistentRead:       aws.Bool(true),\n\t}\n\n\tresp, err := c.dynClient.GetItem(ctx, getParams)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"Unable to retrieve item from DynamoDB table %q: %w\", c.ddbTable, err)\n\t}\n\n\tvar val string\n\tif v, ok := resp.Item[\"Digest\"]; ok {\n\t\tif v, ok := v.(*dynamodbtypes.AttributeValueMemberS); ok {\n\t\t\tval = v.Value\n\t\t}\n\t}\n\n\tsum, err := hex.DecodeString(val)\n\tif err != nil || len(sum) != md5.Size {\n\t\treturn nil, errors.New(\"invalid md5\")\n\t}\n\n\treturn sum, nil\n}\n\n// store the hash of the state so that clients can check for stale state files.\nfunc (c *RemoteClient) putMD5(ctx context.Context, sum []byte) error {\n\tif c.ddbTable == \"\" {\n\t\treturn nil\n\t}\n\n\tif len(sum) != md5.Size {\n\t\treturn errors.New(\"invalid payload md5\")\n\t}\n\n\tputParams := &dynamodb.PutItemInput{\n\t\tItem: map[string]dynamodbtypes.AttributeValue{\n\t\t\t\"LockID\": &dynamodbtypes.AttributeValueMemberS{","sourceCodeStart":603,"sourceCodeEnd":639,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/s3/client.go#L603-L639","documentation":"Computed and Required are mutually exclusive on an Attribute. Required forces the user to supply the value, while Computed means the provider supplies it — the combination is contradictory. Note that Computed+Optional is permitted (user may override a provider-supplied default).","triggerScenarios":"An Attribute with both Computed: true and Required: true. Guard at internal_validate.go:152 is `a.Computed && a.Required`.","commonSituations":"Marking a previously-required attribute as Computed without clearing Required; misunderstanding and thinking Computed+Required means 'provider fills if user omits'.","solutions":["If the provider supplies the value but the user may override, use Optional: true, Computed: true (drop Required).","If the user must always set it, drop Computed and keep Required."],"exampleFix":"// before\n\"region\": { Type: cty.String, Required: true, Computed: true },\n// after\n\"region\": { Type: cty.String, Optional: true, Computed: true },","handlingStrategy":"validation","validationCode":"// Computed and Required are mutually exclusive.\nfunc notComputedAndRequired(a *configschema.Attribute) bool {\n    return a == nil || !(a.Computed && a.Required)\n}","typeGuard":"func notBoth(computed, required bool) bool { return !(computed && required) }","tryCatchPattern":null,"preventionTips":["Drop Required when you add Computed; use Optional+Computed for overrides.","Treat Required+Computed as a schema smell and reject it in review.","Lint flag combinations in CI."],"tags":["schema-validation","configschema","attribute","computed","required","provider-schema"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}