{"record":{"id":"fc371d6669bdfdfd","repo":"hashicorp/terraform","slug":"failed-to-upload-part-d-w","errorCode":null,"errorMessage":"failed to upload part %d: %w","messagePattern":"failed to upload part (.+?): %w","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oci/multipart_upload.go","lineNumber":241,"sourceCode":"\t\t\tUploadPartBody: io.NopCloser(bytes.NewReader(buffer)),\n\t\t\tUploadPartNum:  block.blockNumber,\n\t\t\tContentMD5:     common.String(base64.StdEncoding.EncodeToString(sum[:])),\n\t\t\tRequestMetadata: common.RequestMetadata{\n\t\t\t\tRetryPolicy: getDefaultRetryPolicy(),\n\t\t\t},\n\t\t}\n\n\t\tif ctx.client.kmsKeyID != \"\" {\n\t\t\tuploadPartRequest.OpcSseKmsKeyId = common.String(ctx.client.kmsKeyID)\n\t\t} else if ctx.client.SSECustomerKey != \"\" && ctx.client.SSECustomerKeySHA256 != \"\" {\n\t\t\tuploadPartRequest.OpcSseCustomerKey = common.String(ctx.client.SSECustomerKey)\n\t\t\tuploadPartRequest.OpcSseCustomerKeySha256 = common.String(ctx.client.SSECustomerKeySHA256)\n\t\t\tuploadPartRequest.OpcSseCustomerAlgorithm = common.String(ctx.client.SSECustomerAlgorithm)\n\t\t}\n\n\t\tresponse, err := ctx.client.objectStorageClient.UploadPart(context.Background(), *uploadPartRequest)\n\t\tif err != nil {\n\t\t\tctx.errChan <- fmt.Errorf(\"failed to upload part %d: %w\", *block.blockNumber, err)\n\t\t\treturn\n\t\t}\n\t\tctx.osUploadPartResponses <- objectStorageUploadPartResponse{\n\t\t\tresponse:   response,\n\t\t\terror:      nil,\n\t\t\tpartNumber: block.blockNumber,\n\t\t}\n\t\tctx.wg.Done()\n\n\t}\n}\n","sourceCodeStart":223,"sourceCodeEnd":253,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oci/multipart_upload.go#L223-L253","documentation":"Thrown by uploadPartsWorker() when the OCI SDK's UploadPart API call fails for a specific part during multipart state upload. This is the most common multipart error — it wraps the underlying OCI SDK error (network failure, authentication issue, throttling, or service error) with the failing part number for diagnostics.","triggerScenarios":"ctx.client.objectStorageClient.UploadPart(context.Background(), *uploadPartRequest) returns a non-nil error. The part request includes uploadId, object name, namespace, bucket, content length, body, and part number. Common triggers: expired session token, network timeout to OCI Object Storage, bucket not found, KMS key access denied, or SSE customer key mismatch.","commonSituations":"Transient network issues during large state uploads (>128MB). Expired or rotated OCI API keys. IAM policy missing objectstorage:ObjectPutPart permission. KMS key ID configured but not accessible. Running in a restricted network (corporate proxy, VCN without Service Gateway for Object Storage).","solutions":["Check OCI IAM credentials — run 'oci os ns get' to verify the profile can access Object Storage.","Verify the bucket exists and the IAM user has ObjectPutPart and ObjectManageReadAccess permissions.","If using KMS (kms_key_id), ensure the key is enabled and the user has keys/Decrypt and keys/Encrypt permissions.","Check network connectivity to Object Storage — add a Service Gateway to the VCN for OCI-native access.","Retry the operation — transient throttling (429) or service errors (5xx) are common for large uploads."],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// Pre-flight check: verify OCI credentials and bucket access before multipart upload\nfunc verifyOCIAccess(client *objectstorage.ObjectStorageClient, namespace, bucket string) error {\n    req := objectstorage.HeadBucketRequest{\n        NamespaceName: common.String(namespace),\n        BucketName:    common.String(bucket),\n    }\n    _, err := client.HeadBucket(context.Background(), req)\n    return err\n}","typeGuard":null,"tryCatchPattern":"// Retry UploadPart failures with exponential backoff\nmaxRetries := 3\nfor attempt := 0; attempt < maxRetries; attempt++ {\n    response, err = ctx.client.objectStorageClient.UploadPart(context.Background(), *uploadPartRequest)\n    if err == nil {\n        break\n    }\n    if attempt < maxRetries-1 {\n        time.Sleep(time.Duration(1<<attempt) * time.Second)\n        // Rebuild request body if needed — the reader may have been consumed\n        uploadPartRequest.UploadPartBody = io.NopCloser(bytes.NewReader(buffer))\n    }\n}","preventionTips":["Verify OCI IAM credentials and Object Storage permissions before running Terraform.","Configure a Service Gateway in the VCN for reliable, low-latency Object Storage access.","Ensure KMS key IDs in the backend config are valid and accessible.","Use OCI's default retry policy (already set via RequestMetadata in the upload data)."],"tags":["oci","multipart-upload","network","authentication","object-storage"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}