hashicorp/terraform · error
encountered a malformed backend state file with a…
Error message
encountered a malformed backend state file with a 'state_store' block that is missing the required 'provider_supply_mode' property
What it means
ParseBackendStateFile decoded a state_store block but its required `provider_supply_mode` property is empty/missing. ProviderSupplyMode drives how Terraform sources the state-store's nested provider (built-in, managed-by-terraform, reattached, dev-override); without it later code would crash on an empty version, so parsing fails fast with a clear message instead.
Solutions
- Re-run `terraform init` so the state_store block is rewritten with all required fields.
- Verify you are on a Terraform/OpenTofu version that actually supports state_store — older versions never wrote this field.
- Delete the corrupt file and re-init from your state_store configuration block.
Example fix
rm .terraform/terraform.tfstate terraform init
Defensive patterns
Strategy: validation
Validate before calling
// pre-flight: require provider_supply_mode on state_store
var probe struct {
StateStore *struct {
Mode string `json:"provider_supply_mode"`
} `json:"state_store"`
}
_ = json.Unmarshal(src, &probe)
if probe.StateStore != nil && probe.StateStore.Mode == "" {
return nil, errors.New("state_store block missing provider_supply_mode; re-run `terraform init`")
} Prevention
- Stay on a Terraform/OpenTofu version that supports state_store end-to-end.
- Don't hand-edit the state_store section.
When it happens
Trigger: A .terraform/terraform.tfstate with a `state_store` object that omits `provider_supply_mode`. Possible causes: hand-editing, a buggy/old fork that didn't write the field, or a file truncated mid-write.
Common situations: Pre-release or experimental state_store support that predates the field, third-party tooling that wrote an incomplete state_store block, or filesystem-level tampering.
Understand the failure class
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- attempted to encode a malformed backend state file…
- attempted to encode a malformed backend state file…
- encountered a malformed backend state file that contains…
- attempted to encode a malformed backend state file; it…
- attempted to encode a malformed backend state file; state…
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/441bf995c0a5f7cd.
Report an issue: GitHub.
Appendix: source
Thrown at internal/command/workdir/backend_state.go:116
var stateFile BackendStateFile
err = json.Unmarshal(src, &stateFile)
if err != nil {
return nil, fmt.Errorf("invalid syntax: %w", err)
}
if stateFile.Backend == nil && stateFile.Remote != nil {
// It's very unlikely to get here, but one way it could happen is
// if this working directory was most recently used with Terraform v0.8
// or earlier, which didn't yet include the concept of backends.
// This error message assumes that's the case.
return nil, fmt.Errorf("this working directory uses legacy remote state and so must first be upgraded using Terraform v0.9")
}
if stateFile.Backend != nil && stateFile.StateStore != nil {
return nil, fmt.Errorf("encountered a malformed backend state file that contains state for both a 'backend' and a 'state_store' block")
}
if stateFile.StateStore != nil && stateFile.StateStore.ProviderSupplyMode == "" {
// Check for this, as lacking this data can cause problems later when an empty provider version
// is encountered. This error will make debugging much easier.
return nil, fmt.Errorf("encountered a malformed backend state file with a 'state_store' block that is missing the required 'provider_supply_mode' property")
}
return &stateFile, nil
}
func EncodeBackendStateFile(f *BackendStateFile) ([]byte, error) {
f.Version = 3 // we only support version 3
f.TFVersion = version.SemVer.String()
switch {
case f.Backend != nil && f.StateStore != nil:
return nil, fmt.Errorf("attempted to encode a malformed backend state file; it contains state for both a 'backend' and a 'state_store' block. This is a bug in Terraform and should be reported.")
case f.Backend == nil && f.StateStore == nil:
// This is valid - if the user has a backend state file and an implied local backend in use
// the backend state file exists but has no Backend data.
case f.Backend != nil:
// Not implementing anything here - risk of breaking changes
case f.StateStore != nil:View on GitHub (pinned to d32a084675)