hashicorp/terraform · error

Error unlocking Alibaba Cloud OSS state file: Lock ID

Error message

Error unlocking Alibaba Cloud OSS state file:

Lock ID: %s
Error message: %#v

You may have to force-unlock this state in order to use it again.
The Alibaba Cloud backend acquires a lock during initialization to ensure the initial state file is created.

What it means

Thrown by the lockUnlock helper inside StateMgr init: after acquiring the OSS state lock and then encountering an error during RefreshState/state-write, the backend tried to release the lock (stateMgr.Unlock) and that unlock itself failed. The user is told the lock ID and advised to force-unlock manually.

Solutions

  1. Record the reported Lock ID and run 'terraform force-unlock <LOCK_ID>'.
  2. Verify OTS credentials still have ots:DeleteRow on the lock table.
  3. Confirm OTS endpoint reachability and retry the init.
  4. Investigate why the original RefreshState failed to prevent repeated lock-then-fail cycles.
Defensive patterns

Strategy: try-catch

Try / catch

// If unlock fails during cleanup, report the lock ID for manual force-unlock.
if err := stateMgr.Unlock(lockId); err != nil {
    return fmt.Errorf("unlock failed; run 'terraform force-unlock %s': %w", lockId, err)
}

Prevention

When it happens

Trigger: Unlock(lockId) returned an error while cleaning up after a prior failure during state initialization. The OTS DeleteRow to release the lock failed — credentials, endpoint, or the lock row changed between acquire and release.

Common situations: Credentials rotated between lock and unlock; OTS transient failure; lock row manually removed mid-init; permission revoked mid-run. The state is now stranded behind an unreleased lock.

Related errors


AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11). Data as JSON: /api/errors/b570370c2dc11344. Report an issue: GitHub.

Appendix: source

Thrown at internal/backend/remote-state/oss/backend_state.go:157

		if s == name {
			exists = true
			break
		}
	}
	// We need to create the object so it's listed by States.
	if !exists {
		// take a lock on this state while we write it
		lockInfo := statemgr.NewLockInfo()
		lockInfo.Operation = "init"
		lockId, err := client.Lock(lockInfo)
		if err != nil {
			return nil, diags.Append(fmt.Errorf("failed to lock OSS state: %s", err))
		}

		// Local helper function so we can call it multiple places
		lockUnlock := func(e error) error {
			if err := stateMgr.Unlock(lockId); err != nil {
				return fmt.Errorf(strings.TrimSpace(stateUnlockError), lockId, err)
			}
			return e
		}

		// Grab the value
		if err := stateMgr.RefreshState(); err != nil {
			err = lockUnlock(err)
			return nil, diags.Append(err)
		}

		// If we have no state, we have to create an empty state
		if v := stateMgr.State(); v == nil {
			if err := stateMgr.WriteState(states.NewState()); err != nil {
				err = lockUnlock(err)
				return nil, diags.Append(err)
			}
			if err := stateMgr.PersistState(nil); err != nil {
				err = lockUnlock(err)

View on GitHub (pinned to d32a084675)