hashicorp/terraform · error
Error unlocking Alibaba Cloud OSS state file: Lock ID
Error message
Error unlocking Alibaba Cloud OSS state file: Lock ID: %s Error message: %#v You may have to force-unlock this state in order to use it again. The Alibaba Cloud backend acquires a lock during initialization to ensure the initial state file is created.
What it means
Thrown by the lockUnlock helper inside StateMgr init: after acquiring the OSS state lock and then encountering an error during RefreshState/state-write, the backend tried to release the lock (stateMgr.Unlock) and that unlock itself failed. The user is told the lock ID and advised to force-unlock manually.
Solutions
- Record the reported Lock ID and run 'terraform force-unlock <LOCK_ID>'.
- Verify OTS credentials still have ots:DeleteRow on the lock table.
- Confirm OTS endpoint reachability and retry the init.
- Investigate why the original RefreshState failed to prevent repeated lock-then-fail cycles.
Defensive patterns
Strategy: try-catch
Try / catch
// If unlock fails during cleanup, report the lock ID for manual force-unlock.
if err := stateMgr.Unlock(lockId); err != nil {
return fmt.Errorf("unlock failed; run 'terraform force-unlock %s': %w", lockId, err)
} Prevention
- Train operators to capture the lock ID from the error and run force-unlock.
- Investigate recurring lock-then-fail patterns (the original RefreshState error) rather than just unlocking.
- Verify OTS DeleteRow permission persists for the whole run.
When it happens
Trigger: Unlock(lockId) returned an error while cleaning up after a prior failure during state initialization. The OTS DeleteRow to release the lock failed — credentials, endpoint, or the lock row changed between acquire and release.
Common situations: Credentials rotated between lock and unlock; OTS transient failure; lock row manually removed mid-init; permission revoked mid-run. The state is now stranded behind an unreleased lock.
Related errors
- failed to lock OSS state
- invoking PutRow got an error: %#v
- failed to retrieve lock info
- getting lock info got an error: %#v
- error describing table store
AI-assisted analysis of hashicorp/terraform@d32a084675 (2026-08-11).
Data as JSON: /api/errors/b570370c2dc11344.
Report an issue: GitHub.
Appendix: source
Thrown at internal/backend/remote-state/oss/backend_state.go:157
if s == name {
exists = true
break
}
}
// We need to create the object so it's listed by States.
if !exists {
// take a lock on this state while we write it
lockInfo := statemgr.NewLockInfo()
lockInfo.Operation = "init"
lockId, err := client.Lock(lockInfo)
if err != nil {
return nil, diags.Append(fmt.Errorf("failed to lock OSS state: %s", err))
}
// Local helper function so we can call it multiple places
lockUnlock := func(e error) error {
if err := stateMgr.Unlock(lockId); err != nil {
return fmt.Errorf(strings.TrimSpace(stateUnlockError), lockId, err)
}
return e
}
// Grab the value
if err := stateMgr.RefreshState(); err != nil {
err = lockUnlock(err)
return nil, diags.Append(err)
}
// If we have no state, we have to create an empty state
if v := stateMgr.State(); v == nil {
if err := stateMgr.WriteState(states.NewState()); err != nil {
err = lockUnlock(err)
return nil, diags.Append(err)
}
if err := stateMgr.PersistState(nil); err != nil {
err = lockUnlock(err)View on GitHub (pinned to d32a084675)