Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(misconf): properly expand dynamic blocks #7612

Merged
merged 5 commits into from
Oct 19, 2024

Conversation

nikpivkin
Copy link
Contributor

@nikpivkin nikpivkin commented Sep 28, 2024

Description

This PR separates the logic for expanding dynamic blocks from expanding the for-each meta argument.

Related issues

Checklist

  • I've read the guidelines for contributing to this repository.
  • I've followed the conventions in the PR title.
  • I've added tests that prove my fix is effective or that my feature works.
  • I've updated the documentation with the relevant information (if needed).
  • I've added usage information (if the PR introduces new options)
  • I've included a "before" and "after" example to the description (if the PR is a user interface change).

Signed-off-by: nikpivkin <nikita.pivkin@smartforce.io>
Signed-off-by: nikpivkin <nikita.pivkin@smartforce.io>
@nikpivkin nikpivkin marked this pull request as ready for review October 7, 2024 03:15
@nikpivkin nikpivkin requested a review from simar7 as a code owner October 7, 2024 03:16
@@ -567,7 +567,7 @@ resource "something" "else" {
for_each = toset(["true"])

content {
ok = each.value
ok = blah.value
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For reviewers: this test should not have run successfully because dynamic blocks do not create an each object.

nikpivkin and others added 2 commits October 17, 2024 11:54
Signed-off-by: nikpivkin <nikita.pivkin@smartforce.io>
Comment on lines 694 to 696
if forEachVal.IsNull() || !forEachVal.IsKnown() {
return cty.NilVal, errors.New("cannot use a null or unknown value in for_each")
}
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In my coverage this seems to be untested so I decided to investigate. Would this ever be reached since we already check for !forEachVal.CanIterateElements() prior to this? If you have a sample input, it'd be nice to understand.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, this check is unreachable, I removed it. 4d3de2a

Signed-off-by: nikpivkin <nikita.pivkin@smartforce.io>
@simar7 simar7 self-requested a review October 19, 2024 00:55
@simar7 simar7 added this pull request to the merge queue Oct 19, 2024
Merged via the queue into aquasecurity:main with commit 8d5dbc9 Oct 19, 2024
12 checks passed
@wplj
Copy link

wplj commented Nov 4, 2024

It looks like the issue is still there (0.57.0):

2024-11-04T11:26:35+01:00       ERROR   [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.  block="module.app_vm.azurerm_backup_protected_vm.this" value="cty.NilVal"

I'm using the same module as before (https://github.com/Azure/terraform-azurerm-avm-res-compute-virtualmachine/blob/main/main.backup.tf)

@nikpivkin nikpivkin deleted the tf-dyn branch November 8, 2024 06:05
@stewartcampbell
Copy link

I'm seeing similar issues still with 0.57.0:

2024-11-12T11:44:53Z    ERROR   [terraform evaluator] Failed to expand block. Invalid "for-each" argument. Must be known and iterable.  block="data.aws_subnet.ecs_cluster_vpc_private" value="cty.NilVal"
2024-11-12T11:44:53Z    ERROR   [terraform evaluator] Failed to expand dynamic block.   block="module.ecs_service.aws_ecs_service.aurora" err="2 errors occurred:\n\t* invalid for-each in aws_ecs_service.aurora.dynamic.ordered_placement_strategy block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\t* invalid for-each in aws_ecs_service.aurora.dynamic.ordered_placement_strategy block: cannot use a cty.NilVal value in for_each. An iterable collection is required\n\n"

@nikpivkin
Copy link
Contributor Author

nikpivkin commented Nov 12, 2024

Hi @stewartcampbell !

You are using blocks of data that cannot be analyzed statically in some cases #7731 (comment)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment