Skip to content

Use a diagnostic's stable code for automation. Its message explains the immediate problem; source validation also gives a sanitized path and range when available. Analysis diagnostics name a stage or instance when applicable. A warning about uncertain evidence is not proof of absence.

Severity by phase

PhaseTypical severityConsequence
Language discovery, parsing, compilationErrorInvalid source cannot be used
Plan/state input and saved-plan pairingError for refusal; warning for recoverable lost enrichmentInput may be refused or analyzed with less evidence
Instance interpretationError or warningAffected Rule or emission may remain undecided
ComparisonWarning or infoComparability or drift wording is constrained
Policy linking and evaluationErrorNo compliance decision from affected Policy
Form validationErrorForm refused

RF source diagnostics

These codes come from rootform validate dialects, definition validation, or Policy Pack compilation. All have error severity.

Discovery and parsing

CodeCause
ROOT_UNREADABLESource root cannot be read
FILE_UNREADABLEDiscovered source file cannot be read
FILE_NOT_REGULARMatching source path is not a regular file
SYMLINK_OUTSIDE_ROOTSymlink escapes the source root
NESTING_TOO_DEEPSource nesting exceeds 10,000 levels
HCL_PARSENative or JSON HCL syntax fails

Closed structure and values

CodeCause
UNKNOWN_ATTRIBUTEAttribute is outside the block schema
UNKNOWN_BLOCKBlock is outside the source-unit schema
INVALID_LABELBlock label count or identifier is invalid
MISSING_ATTRIBUTERequired attribute is absent
DUPLICATE_BLOCKA single-cardinality block appears more than once
INVALID_VALUEStatic value has wrong type, format, enum, or bound
INVALID_EXPRESSIONExpression is outside the closed language expression union
INVALID_REFERENCEReference or traversal has wrong shape, kind, root, or scope
DUPLICATE_IDCanonical identity is declared more than once
ARTIFACT_INVALIDCompiled artifact violates its language contract
COMPILER_FAILEDCompiler cannot produce a valid artifact

Dialect, definitions, and Rules

CodeCause
DIALECT_MISSINGSource root has no dialect declaration
DIALECT_DUPLICATESource root has more than one dialect declaration
DIALECT_RESERVEDDialect owner is reserved rf
PROVIDER_INVALIDProvider source address, label, or version constraint is invalid
PROVIDER_REQUIREDDialect has Rules but no provider declaration
CONCEPT_INVALIDConcept definition is invalid or exceeds its bound
CONTEXT_INVALIDContext definition is invalid or exceeds its bound
RELATION_INVALIDRelation definition is invalid or exceeds its bound
RULE_INVALIDRule lacks exactly one match, or its type is empty
RULE_NO_ARCHITECTURERule has no as, emission, or nonempty composition
MATCH_KIND_UNKNOWNmatch.kind is outside the closed 15-value set
PREDICATE_UNRESOLVEDAuthored predicate cannot compile safely
FACT_INVALIDEmission lacks to or via, or Context/Relation syntax is invalid
COMPOSITION_INVALIDComposition is empty or a member is malformed or out of order
CONCEPT_UNKNOWNConcept reference does not resolve in permitted scope
CONTEXT_UNKNOWNContext reference does not resolve in permitted scope
RELATION_UNKNOWNRelation reference does not resolve in permitted scope
RULE_UNKNOWNRule reference does not resolve in permitted scope
EMISSION_ON_NULL_REQUIRED, EMISSION_ON_EMPTY_REQUIREDEmission omits explicit null or empty behavior
MATCH_IDENTITY_UNDECLAREDmatch.by path is absent from target Rule identities
DISCLOSE_REQUIRES_EXTERNAL_ALLOWNon-default disclosure requires external = "allow"
PREFIX_REQUIRES_MATCHPrefix is declared without explicit target matching

Policy Pack source

CodeCause
PACK_MISSINGSource root has no policy_pack declaration
PACK_DUPLICATESource root has more than one policy_pack declaration
POLICY_NOT_ALLOWEDpolicy appears in a Dialect source root
POLICY_REFERENCE_UNQUALIFIEDPolicy semantic reference omits its owner
POLICY_INVALIDPolicy target, assertion, message, list, or built-in call is invalid

A Rule with only match returns RULE_NO_ARCHITECTURE. Add actual architecture meaning; do not silence the diagnostic with an arbitrary Concept. Test and validate shows the validation command.

Architecture interpretation diagnostics

Source and selection errors

CodeSeverityCause and next check
INPUT_UNRECOGNIZED, INPUT_INVALID, INPUT_UNREADABLE, INPUT_REFUSEDErrorInput shape, content, access, or allowed size is wrong; regenerate or inspect the export
PLAN_ERROREDErrorTerraform or OpenTofu marked the plan as errored; fix the plan failure and export again
PLAN_MASK_INVALIDWarningMalformed unknown/sensitive mask discards affected instance values; inspect the exported JSON
PLAN_FILE_REQUIRED, PLAN_FILE_UNREADABLE, PLAN_PAIR_MISMATCHError or warningSaved plan missing, unreadable, or not paired with plan JSON; repeat terraform show -json from the same saved plan
PROVIDER_UNBOUNDWarningObserved provider has no selected Dialect binding; inspect provider identity and selection
RULE_MATCH_AMBIGUOUSErrorMore than one selected Rule accepts the instance; narrow overlapping where predicates or the selected Dialect set. Provider source addresses determine binding; provider version constraints do not distinguish Rules.

Emission warnings

CodeSeverityCause and next check
EMISSION_PATH_UNDEFINEDWarningvia path is not defined on the emitted instance; correct the Dialect path
VIA_VALUE_SHAPEWarningEvaluated value has unsupported endpoint shape; choose a scalar or list of scalars
DUPLICATE_IDENTITYWarningMultiple eligible target instances share the matched identity; refine target identity
EVIDENCE_CONFLICTWarningKnown value and verified traversal identify different endpoints; inspect source and Rule declarations

Comparison diagnostics

CodeSeverityCause
CROSS_INPUT_NOT_DRIFTInfoDifference between two inputs is a comparison, not drift reported by Terraform or OpenTofu
RELEASE_SET_MISMATCH, SELECTION_MISMATCHWarningComparison sides use incompatible semantic selection

An indeterminate closure records a reason such as unknown_until_apply, sensitive, ambiguous_unknown, uncomparable_candidate, duplicate_identity, identity_incomplete, reference_ambiguous, unavailable, or external_denied. These are closure reasons, not interchangeable diagnostic codes. For via = provider.<path>, unavailable includes a missing verified Planned-stage reference; a literal provider value is never read. See Fact emissions.

Policy linking and evaluation diagnostics

CodeMeaning
POLICY_OWNER_UNKNOWN, POLICY_CONCEPT_UNKNOWN, POLICY_CONTEXT_UNKNOWN, POLICY_RELATION_UNKNOWN, POLICY_RULE_UNKNOWNReferenced owner or definition unavailable
POLICY_TARGET_CONTRADICTORYTarget filters cannot select a compatible Rule
POLICY_SEMANTICS_MISMATCH, POLICY_ARCHITECTURE_INVALIDPack and Form cannot be safely evaluated together
POLICY_STAGE_MISSINGRequested evaluation stage is unavailable
POLICY_LIMIT_EXCEEDED, POLICY_PACK_DUPLICATEEvaluation bound or Pack identity invalid
POLICY_SELECTION_INVALIDA selected Policy is not declared by a linked Policy Pack
POLICY_UNAVAILABLENo Policy Pack is selected; check exits 3

An unknown assertion or incomplete target domain produces an indeterminate evaluation, not a violation or pass. The Policy result and its diagnostics identify the affected target; see Evaluation.

Form validation

rootform validate form analysis.json checks a saved Form. The validator reports a dotted field path and one of these code groups:

CodesFault
DOCUMENT_JSON_INVALID, DOCUMENT_TRAILING_CONTENT, DOCUMENT_FIELD_UNKNOWNJSON or unknown field
DOCUMENT_FORMAT_UNSUPPORTED, DOCUMENT_KIND_INVALID, DOCUMENT_GENERATOR_INVALID, DOCUMENT_STAGE_INVALIDEnvelope or stage
DOCUMENT_FIELD_REQUIRED, DOCUMENT_FIELD_FORBIDDEN, DOCUMENT_VOCABULARY_INVALIDField presence or closed vocabulary
DOCUMENT_ID_INVALID, DOCUMENT_ID_DUPLICATE, DOCUMENT_REFERENCE_MISSINGIdentity or reference
DOCUMENT_CLOSURE_INCOMPLETE, DOCUMENT_CLOSURE_EXTRA, DOCUMENT_ACCOUNTING_MISMATCH, DOCUMENT_INCONSISTENTClosure or cross-field accounting

DOCUMENT_INVALID or ANALYSIS_INVALID marks a refused Form at a command boundary. A rejected Form cannot support a no-change or compliance conclusion. Regenerate it from the original plan or state JSON rather than editing evidence to satisfy validation.

Limits

Input documents

ItemLimit
Plan JSON, state JSON, or saved Form128 MiB per document

Rootform applies this document-read ceiling before decoding each input. It is separate from the 16 MiB serialized-input limit for a compiled Policy Pack.

Exceeding a limit fails closed. These bounds are part of the language and evaluation contract.

RF source and artifact

ItemLimit
Source nesting10,000 levels
Identifier64 bytes
Definition description1,024 UTF-8 bytes
Policy message1–1,024 UTF-8 bytes
Authored expression4,096 source bytes
Compiled expression depth64
Compiled expression nodes1,024 per expression

Compiled Policy Pack

ItemLimit
Serialized compiled Policy Pack input16 MiB
Policies and semantic pins1,024 each
Rule references or Dialect owners per Policy target1,024 each
Aggregate expression nodes65,536
Aggregate string bytes4 MiB
One serialized string4,096 bytes
JSON nesting80 levels
JSON values2,097,152

One Policy evaluation run

ItemLimit
Policies1,024
Per-target evaluations100,000
Inspected fact references100,000

Architecture compilation

ItemLimit
Semantic definitions200,000
Architecture objects200,000
Active Rule-emission pairs200,000
Provenance records per fact1,024

A limit failure cannot be treated as a partial pass. See Test and validate for the authoring sequence that exposes source and fixture problems before distribution.

Fixing a diagnostic

  1. Use the stable code to identify the phase and construct.
  2. Read its sanitized source range or Form path.
  3. Fix the earliest source error first; later references may depend on it.
  4. Repeat source validation and the affected fixture or rootform check.

Keep warnings as incomplete evidence until the instance and closure explain them.