Upstream Patches
upstream/ is a git submodule pointing to the upstream Terraform provider. patches/ contains patch files applied on top of it. Use ./scripts/upstream.sh to manage patch state.
Default Behavior
- If fixing a regression introduced by an existing patch, amend the owning patch commit.
- Do not create a new patch unless the user explicitly asks.
Commands Reference
Guardrails
- Never commit directly to
upstream/withoutcheckout/check_in. - Direct edits under
upstream/outside checkout are ephemeral duringupgrade-provider; the tool resets submodule state. - Do not hand-edit
patches/*.patchunless intentionally doing raw patch surgery. - Prefer non-interactive rewrite flow over interactive rebase for agents.
Find Owning Patch First
Before editing patch content, identify the owning patch/commit.
If rg is unavailable, use grep -En for the patch search. Set target_sha to the owning commit and edit that commit, not HEAD.
Amend Existing Patch (Preferred, Non-Interactive)
Interactive fallback:
Remove Entire Patch
Use when a patch should be deleted completely.
Remove Part of a Patch
Use when only selected hunks/files should be removed from an existing patch.
- Find owning patch/commit (
target_sha) and use the amend workflow above. - Revert only unwanted changes from the target commit, then amend.
Example during amend step:
Create New Patch (Only If Requested)
Rebasing Patches to a New Upstream Version
Verification Checklist
Before check_in:
- Confirm expected patch count change (
0by default;-1for full patch removal). - Confirm whether target patch should remain present (default yes) or be removed (explicit deletion case).
- Confirm you are editing the owning commit, not adding a new commit by accident.
After check_in:
- Verify patch count matches expectation.
- Verify target patch number/purpose is still present when expected.
- Verify no unexpected new
00NN-*.patchwas introduced.
Interrupted Checkout or Rebase
Preserve work by default. Inspect git -C upstream status, complete the active git am/rebase, verify that every patch was applied, and run ./scripts/upstream.sh check_in before rerunning automation. An interrupted checkout invokes git am separately for each patch, so later patch files may not have been reached.
Use ./scripts/upstream.sh init -f only when intentionally discarding all interrupted work. It can remove conflict resolution, patch commits, operation metadata, and untracked files; it is not routine recovery for a stuck checkout.


