{"record":{"id":"0651a9a1232535fd","repo":"grpc/grpc-go","slug":"outlierdetectionloadbalancingconfig-max-ejection-p","errorCode":null,"errorMessage":"OutlierDetectionLoadBalancingConfig.max_ejection_percent = %v; must be <= 100","messagePattern":"OutlierDetectionLoadBalancingConfig\\.max_ejection_percent = (.+?); must be <= 100","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/balancer/outlierdetection/balancer.go","lineNumber":143,"sourceCode":"\t// google.protobuf.Duration documentation and they must have non-negative\n\t// values.\" - A50\n\t// Approximately 290 years is the maximum time that time.Duration (int64)\n\t// can represent. The restrictions on the protobuf.Duration field are to be\n\t// within +-10000 years. Thus, just check for negative values.\n\tcase lbCfg.Interval < 0:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.interval = %s; must be >= 0\", lbCfg.Interval)\n\tcase lbCfg.BaseEjectionTime < 0:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.base_ejection_time = %s; must be >= 0\", lbCfg.BaseEjectionTime)\n\tcase lbCfg.MaxEjectionTime < 0:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.max_ejection_time = %s; must be >= 0\", lbCfg.MaxEjectionTime)\n\n\t// \"The fields max_ejection_percent,\n\t// success_rate_ejection.enforcement_percentage,\n\t// failure_percentage_ejection.threshold, and\n\t// failure_percentage.enforcement_percentage must have values less than or\n\t// equal to 100.\" - A50\n\tcase lbCfg.MaxEjectionPercent > 100:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.max_ejection_percent = %v; must be <= 100\", lbCfg.MaxEjectionPercent)\n\tcase lbCfg.SuccessRateEjection != nil && lbCfg.SuccessRateEjection.EnforcementPercentage > 100:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.SuccessRateEjection.enforcement_percentage = %v; must be <= 100\", lbCfg.SuccessRateEjection.EnforcementPercentage)\n\tcase lbCfg.FailurePercentageEjection != nil && lbCfg.FailurePercentageEjection.Threshold > 100:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.FailurePercentageEjection.threshold = %v; must be <= 100\", lbCfg.FailurePercentageEjection.Threshold)\n\tcase lbCfg.FailurePercentageEjection != nil && lbCfg.FailurePercentageEjection.EnforcementPercentage > 100:\n\t\treturn nil, fmt.Errorf(\"OutlierDetectionLoadBalancingConfig.FailurePercentageEjection.enforcement_percentage = %v; must be <= 100\", lbCfg.FailurePercentageEjection.EnforcementPercentage)\n\t}\n\treturn lbCfg, nil\n}\n\nfunc (bb) Name() string {\n\treturn Name\n}\n\n// scUpdate wraps a subConn update to be sent to the child balancer.\ntype scUpdate struct {\n\tscw   *subConnWrapper\n\tstate balancer.SubConnState","sourceCodeStart":125,"sourceCodeEnd":161,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/balancer/outlierdetection/balancer.go#L125-L161","documentation":"Per gRFC A50, OutlierDetectionLoadBalancingConfig.max_ejection_percent must be <= 100. ParseConfig checks lbCfg.MaxEjectionPercent > 100 and rejects it (balancer.go:142-143). The field caps how many endpoints may be ejected at once; values over 100 make no sense.","triggerScenarios":"lbCfg.MaxEjectionPercent > 100 after JSON unmarshaling (e.g. \"max_ejection_percent\": 150).","commonSituations":"Manual config with a percentage over 100; typo; control plane misconfiguration bypassing xdsclient validation.","solutions":["Set max_ejection_percent to a value in [0, 100] (A50 default is 10).","Validate the percentage range before constructing the config."],"exampleFix":"// before\ncfg.MaxEjectionPercent = 150\n// after\ncfg.MaxEjectionPercent = 10","handlingStrategy":"validation","validationCode":"func validateMaxEjectionPercent(p uint32) error {\n    if p > 100 { return fmt.Errorf(\"max_ejection_percent must be <= 100, got %d\", p) }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Default MaxEjectionPercent to 10 per A50.","Range-check every percentage field (0..100) before building the LBConfig.","Add a unit test that asserts all percentage fields stay in range."],"tags":["go","grpc","xds","outlier-detection","validation","percentage"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}