{"record":{"id":"07d3a91c38f95e43","repo":"grpc/grpc-go","slug":"gcpauthn-failed-to-unmarshal-filter-config-v","errorCode":null,"errorMessage":"gcpauthn: failed to unmarshal filter config: %v","messagePattern":"gcpauthn: failed to unmarshal filter config: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go","lineNumber":69,"sourceCode":"type builder struct{}\n\ntype config struct {\n\thttpfilter.FilterConfig\n\tcacheSize uint64\n}\n\nfunc (builder) TypeURLs() []string {\n\treturn []string{\"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig\"}\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"gcpauthn: invalid filter config type %T\", cfg)\n\t}\n\tmsg := &v3gcpauthnpb.GcpAuthnFilterConfig{}\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"gcpauthn: failed to unmarshal filter config: %v\", err)\n\t}\n\n\tcacheSize := uint64(defaultCacheSize)\n\tif cacheSizeConfig := msg.GetCacheConfig().GetCacheSize(); cacheSizeConfig != nil {\n\t\tif cacheSize = cacheSizeConfig.GetValue(); cacheSize == 0 {\n\t\t\treturn nil, fmt.Errorf(\"gcpauthn: cache_config.cache_size must be greater than zero\")\n\t\t}\n\t}\n\n\treturn config{cacheSize: cacheSize}, nil\n}\n\n// ParseFilterConfigOverride parses the provided override configuration.\n//\n// Note that we don't support overrides for this filter configuration,\n// but still validate it as part of the normal resource validation.\nfunc (b builder) ParseFilterConfigOverride(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\treturn b.ParseFilterConfig(cfg)","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/gcp_authn/gcp_authn_filter.go#L51-L87","documentation":"ParseFilterConfig (gcp_authn_filter.go:68) type-asserted *anypb.Any but UnmarshalTo into GcpAuthnFilterConfig failed. The wrapped bytes are not a valid GcpAuthnFilterConfig: wrong type URL, corrupt payload, or schema mismatch.","triggerScenarios":"anypb.Any with a mismatched type URL, truncated/malformed bytes, or a go-control-plane version whose GcpAuthnFilterConfig schema differs from the client's compiled proto.","commonSituations":"Version skew between control-plane and data-plane; corrupted config in transit; wrong filter config bound to the gcp_authn TypeURL.","solutions":["Ensure the anypb.Any type_url is type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig.","Align go-control-plane versions between server and client.","Log the wrapped error to distinguish type-URL mismatch from wire-format errors."],"exampleFix":"// before\nanyCfg := &anypb.Any{TypeUrl: \"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v2.GcpAuthnFilterConfig\", Value: raw}\n\n// after\nanyCfg := &anypb.Any{TypeUrl: \"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig\", Value: raw}","handlingStrategy":"validation","validationCode":"if m, ok := cfg.(*anypb.Any); ok {\n    want := \"type.googleapis.com/envoy.extensions.filters.http.gcp_authn.v3.GcpAuthnFilterConfig\"\n    if m.TypeUrl != want {\n        return nil, fmt.Errorf(\"gcpauthn: type_url %q != %q\", m.TypeUrl, want)\n    }\n}","typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"failed to unmarshal filter config\") {\n    // log err to distinguish type-URL mismatch from wire corruption\n}","preventionTips":["Pin go-control-plane versions across server and client.","Validate the Any.TypeUrl against TypeURLs() before unmarshalling.","Round-trip test GcpAuthnFilterConfig through ParseFilterConfig."],"tags":["gcp-authn","config","protobuf","xds","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}