{"record":{"id":"0b2281f442437741","repo":"grpc/grpc-go","slug":"received-frame-with-incorrect-message-type-v-exp","errorCode":null,"errorMessage":"received frame with incorrect message type %v, expected lower byte %v","messagePattern":"received frame with incorrect message type (.+?), expected lower byte (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/alts/internal/conn/record.go","lineNumber":273,"sourceCode":"\t\t\t\tnRead, err := p.Conn.Read(protected[len(protected):cap(protected)])\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn nil, 0, err\n\t\t\t\t}\n\t\t\t\tprotected = protected[:len(protected)+nRead]\n\t\t\t}\n\t\t\tframedMsg, p.nextFrame, err = ParseFramedMsg(protected, altsRecordLengthLimit)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, 0, err\n\t\t\t}\n\t\t}\n\t\t// Now we have a complete frame, decrypted it.\n\t\tmsg := framedMsg[MsgLenFieldSize:]\n\t\tif len(msg) < msgTypeFieldSize {\n\t\t\treturn nil, 0, fmt.Errorf(\"received frame with size %v which is shorter than message type field size %v\", len(msg), msgTypeFieldSize)\n\t\t}\n\t\tmsgType := binary.LittleEndian.Uint32(msg[:msgTypeFieldSize])\n\t\tif msgType&0xff != altsRecordMsgType {\n\t\t\treturn nil, 0, fmt.Errorf(\"received frame with incorrect message type %v, expected lower byte %v\",\n\t\t\t\tmsgType, altsRecordMsgType)\n\t\t}\n\t\tciphertext := msg[msgTypeFieldSize:]\n\n\t\t// Decrypt directly into the buffer, avoiding a copy from p.buf if\n\t\t// possible.\n\t\tif bufSize >= len(ciphertext) {\n\t\t\tallocatedBuf := pool.Get(bufSize)\n\t\t\tdec, err := p.crypto.Decrypt((*allocatedBuf)[:0], ciphertext)\n\t\t\tif err != nil {\n\t\t\t\tpool.Put(allocatedBuf)\n\t\t\t\treturn nil, 0, err\n\t\t\t}\n\t\t\tp.dropProtectedIfEmtpy()\n\t\t\treturn allocatedBuf, len(dec), nil\n\t\t}\n\t\t// Decrypt requires that if the dst and ciphertext alias, they\n\t\t// must alias exactly. Code here used to use msg[:0], but msg","sourceCodeStart":255,"sourceCodeEnd":291,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/alts/internal/conn/record.go#L255-L291","documentation":"Returned during ALTS record reading when the 4-byte little-endian message type field's lowest byte does not equal altsRecordMsgType (0x06). The ALTS record format mandates a message type whose low byte is 0x06; a mismatch means the data on the wire is not a valid ALTS record.","triggerScenarios":"A frame passes the length checks but its message-type byte differs from 0x06. Reached on every read of an ALTS connection after a complete frame is assembled.","commonSituations":"Non-ALTS data arriving on a connection that was supposed to be ALTS-secured (e.g. plaintext HTTP/2 or a different protocol); corruption of the message-type bytes; an interoperability mismatch with a peer using a different ALTS record format version.","solutions":["Confirm both endpoints are using ALTS transport credentials (not mixing ALTS with TLS or insecure).","Check for a proxy, sidecar, or load balancer that may be speaking a different protocol on the wire.","Capture a packet trace to confirm whether the bytes are valid ALTS records.","Close the connection; it cannot recover once framing is desynchronized."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Wrong message type => not ALTS data on this connection; treat as fatal.\nif err != nil && strings.Contains(err.Error(), \"incorrect message type\") {\n    log.Printf(\"non-ALTS data on ALTS connection: %v\", err)\n    return err // let gRPC reconnect or fail the RPC\n}","preventionTips":["Ensure both endpoints use alts.NewClientCreds/NewServerCreds — do not mix with TLS or insecure.","Check for proxies/sidecars that might inject non-ALTS bytes.","Monitor for this error as a sign of misconfigured or hostile traffic."],"tags":["grpc","alts","framing","corruption","protocol-mismatch"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}