{"record":{"id":"23fefd2d090672fa","repo":"grpc/grpc-go","slug":"extauthz-failed-to-parse-grpc-service-v","errorCode":null,"errorMessage":"extauthz: failed to parse grpc_service: %v","messagePattern":"extauthz: failed to parse grpc_service: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/ext_authz/ext_authz.go","lineNumber":107,"sourceCode":"\treturn codes.Unknown\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"extauthz: error parsing config %v: unknown type %T, want *anypb.Any\", cfg, cfg)\n\t}\n\tmsg := new(v3extauthzpb.ExtAuthz)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to unmarshal config: %v\", err)\n\t}\n\n\tif msg.GetGrpcService() == nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: empty grpc_service provided in config %v\", cfg)\n\t}\n\tserver, err := parseGRPCServiceConfig(msg.GetGrpcService())\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to parse grpc_service: %v\", err)\n\t}\n\n\tfilterEnabled, err := parseFilterEnabled(msg.GetFilterEnabled())\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\tvar denyAtDisable bool\n\tif denyAtDisableFlag := msg.GetDenyAtDisable(); denyAtDisableFlag != nil {\n\t\tif denyAtDisableFlag.GetDefaultValue() == nil {\n\t\t\treturn nil, fmt.Errorf(\"extauthz: missing default_value in deny_at_disable\")\n\t\t}\n\t\tdenyAtDisable = denyAtDisableFlag.GetDefaultValue().GetValue()\n\t}\n\n\thttpStatus := int32(http.StatusForbidden)\n\tif st := msg.GetStatusOnError().GetCode(); st != 0 {\n\t\thttpStatus = int32(st)","sourceCodeStart":89,"sourceCodeEnd":125,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/ext_authz/ext_authz.go#L89-L125","documentation":"The grpc_service field in the ExtAuthz config could not be parsed into a GRPCServiceConfig (ext_authz.go:105-107). Critically, in the current codebase the parseGRPCServiceConfig function is a placeholder that always returns 'parseGRPCServiceConfig not implemented' (ext_authz.go:48-50) — this means gRFC A102 support for client-side ext_authz is incomplete, and any non-empty grpc_service will trigger this error.","triggerScenarios":"parseGRPCServiceConfig(msg.GetGrpcService()) is called with a non-nil grpc_service. Since the current implementation always returns an error ('parseGRPCServiceConfig not implemented'), this error fires for every valid ExtAuthz config that includes a grpc_service.","commonSituations":"Using the experimental client-side ext_authz filter (GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT=true) with an xDS server that sends an ExtAuthz config containing grpc_service — the feature is not yet fully implemented (gRFC A102 pending).","solutions":["Do not enable GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT until gRFC A102 is fully implemented and parseGRPCServiceConfig is replaced with a real implementation","Upgrade to a gRPC version where ext_authz grpc_service parsing is fully supported","If you must test, override the parseGRPCServiceConfig variable (internal/test only) with a real parser","Track the gRFC A102 implementation status in the grpc-go repository"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Check implementation status before enabling the feature.\n// parseGRPCServiceConfig is currently a stub that always returns 'not implemented'.\nif envconfig.XDSClientExtAuthzEnabled {\n    log.Println(\"WARNING: client-side ext_authz grpc_service parsing is not fully implemented (gRFC A102 pending)\")\n}","typeGuard":null,"tryCatchPattern":"_, err := builder.ParseFilterConfig(anyCfg)\nif err != nil && strings.Contains(err.Error(), \"parseGRPCServiceConfig not implemented\") {\n    log.Printf(\"ext_authz grpc_service parsing not yet supported in this gRPC version: %v\", err)\n}","preventionTips":["Do not enable GRPC_EXPERIMENTAL_XDS_EXT_AUTHZ_ON_CLIENT until gRFC A102 is fully implemented","Track gRFC A102 implementation status before relying on client-side ext_authz","Upgrade gRPC versions regularly to pick up ext_authz implementation progress","Test the feature in a staging environment before production"],"tags":["ext-authz","xds","http-filter","grpc-service","not-implemented","experimental"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}