{"record":{"id":"28e786929c5bd07d","repo":"grpc/grpc-go","slug":"error-parsing-custom-audit-logger-config-v","errorCode":null,"errorMessage":"error parsing custom audit logger config: %v","messagePattern":"error parsing custom audit logger config: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":318,"sourceCode":"\t\t}\n\t\tallow.AuditCondition = v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition)\n\t\tdeny.AuditCondition = toDenyCondition(v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition(rbacCondition))\n\t}\n\n\tfor i, config := range options.AuditLoggers {\n\t\tif config.Name == \"\" {\n\t\t\treturn nil, nil, fmt.Errorf(\"missing required field: name in audit_logging_options.audit_loggers[%v]\", i)\n\t\t}\n\t\tif config.Config == nil {\n\t\t\tconfig.Config = &structpb.Struct{}\n\t\t}\n\t\ttypedStruct := &v1xdsudpatypepb.TypedStruct{\n\t\t\tTypeUrl: typeURLPrefix + config.Name,\n\t\t\tValue:   config.Config,\n\t\t}\n\t\tcustomConfig, err := anypb.New(typedStruct)\n\t\tif err != nil {\n\t\t\treturn nil, nil, fmt.Errorf(\"error parsing custom audit logger config: %v\", err)\n\t\t}\n\n\t\tlogger := &v3corepb.TypedExtensionConfig{Name: config.Name, TypedConfig: customConfig}\n\t\trbacConfig := v3rbacpb.RBAC_AuditLoggingOptions_AuditLoggerConfig{\n\t\t\tIsOptional:  config.IsOptional,\n\t\t\tAuditLogger: logger,\n\t\t}\n\t\tallow.LoggerConfigs = append(allow.LoggerConfigs, &rbacConfig)\n\t\tdeny.LoggerConfigs = append(deny.LoggerConfigs, &rbacConfig)\n\t}\n\n\treturn allow, deny, nil\n}\n\n// Maps the AuditCondition coming from AuditLoggingOptions to the proper\n// condition for the deny policy RBAC proto\nfunc toDenyCondition(condition v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition) v3rbacpb.RBAC_AuditLoggingOptions_AuditCondition {\n\t// Mapping the overall policy AuditCondition to what it must be for the Deny and Allow RBAC","sourceCodeStart":300,"sourceCodeEnd":336,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L300-L336","documentation":"Returned by auditLoggingOptions.toProtos (rbac_translator.go:318) when anypb.New(typedStruct) fails while packing the custom audit logger config into a protobuf Any. The TypedStruct wraps the logger's structpb.Struct config with a typeURL of 'grpc.authz.audit_logging/<name>'. anypb.New fails only when the message cannot be serialized (e.g. contains invalid UTF-8 strings in the Struct, or an internal proto error).","triggerScenarios":"An audit logger config Struct whose string values contain invalid UTF-8 bytes, or otherwise cannot be marshaled by proto; extremely rare in normal operation.","commonSituations":"Binary/non-UTF-8 data placed into a Struct string field; corrupt Struct construction; protobuf version mismatch producing a marshal error.","solutions":["Ensure all string values in the audit logger config object are valid UTF-8.","Simplify the config to isolate which field causes the marshal failure, then correct the offending value.","If using a programmatically built structpb.Struct, validate strings before insertion."],"exampleFix":"// before\n\"config\": { \"topic\": \"<invalid utf-8 bytes>\" }\n\n// after\n\"config\": { \"topic\": \"audit-events\" }","handlingStrategy":"validation","validationCode":"import \"unicode/utf8\"\nfunc validStructStrings(s *structpb.Struct) error {\n    if s == nil { return nil }\n    for k, v := range s.Fields {\n        if !utf8.ValidString(k) { return fmt.Errorf(\"invalid utf-8 key: %q\", k) }\n        if v.GetStringValue() != \"\" && !utf8.ValidString(v.GetStringValue()) {\n            return fmt.Errorf(\"invalid utf-8 value for key %q\", k)\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if strings.Contains(err.Error(), \"error parsing custom audit logger config\") {\n        // sanitize the audit logger config struct (valid UTF-8) and reload\n    }\n}","preventionTips":["Keep audit logger config values as valid UTF-8 strings.","Avoid placing binary/base64 blobs into Struct string fields."],"tags":["grpc","authz","rbac","audit","protobuf","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}