{"record":{"id":"390a82d837647671","repo":"grpc/grpc-go","slug":"extauthz-failed-to-unmarshal-config-v","errorCode":null,"errorMessage":"extauthz: failed to unmarshal config: %v","messagePattern":"extauthz: failed to unmarshal config: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/ext_authz/ext_authz.go","lineNumber":99,"sourceCode":"\treturn fraction{numerator: num, denominator: den}, nil\n}\n\n// grpcStatusCode converts an HTTP status code to a gRPC status code.\nfunc grpcStatusCode(httpStatus int32) codes.Code {\n\tif code, ok := transport.HTTPStatusConvTab[int(httpStatus)]; ok {\n\t\treturn code\n\t}\n\treturn codes.Unknown\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"extauthz: error parsing config %v: unknown type %T, want *anypb.Any\", cfg, cfg)\n\t}\n\tmsg := new(v3extauthzpb.ExtAuthz)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to unmarshal config: %v\", err)\n\t}\n\n\tif msg.GetGrpcService() == nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: empty grpc_service provided in config %v\", cfg)\n\t}\n\tserver, err := parseGRPCServiceConfig(msg.GetGrpcService())\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to parse grpc_service: %v\", err)\n\t}\n\n\tfilterEnabled, err := parseFilterEnabled(msg.GetFilterEnabled())\n\tif err != nil {\n\t\treturn nil, err\n\t}\n\n\tvar denyAtDisable bool\n\tif denyAtDisableFlag := msg.GetDenyAtDisable(); denyAtDisableFlag != nil {\n\t\tif denyAtDisableFlag.GetDefaultValue() == nil {","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/ext_authz/ext_authz.go#L81-L117","documentation":"The Any-wrapped configuration could not be unmarshaled into an envoy.extensions.filters.http.ext_authz.v3.ExtAuthz proto (ext_authz.go:98-99). The serialized payload in the Any does not match the ExtAuthz schema or the TypeURL is incorrect.","triggerScenarios":"anypb.Any.UnmarshalTo(msg) fails because the Any payload is corrupted, truncated, or the TypeURL does not match 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz'.","commonSituations":"xDS server proto version mismatch (different Envoy ext_authz proto revision); TypeURL in the Any does not match the expected v3 ExtAuthz URL; payload corruption in transit; server sends a different filter type under the ext_authz type URL.","solutions":["Verify the TypeURL matches 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz'","Ensure the xDS server and client use compatible go-control-plane / Envoy proto versions","Use xDS config dump to inspect the raw Any payload for corruption","Check for go-control-plane version mismatches between server and client"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate the TypeURL before unmarshaling.\nconst extAuthzTypeURL = \"type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthz\"\nif anyMsg.TypeUrl != extAuthzTypeURL {\n    return fmt.Errorf(\"unexpected TypeURL %q, want %q\", anyMsg.TypeUrl, extAuthzTypeURL)\n}","typeGuard":null,"tryCatchPattern":"_, err := builder.ParseFilterConfig(anyCfg)\nif err != nil && strings.Contains(err.Error(), \"failed to unmarshal config\") {\n    log.Printf(\"ExtAuthz config unmarshal failed: %v — check TypeURL and proto version\", err)\n}","preventionTips":["Keep go-control-plane and gRPC proto versions aligned between xDS server and client","Validate TypeURLs before dispatching to filter parsers","Use xDS config dump to inspect raw payloads for corruption or version mismatches"],"tags":["ext-authz","xds","http-filter","protobuf","unmarshal"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}