{"record":{"id":"3b73fb72b6de1871","repo":"grpc/grpc-go","slug":"httpfilter-v","errorCode":null,"errorMessage":"httpfilter: %v","messagePattern":"httpfilter: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/extconfig.go","lineNumber":83,"sourceCode":"\t\tif err != nil {\n\t\t\treturn nil, err\n\t\t}\n\t\tmatchers = append(matchers, sm)\n\t}\n\treturn matchers, nil\n}\n\n// HeaderMutationRulesFromProto converts a protobuf HeaderMutationRules proto\n// message to a HeaderMutationRules struct.\nfunc HeaderMutationRulesFromProto(mr *v3mutationpb.HeaderMutationRules) (HeaderMutationRules, error) {\n\tvar rules HeaderMutationRules\n\tif mr == nil {\n\t\treturn rules, nil\n\t}\n\tif allowExpr := mr.GetAllowExpression(); allowExpr != nil {\n\t\tre, err := matcher.CompileSafeRegex(allowExpr.GetRegex())\n\t\tif err != nil {\n\t\t\treturn rules, fmt.Errorf(\"httpfilter: %v\", err)\n\t\t}\n\t\trules.AllowExpr = re\n\t}\n\tif disallowExpr := mr.GetDisallowExpression(); disallowExpr != nil {\n\t\tre, err := matcher.CompileSafeRegex(disallowExpr.GetRegex())\n\t\tif err != nil {\n\t\t\treturn rules, fmt.Errorf(\"httpfilter: %v\", err)\n\t\t}\n\t\trules.DisallowExpr = re\n\t}\n\trules.DisallowAll = mr.GetDisallowAll().GetValue()\n\trules.DisallowIsError = mr.GetDisallowIsError().GetValue()\n\treturn rules, nil\n}\n\n// ApplyAdditions takes a set of header mutations (for additions and\n// modifications) received from an external server and applies them to the\n// provided metadata, subject to the rules defined in hmr.","sourceCodeStart":65,"sourceCodeEnd":101,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/extconfig.go#L65-L101","documentation":"The allow_expression regex in the ExtAuthz header mutation rules could not be compiled (extconfig.go:81-83). CompileSafeRegex first tries regexp.Compile to catch syntax errors, and this failed, meaning the regex pattern contains invalid RE2 syntax.","triggerScenarios":"HeaderMutationRulesFromProto receives a non-nil allow_expression whose GetRegex() pattern fails regexp.Compile — e.g. unbalanced parentheses, invalid escape sequences, invalid character classes.","commonSituations":"xDS server sends an invalid allow_expression regex pattern; Envoy RE2 regex syntax incompatibility with Go's regexp engine; typo in the regex configuration on the server side.","solutions":["Test the allow_expression regex locally with Go's regexp.Compile before deploying to the xDS server","Verify the regex uses only RE2-compatible syntax (no backreferences, no lookahead/lookbehind)","Check for common syntax errors: unbalanced parentheses, invalid escape sequences, unterminated character classes","If the regex works in Envoy's C++ regex engine but not Go's RE2, rewrite it in RE2-compatible syntax"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Pre-validate the allow_expression regex before sending it via xDS.\nif allowExpr := rules.GetAllowExpression(); allowExpr != nil {\n    if _, err := regexp.Compile(allowExpr.GetRegex().GetRegex()); err != nil {\n        return fmt.Errorf(\"invalid allow_expression regex: %w\", err)\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Test all regex patterns with Go's regexp.Compile before deploying to the xDS server","Ensure regex patterns use only RE2-compatible syntax (no backreferences, no lookahead)","Add server-side config validation that rejects invalid regex patterns","Keep a registry of tested regex patterns for reuse"],"tags":["http-filter","regex","header-mutation","ext-authz","configuration"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}