{"record":{"id":"3cd421993a0c55fc","repo":"grpc/grpc-go","slug":"rbac-nil-configuration-message-provided","errorCode":null,"errorMessage":"rbac: nil configuration message provided","messagePattern":"rbac: nil configuration message provided","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/rbac/rbac.go","lineNumber":187,"sourceCode":"// normalizeHeaderMatcher rejects header matchers that A41 forbids (:scheme or a\n// grpc- prefixed name) and rewrites a \"host\" matcher to \":authority\".\nfunc normalizeHeaderMatcher(header *v3routepb.HeaderMatcher) error {\n\tname := header.GetName()\n\tif name == \":scheme\" {\n\t\treturn fmt.Errorf(\"rbac: header matcher for %q is %q\", name, \":scheme\")\n\t}\n\tif strings.HasPrefix(name, \"grpc-\") {\n\t\treturn fmt.Errorf(\"rbac: header matcher for %q starts with %q\", name, \"grpc-\")\n\t}\n\tif name == \"host\" {\n\t\theader.Name = \":authority\"\n\t}\n\treturn nil\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tif cfg == nil {\n\t\treturn nil, fmt.Errorf(\"rbac: nil configuration message provided\")\n\t}\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing config %v: unknown type %T\", cfg, cfg)\n\t}\n\tmsg := new(rpb.RBAC)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing config %v: %v\", cfg, err)\n\t}\n\treturn parseConfig(msg)\n}\n\nfunc (builder) ParseFilterConfigOverride(override proto.Message) (httpfilter.FilterConfig, error) {\n\tif override == nil {\n\t\treturn nil, fmt.Errorf(\"rbac: nil configuration message provided\")\n\t}\n\tm, ok := override.(*anypb.Any)\n\tif !ok {","sourceCodeStart":169,"sourceCodeEnd":205,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/rbac/rbac.go#L169-L205","documentation":"ParseFilterConfig (rbac.go:186) rejects a nil proto.Message up front. The RBAC filter requires a non-nil *anypb.Any wrapping an rpb.RBAC proto; nil indicates a programming or control-plane error. (Note: ParseFilterConfigOverride also returns this same message for a nil override.)","triggerScenarios":"ParseFilterConfig(nil) or ParseFilterConfigOverride(nil) is invoked, either directly or because the xDS resource contained a nil-typed config for the RBAC filter.","commonSituations":"xDS server emits an RBAC filter entry with an empty typed_config; programmatic registration with nil; test code that forgot to populate the config.","solutions":["Provide a non-nil *anypb.Any wrapping an rpb.RBAC proto to ParseFilterConfig.","Confirm the xDS Listener/Route contains the RBAC filter's typed_config with the correct type URL.","If RBAC is not desired, remove the filter from the resource rather than sending nil."],"exampleFix":"// before\ncfg, err := rbacBuilder.ParseFilterConfig(nil)\n\n// after\nanyCfg, _ := anypb.New(&rpb.RBAC{Rules: &v3rbacpb.RBAC{Action: v3rbacpb.RBAC_ALLOW}})\ncfg, err := rbacBuilder.ParseFilterConfig(anyCfg)","handlingStrategy":"validation","validationCode":"if cfg == nil {\n    return nil, errors.New(\"rbac: refusing to parse nil config\")\n}","typeGuard":null,"tryCatchPattern":"fc, err := rbacBuilder.ParseFilterConfig(anyCfg)\nif err != nil {\n    if strings.Contains(err.Error(), \"nil configuration message\") {\n        // populate typed_config in the xDS resource\n    }\n    return err\n}","preventionTips":["Populate the RBAC filter's typed_config in xDS.","Reject nil configs at the control-plane.","Unit-test registration paths with non-nil inputs."],"tags":["rbac","config","xds","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}