{"record":{"id":"3f46f004e37fe999","repo":"grpc/grpc-go","slug":"unsupported-field-use-original-dst-is-present-an","errorCode":null,"errorMessage":"unsupported field 'use_original_dst' is present and set to true","messagePattern":"unsupported field 'use_original_dst' is present and set to true","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/xdsclient/xdsresource/unmarshal_lds.go","lineNumber":277,"sourceCode":"\t}\n\tvar i int\n\tfor ; i < len(ret)-1; i++ {\n\t\tif ret[i].Filter.IsTerminal() {\n\t\t\treturn nil, fmt.Errorf(\"http filter %q is a terminal filter but it is not last in the filter chain\", ret[i].Name)\n\t\t}\n\t}\n\tif !ret[i].Filter.IsTerminal() {\n\t\treturn nil, fmt.Errorf(\"http filter %q is not a terminal filter\", ret[len(ret)-1].Name)\n\t}\n\treturn ret, nil\n}\n\nfunc processServerSideListener(lis *v3listenerpb.Listener) (*ListenerUpdate, error) {\n\tif n := len(lis.ListenerFilters); n != 0 {\n\t\treturn nil, fmt.Errorf(\"unsupported field 'listener_filters' contains %d entries\", n)\n\t}\n\tif lis.GetUseOriginalDst().GetValue() {\n\t\treturn nil, errors.New(\"unsupported field 'use_original_dst' is present and set to true\")\n\t}\n\taddr := lis.GetAddress()\n\tif addr == nil {\n\t\treturn nil, fmt.Errorf(\"no address field in LDS response: %+v\", lis)\n\t}\n\tsockAddr := addr.GetSocketAddress()\n\tif sockAddr == nil {\n\t\treturn nil, fmt.Errorf(\"no socket_address field in LDS response: %+v\", lis)\n\t}\n\tlu := &ListenerUpdate{\n\t\tTCPListener: &InboundListenerConfig{\n\t\t\tAddress: sockAddr.GetAddress(),\n\t\t\tPort:    strconv.Itoa(int(sockAddr.GetPortValue())),\n\t\t},\n\t}\n\n\t// Populate the default filter chain.\n\tif dfc := lis.GetDefaultFilterChain(); dfc != nil {","sourceCodeStart":259,"sourceCodeEnd":295,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/xdsclient/xdsresource/unmarshal_lds.go#L259-L295","documentation":"Returned by processServerSideListener when the LDS Listener has use_original_dst set to true. grpc-go's inbound listener handling does not implement Envoy's original-destination-based filter chain selection, so this field being true is treated as an unsupported configuration and the resource is rejected (NACK).","triggerScenarios":"An LDS Listener destined for a gRPC server has use_original_dst=true. Typically comes from an Envoy-style config (e.g. transparent proxying / iptables redirect setups) being reused for a gRPC xDS server.","commonSituations":"Operator copied an Envoy Listener config (designed for transparent proxying with SO_ORIGINAL_DST) into a gRPC-managed LDS resource. Istio Pilot/ambient mesh emitted original-dst listener for a workload that grpc-go is consuming directly.","solutions":["Remove or set use_original_dst=false on the LDS Listener resource consumed by grpc-go.","If original-dst routing is genuinely required, terminate LDS with Envoy/proxy rather than the in-process grpc-go xDS server.","Filter the listener at the control plane so grpc-go only receives listeners without use_original_dst."],"exampleFix":"// before\n//   listener: { name: \"inbound\", use_original_dst: { value: true }, address: { ... } }\n// after\n//   listener: { name: \"inbound\", address: { ... } }","handlingStrategy":"validation","validationCode":"// Reject listeners with use_original_dst before publishing to grpc-go.\nfunc isGrpcCompatibleListener(lis *envoy_listener_pb.Listener) error {\n    if lis.GetUseOriginalDst().GetValue() {\n        return errors.New(\"use_original_dst unsupported by grpc-go xDS server; remove this field\")\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"Catch in the LDS watcher; log and alert. The fix is in the control plane (unset the field) or in deployment topology (use Envoy as the listener).","preventionTips":["Do not reuse Envoy transparent-proxy Listener configs for grpc-go xDS.","Maintain separate listener templates for gRPC vs Envoy server topologies.","Add a policy rule on the xDS server that strips/rejects use_original_dst for gRPC-targeted listeners."],"tags":["xds","lds","listener","unsupported-field","control-plane"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}