{"record":{"id":"8b02a2de149f4444","repo":"grpc/grpc-go","slug":"allow-rules-v","errorCode":null,"errorMessage":"\"allow_rules\" %v","messagePattern":"\"allow_rules\" (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"authz/rbac_translator.go","lineNumber":394,"sourceCode":"\tif err != nil {\n\t\treturn nil, \"\", err\n\t}\n\trbacs := make([]*v3rbacpb.RBAC, 0, 2)\n\tif len(policy.DenyRules) > 0 {\n\t\tdenyPolicies, err := parseRules(policy.DenyRules, policy.Name)\n\t\tif err != nil {\n\t\t\treturn nil, \"\", fmt.Errorf(`\"deny_rules\" %v`, err)\n\t\t}\n\t\tdenyRBAC := &v3rbacpb.RBAC{\n\t\t\tAction:              v3rbacpb.RBAC_DENY,\n\t\t\tPolicies:            denyPolicies,\n\t\t\tAuditLoggingOptions: denyLogger,\n\t\t}\n\t\trbacs = append(rbacs, denyRBAC)\n\t}\n\tallowPolicies, err := parseRules(policy.AllowRules, policy.Name)\n\tif err != nil {\n\t\treturn nil, \"\", fmt.Errorf(`\"allow_rules\" %v`, err)\n\t}\n\tallowRBAC := &v3rbacpb.RBAC{Action: v3rbacpb.RBAC_ALLOW, Policies: allowPolicies, AuditLoggingOptions: allowLogger}\n\treturn append(rbacs, allowRBAC), policy.Name, nil\n}\n","sourceCodeStart":376,"sourceCodeEnd":399,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/authz/rbac_translator.go#L376-L399","documentation":"Returned by translatePolicy (rbac_translator.go:394) wrapping a failure from parseRules(policy.AllowRules, policy.Name). Since allow_rules is mandatory and already non-empty (checked at line 372), this error indicates one of the allow rule entries is itself invalid (missing name or malformed request). The %v carries the index and the specific sub-error.","triggerScenarios":"An allow_rules[] entry that lacks \"name\" or whose request.headers/paths are malformed, even though the allow_rules array itself is non-empty.","commonSituations":"Authoring allow rules and omitting a required sub-field on one of them; templating that produced a partial rule.","solutions":["Read the wrapped %v to locate the offending allow rule (index + sub-cause) and fix it.","Lint each allow rule for: non-empty unique name, valid headers (key + non-empty values + allowed header names), valid paths.","Reload via the file watcher so the prior good policy remains active during the fix."],"exampleFix":"// before\n\"allow_rules\": [ { \"request\": { \"paths\": [\"/\"] } } ]\n// error: \"allow_rules\" 0: \"name\" is not present\n\n// after\n\"allow_rules\": [ { \"name\": \"allow_all\", \"request\": { \"paths\": [\"/\"] } } ]","handlingStrategy":"validation","validationCode":"for i, r := range allowRules {\n    if r.Name == \"\" || !validRequest(r.Request) {\n        return fmt.Errorf(\"allow_rules[%d]: invalid\", i)\n    }\n}","typeGuard":null,"tryCatchPattern":"interceptor, err := authz.NewStatic(policyJSON)\nif err != nil {\n    if strings.Contains(err.Error(), `\"allow_rules\"`) {\n        // wrapped %v names the allow-rule index + cause; fix and reload\n    }\n}","preventionTips":["Validate every allow rule's name and request block before deploy.","Parse the composite error: index is the rule, remainder is the field cause.","Use file-watcher reload to keep serving the previous good policy."],"tags":["grpc","authz","rbac","policy","config","go"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}