{"record":{"id":"8f3ea633cff22290","repo":"grpc/grpc-go","slug":"rbac-error-parsing-config-v-v","errorCode":null,"errorMessage":"rbac: error parsing config %v: %v","messagePattern":"rbac: error parsing config (.+?): (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/rbac/rbac.go","lineNumber":195,"sourceCode":"\t\treturn fmt.Errorf(\"rbac: header matcher for %q starts with %q\", name, \"grpc-\")\n\t}\n\tif name == \"host\" {\n\t\theader.Name = \":authority\"\n\t}\n\treturn nil\n}\n\nfunc (builder) ParseFilterConfig(cfg proto.Message) (httpfilter.FilterConfig, error) {\n\tif cfg == nil {\n\t\treturn nil, fmt.Errorf(\"rbac: nil configuration message provided\")\n\t}\n\tm, ok := cfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing config %v: unknown type %T\", cfg, cfg)\n\t}\n\tmsg := new(rpb.RBAC)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing config %v: %v\", cfg, err)\n\t}\n\treturn parseConfig(msg)\n}\n\nfunc (builder) ParseFilterConfigOverride(override proto.Message) (httpfilter.FilterConfig, error) {\n\tif override == nil {\n\t\treturn nil, fmt.Errorf(\"rbac: nil configuration message provided\")\n\t}\n\tm, ok := override.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing override config %v: unknown type %T\", override, override)\n\t}\n\tmsg := new(rpb.RBACPerRoute)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"rbac: error parsing override config %v: %v\", override, err)\n\t}\n\treturn parseConfig(msg.Rbac)\n}","sourceCodeStart":177,"sourceCodeEnd":213,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/rbac/rbac.go#L177-L213","documentation":"ParseFilterConfig (rbac.go:194) type-asserted *anypb.Any but UnmarshalTo into rpb.RBAC failed. The wrapped bytes are not a valid rpb.RBAC: wrong type URL, corrupt payload, or schema mismatch.","triggerScenarios":"anypb.Any with a mismatched type URL (e.g., the v2 URL or a different filter's URL), truncated/malformed bytes, or a go-control-plane version whose rpb.RBAC schema differs from the client's compiled proto.","commonSituations":"Version skew between control-plane and data-plane; corrupted config in transit; wrong filter config bound to the RBAC TypeURL.","solutions":["Ensure the anypb.Any type_url is type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC (or the RBACPerRoute URL for overrides).","Align go-control-plane versions between server and client.","Log the wrapped error to distinguish type-URL mismatch from wire-format decode errors."],"exampleFix":"// before\nanyCfg := &anypb.Any{TypeUrl: \"type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute\", Value: rawRbacBytes}\n\n// after\nanyCfg := &anypb.Any{TypeUrl: \"type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC\", Value: rawRbacBytes}","handlingStrategy":"validation","validationCode":"if m, ok := cfg.(*anypb.Any); ok {\n    want := \"type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBAC\"\n    if m.TypeUrl != want {\n        return nil, fmt.Errorf(\"rbac: type_url %q != %q\", m.TypeUrl, want)\n    }\n}","typeGuard":null,"tryCatchPattern":"if err != nil && strings.Contains(err.Error(), \"error parsing config\") {\n    // inspect the wrapped error to distinguish type-URL mismatch from wire corruption\n}","preventionTips":["Pin go-control-plane versions across server and client.","Validate the Any.TypeUrl against builder.TypeURLs() before unmarshalling.","Round-trip test rpb.RBAC through ParseFilterConfig."],"tags":["rbac","config","protobuf","xds","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}