{"record":{"id":"90adede8847b0a77","repo":"sidorares/node-mysql2","slug":"unexpected-data-in-authmoredata-packet-received-by","errorCode":null,"errorMessage":"Unexpected data in AuthMoreData packet received by ${PLUGIN_NAME} plugin in STATE_FINAL state.","messagePattern":"Unexpected data in AuthMoreData packet received by (.+?) plugin in STATE_FINAL state\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"lib/auth_plugins/caching_sha2_password.js","lineNumber":100,"sourceCode":"\n            // if client provides key we can save one extra roundrip on first connection\n            if (pluginOptions.serverPublicKey) {\n              return authWithKey(pluginOptions.serverPublicKey);\n            }\n\n            state = STATE_WAIT_SERVER_KEY;\n            return REQUEST_SERVER_KEY_PACKET;\n          }\n          throw new Error(\n            `Invalid AuthMoreData packet received by ${PLUGIN_NAME} plugin in STATE_TOKEN_SENT state.`\n          );\n        case STATE_WAIT_SERVER_KEY:\n          if (pluginOptions.onServerPublicKey) {\n            pluginOptions.onServerPublicKey(data);\n          }\n          return authWithKey(data);\n        case STATE_FINAL:\n          throw new Error(\n            `Unexpected data in AuthMoreData packet received by ${PLUGIN_NAME} plugin in STATE_FINAL state.`\n          );\n      }\n\n      throw new Error(\n        `Unexpected data in AuthMoreData packet received by ${PLUGIN_NAME} plugin in state ${state}`\n      );\n    };\n  };\n\n// Export the plugin factory as default\nmodule.exports = pluginFactory;\n\n// Export calculateToken for reuse in initial handshake optimization\nmodule.exports.calculateToken = calculateToken;\n","sourceCodeStart":82,"sourceCodeEnd":116,"githubUrl":"https://github.com/sidorares/node-mysql2/blob/8b1f829d3706404ab372cf97bd77ebcf86578d97/lib/auth_plugins/caching_sha2_password.js#L82-L116","documentation":"Thrown by caching_sha2_password when the plugin has already reached STATE_FINAL (-1) — meaning authentication is logically complete — yet the server sends another AuthMoreData packet (lib/auth_plugins/caching_sha2_password.js:99-102). In a well-formed exchange no further packets should arrive after STATE_FINAL, so this signals a protocol desync or an out-of-band packet arriving on a dead connection.","triggerScenarios":"The server sends an extra trailing byte after the fast-auth-success path (line 68-70 set STATE_FINAL and returned null, but a subsequent AuthMoreData packet still arrives); reuse of a pooled connection whose previous auth state was not fully reset; a server-side protocol extension emitting an unsolicited AuthMoreData that mysql2 does not yet understand.","commonSituations":"Connection pool reusing a socket whose prior session ended abnormally; a MySQL/MariaDB fork that adds extra auth-roundtrip bytes; version skew between an older mysql2 client and a newer server that appends a metadata packet post-auth.","solutions":["Reproduce against a direct, non-pooled connection to rule out socket reuse.","Upgrade mysql2 to the current release to pick up state-machine fixes for newer server versions.","If pooling, ensure connections are fully closed on error rather than returned to the pool (set the pool error handlers to destroy).","Capture the wire exchange with a packet trace to identify the unexpected trailing packet and report it upstream."],"exampleFix":"// before: errored connection silently returned to pool\npool.on('connection', (c) => c.on('error', () => {}));\n\n// after: destroy errored connections so auth state resets\npool.on('connection', (c) => c.on('error', () => { c.destroy(); }));","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await conn.connect();\n} catch (e) {\n  if (/STATE_FINAL/.test(e.message)) { conn.destroy(); throw new Error('auth desync, retry on fresh socket'); }\n  throw e;\n}","preventionTips":["Destroy (not return) pooled connections that error during auth.","Avoid sharing a socket across concurrent handshakes.","Upgrade mysql2 and the server together."],"tags":["authentication","caching-sha2-password","connection-pool","protocol"],"backgroundTag":null,"analyzedSha":"8b1f829d3706404ab372cf97bd77ebcf86578d97","analyzedAt":"2026-08-11T02:54:28.964Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}