{"record":{"id":"bbcf7179fe45c777","repo":"grpc/grpc-go","slug":"unsupported-mode-v","errorCode":null,"errorMessage":"unsupported mode: %v","messagePattern":"unsupported mode: (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/google/google.go","lineNumber":146,"sourceCode":"\n// NewWithMode should make a copy of Bundle, and switch mode. Modifying the\n// existing Bundle may cause races.\nfunc (c *creds) NewWithMode(mode string) (credentials.Bundle, error) {\n\tnewCreds := &creds{\n\t\topts: c.opts,\n\t\tmode: mode,\n\t}\n\n\t// Create transport credentials.\n\tswitch mode {\n\tcase internal.CredsBundleModeFallback:\n\t\tnewCreds.transportCreds = newClusterTransportCreds(newTLS(), newALTS())\n\tcase internal.CredsBundleModeBackendFromBalancer, internal.CredsBundleModeBalancer:\n\t\t// Only the clients can use google default credentials, so we only need\n\t\t// to create new ALTS client creds here.\n\t\tnewCreds.transportCreds = newALTS()\n\tdefault:\n\t\treturn nil, fmt.Errorf(\"unsupported mode: %v\", mode)\n\t}\n\n\tif mode == internal.CredsBundleModeFallback || mode == internal.CredsBundleModeBackendFromBalancer {\n\t\tnewCreds.perRPCCreds = newCreds.opts.PerRPCCreds\n\t}\n\n\treturn newCreds, nil\n}\n\n// dualPerRPCCreds implements credentials.PerRPCCredentials by embedding the\n// fallback PerRPCCredentials and the ALTS one. It pickes one of them based on\n// the channel type.\ntype dualPerRPCCreds struct {\n\tperRPCCreds     credentials.PerRPCCredentials\n\taltsPerRPCCreds credentials.PerRPCCredentials\n}\n\nfunc (d *dualPerRPCCreds) GetRequestMetadata(ctx context.Context, uri ...string) (map[string]string, error) {","sourceCodeStart":128,"sourceCodeEnd":164,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/google/google.go#L128-L164","documentation":"Returned by (*creds).NewWithMode when the requested mode string is not one of the three internal constants (CredsBundleModeFallback, CredsBundleModeBackendFromBalancer, CredsBundleModeBalancer). This is an internal gRPC API: external callers should not pass arbitrary mode strings. The %v echoes the offending mode.","triggerScenarios":"Calling the Bundle.NewWithMode method on a google credentials bundle with a custom or empty mode string; a version mismatch where internal mode constant values changed but a caller hardcodes a literal.","commonSituations":"Custom resolvers or balancer plugins that invoke NewWithMode with a mode not defined in internal/internal.go; copy-pasted code from an older gRPC version using now-renamed constants; testing harnesses that fuzz the mode parameter.","solutions":["Stop calling NewWithMode with custom strings; use only the public constructors (NewDefaultCredentials, NewComputeEngineCredentials).","If you must call NewWithMode, import the mode constants from google.golang.org/grpc/internal (or prefer the public bundle API) and never pass literals.","Align gRPC versions across modules so the internal constant values are consistent."],"exampleFix":"// before\nbundle, err := c.NewWithMode(\"custom-mode\")\n// after\nbundle, err := c.NewWithMode(internal.CredsBundleModeFallback)","handlingStrategy":"validation","validationCode":"// Do not construct custom mode strings; use only the public bundle constructors.\n// If you must call NewWithMode, validate against the known set:\nfunc isValidMode(m string) bool {\n    return m == internal.CredsBundleModeFallback ||\n        m == internal.CredsBundleModeBackendFromBalancer ||\n        m == internal.CredsBundleModeBalancer\n}\nif !isValidMode(mode) {\n    return fmt.Errorf(\"unsupported mode %q; use a public credentials constructor\", mode)\n}","typeGuard":null,"tryCatchPattern":"bundle, err := c.NewWithMode(mode)\nif err != nil && strings.HasPrefix(err.Error(), \"unsupported mode\") {\n    log.Fatalf(\"internal API misuse: %v\", err)\n}","preventionTips":["Prefer NewDefaultCredentials / NewComputeEngineCredentials over manual NewWithMode calls.","Treat NewWithMode as internal; never fuzz or expose its mode parameter.","Keep all grpc modules at the same version so internal constants agree."],"tags":["grpc","internal","credentials","configuration"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}