{"record":{"id":"d735803f50196e5b","repo":"grpc/grpc-go","slug":"external-processor-sent-an-immediate-response-but","errorCode":null,"errorMessage":"external processor sent an immediate response but immediate responses are disabled in configuration","messagePattern":"external processor sent an immediate response but immediate responses are disabled in configuration","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/extproc/ext_proc.go","lineNumber":1743,"sourceCode":"\t// external processor.\n\toutgoingMD, _ := metadata.FromOutgoingContext(ctx)\n\tif outgoingMD == nil {\n\t\toutgoingMD = metadata.MD{}\n\t}\n\tif err = cs.applyMutations(header.GetResponse().GetHeaderMutation(), outgoingMD); err != nil {\n\t\tcs.handleHeaderError(err, newStream, opts)\n\t\treturn false\n\t}\n\tdataplaneCtx := metadata.NewOutgoingContext(ctx, outgoingMD)\n\tif err = cs.createDataplaneStream(dataplaneCtx, newStream, opts); err != nil {\n\t\treturn false\n\t}\n\treturn true\n}\n\nfunc (cs *clientStream) handleImmediateResponse(imm *v3procservicepb.ImmediateResponse, newStream func(context.Context, ...grpc.CallOption) (grpc.ClientStream, error), opts []grpc.CallOption) {\n\tif cs.config.disableImmediateResponse {\n\t\terr := fmt.Errorf(\"external processor sent an immediate response but immediate responses are disabled in configuration\")\n\t\tif cs.dataplaneStream == nil {\n\t\t\tcs.handleHeaderError(err, newStream, opts)\n\t\t} else {\n\t\t\tcs.failProcStream(err)\n\t\t}\n\t\treturn\n\t}\n\n\tstatusCode := codes.Internal\n\tif imm.GetGrpcStatus() != nil {\n\t\tstatusCode = codes.Code(imm.GetGrpcStatus().GetStatus())\n\t\tif statusCode > codes.Code(16) {\n\t\t\tstatusCode = codes.Unknown\n\t\t}\n\t}\n\terr := status.Error(statusCode, imm.GetDetails())\n\n\tif cs.trailerSent.Load() {","sourceCodeStart":1725,"sourceCodeEnd":1761,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/extproc/ext_proc.go#L1725-L1761","documentation":"handleImmediateResponse (ext_proc.go:1742) fires when the external processor sends an immediate_response while config.disableImmediateResponse is true. The filter is configured to forbid immediate responses, so it fails the stream (or bypasses it per failureModeAllow) instead of honoring the abort.","triggerScenarios":"Client filter config sets disableImmediateResponse=true and the external processor returns a ProcessingResponse with the immediate_response variant set.","commonSituations":"Operator disabled immediate responses for safety/latency reasons, but the external processor still emits them (e.g., for auth rejection). Mismatch between control-plane filter config and server behavior.","solutions":["If immediate responses are intended, remove disableImmediateResponse from the extproc filter config in the xDS Listener/Route.","If immediate responses must stay disabled, fix the external processor to never send them (use header mutation + CONTINUE instead).","Reconcile the control-plane config and server contract before redeploying."],"exampleFix":"// before (xDS filter config)\ndisable_immediate_response: true\n\n// after\n// (field removed or set false) disable_immediate_response: false","handlingStrategy":"validation","validationCode":"// Before deploying, reconcile filter config and server contract\nif filterConfig.DisableImmediateResponse && serverSendsImmediateResponses {\n    return errors.New(\"extproc: immediate responses disabled in config but server emits them\")\n}","typeGuard":null,"tryCatchPattern":"// Client-side: surfaces as codes.Internal.\nif st, ok := status.FromError(err); ok && strings.Contains(st.Message(), \"immediate responses are disabled\") {\n    // remove disableImmediateResponse from config or stop sending immediate responses\n}","preventionTips":["Document the disableImmediateResponse flag at the control-plane and server teams.","If the server needs to reject requests, agree on whether to use immediate_response or header mutation + CONTINUE."],"tags":["extproc","grpc","config","xds","external-processor"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}