{"record":{"id":"e05e48a7ef5d4fee","repo":"grpc/grpc-go","slug":"failed-to-receive-alts-handshaker-response-w","errorCode":null,"errorMessage":"failed to receive ALTS handshaker response: %w","messagePattern":"failed to receive ALTS handshaker response: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/alts/internal/handshaker/handshaker.go","lineNumber":309,"sourceCode":"\t}\n\tmaxFrameSize := int(envconfig.ALTSMaxFrameSize)\n\tif peerMax := int(result.GetMaxFrameSize()); peerMax > 0 {\n\t\tmaxFrameSize = min(peerMax, maxFrameSize)\n\t}\n\tsc, err := conn.NewConnWithMaxFrameSize(h.conn, h.side, result.GetRecordProtocol(), result.KeyData[:keyLen], extra, maxFrameSize)\n\tif err != nil {\n\t\treturn nil, nil, err\n\t}\n\treturn sc, result, nil\n}\n\nfunc (h *altsHandshaker) accessHandshakerService(req *altspb.HandshakerReq) (*altspb.HandshakerResp, error) {\n\tif err := h.stream.Send(req); err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to send ALTS handshaker request: %w\", err)\n\t}\n\tresp, err := h.stream.Recv()\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"failed to receive ALTS handshaker response: %w\", err)\n\t}\n\treturn resp, nil\n}\n\n// processUntilDone processes the handshake until the handshaker service returns\n// the results. Handshaker service takes care of frame parsing, so we read\n// whatever received from the network and send it to the handshaker service.\nfunc (h *altsHandshaker) processUntilDone(resp *altspb.HandshakerResp, extra []byte) (*altspb.HandshakerResult, []byte, error) {\n\tvar lastWriteTime time.Time\n\tbuf := make([]byte, frameLimit)\n\tfor {\n\t\tif len(resp.OutFrames) > 0 {\n\t\t\tlastWriteTime = time.Now()\n\t\t\tif _, err := h.conn.Write(resp.OutFrames); err != nil {\n\t\t\t\treturn nil, nil, err\n\t\t\t}\n\t\t}\n\t\tif resp.Result != nil {","sourceCodeStart":291,"sourceCodeEnd":327,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/alts/internal/handshaker/handshaker.go#L291-L327","documentation":"Returned by accessHandshakerService when receiving a HandshakerResp on the open DoHandshake stream fails (h.stream.Recv returns an error). The underlying error is wrapped with %w. This indicates the control stream to the GCP handshaker service broke after a request was sent.","triggerScenarios":"After successfully Sending a HandshakerReq, Recv() on the same stream returns an error (EOF, transport error, RST_STREAM). Reached during every doHandshake iteration and the processUntilDone loop.","commonSituations":"Handshaker service crashed/restarted mid-handshake; network drop to the metadata server; the stream was cancelled by context timeout; the peer sent no more frames causing processUntilDone to loop and eventually fail Recv; RPC-level error from the handshaker service causing the stream to terminate.","solutions":["Retry the ALTS handshake/connection — transient.","Inspect the wrapped error: io.EOF often means the handshaker service closed the stream; context.Canceled/DeadlineExceeded means the caller's deadline was too short.","Verify metadata-server reachability and health; check GCP status.","Increase handshake deadlines if large handshakes are timing out."],"exampleFix":null,"handlingStrategy":"retry","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Stream Recv failures during handshake are typically transient; retry.\nif err != nil {\n    if errors.Is(err, io.EOF) {\n        // handshaker service closed the stream; retry the handshake\n    }\n    if errors.Is(err, context.DeadlineExceeded) {\n        // increase handshake deadline\n    }\n}","preventionTips":["Provide an adequately long context deadline for ALTS handshakes.","Distinguish io.EOF (service closed) from context cancellation when triaging.","Alert on sustained Recv failures against the metadata server."],"tags":["grpc","alts","gcp","handshaker-service","network","transient","stream"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}