{"record":{"id":"eec14aaff8ef0fe0","repo":"grpc/grpc-go","slug":"extauthz-failed-to-unmarshal-override-config-v","errorCode":null,"errorMessage":"extauthz: failed to unmarshal override config %v: %v","messagePattern":"extauthz: failed to unmarshal override config (.+?): (.+?)","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/xds/httpfilter/ext_authz/ext_authz.go","lineNumber":176,"sourceCode":"\t\tdecoderHeaderMutationRules: mutationRules,\n\t\tincludePeerCertificate:     msg.GetIncludePeerCertificate(),\n\t}, nil\n}\n\n// ParseFilterConfigOverride parses the provided override configuration.\n//\n// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS\n// resource validation, no filter configuration object is returned. Per-route\n// disabling is supported via the generic FilterConfig wrapper mechanism rather\n// than the ExtAuthzPerRoute.disabled field directly.\nfunc (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {\n\tm, ok := overrideCfg.(*anypb.Any)\n\tif !ok {\n\t\treturn nil, fmt.Errorf(\"extauthz: error parsing override config %v: unknown type %T, want *anypb.Any\", overrideCfg, overrideCfg)\n\t}\n\tmsg := new(v3extauthzpb.ExtAuthzPerRoute)\n\tif err := m.UnmarshalTo(msg); err != nil {\n\t\treturn nil, fmt.Errorf(\"extauthz: failed to unmarshal override config %v: %v\", overrideCfg, err)\n\t}\n\treturn nil, nil\n}\n\nfunc (builder) IsTerminal() bool {\n\treturn false\n}\n","sourceCodeStart":158,"sourceCodeEnd":184,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/xds/httpfilter/ext_authz/ext_authz.go#L158-L184","documentation":"The Any-wrapped override configuration could not be unmarshaled into an envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute proto (ext_authz.go:175-176). The serialized payload does not match the ExtAuthzPerRoute schema or the TypeURL is incorrect.","triggerScenarios":"anypb.Any.UnmarshalTo(msg) fails where msg is *v3extauthzpb.ExtAuthzPerRoute, because the Any payload is corrupted, truncated, or the TypeURL does not match 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'.","commonSituations":"xDS server proto version mismatch (different Envoy ext_authz per-route proto revision); wrong TypeURL in the Any; payload corruption; server sends a different override type under the ExtAuthzPerRoute URL.","solutions":["Verify the TypeURL matches 'type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute'","Ensure the xDS server and client use compatible go-control-plane / Envoy proto versions","Use xDS config dump to inspect the raw override payload for corruption","Check for go-control-plane version mismatches"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate the override TypeURL before unmarshaling.\nconst extAuthzPerRouteTypeURL = \"type.googleapis.com/envoy.extensions.filters.http.ext_authz.v3.ExtAuthzPerRoute\"\nif anyMsg.TypeUrl != extAuthzPerRouteTypeURL {\n    return fmt.Errorf(\"unexpected override TypeURL %q, want %q\", anyMsg.TypeUrl, extAuthzPerRouteTypeURL)\n}","typeGuard":null,"tryCatchPattern":"_, err := builder.ParseFilterConfigOverride(anyCfg)\nif err != nil && strings.Contains(err.Error(), \"failed to unmarshal override config\") {\n    log.Printf(\"ExtAuthzPerRoute override unmarshal failed: %v — check TypeURL and proto version\", err)\n}","preventionTips":["Keep go-control-plane versions aligned between xDS server and client","Validate override TypeURLs before dispatching to filter parsers","Use xDS config dump to inspect raw override payloads for corruption"],"tags":["ext-authz","xds","http-filter","protobuf","unmarshal","per-route"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}