{"record":{"id":"ef1772e20a9c89b1","repo":"grpc/grpc-go","slug":"bad-resolver-state","errorCode":null,"errorMessage":"bad resolver state","messagePattern":"bad resolver state","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"balancer/balancer.go","lineNumber":394,"sourceCode":"type ExitIdler interface {\n\t// ExitIdle instructs the LB policy to reconnect to backends / exit the\n\t// IDLE state, if appropriate and possible.  Note that SubConns that enter\n\t// the IDLE state will not reconnect until SubConn.Connect is called.\n\tExitIdle()\n}\n\n// ClientConnState describes the state of a ClientConn relevant to the\n// balancer.\ntype ClientConnState struct {\n\tResolverState resolver.State\n\t// The parsed load balancing configuration returned by the builder's\n\t// ParseConfig method, if implemented.\n\tBalancerConfig serviceconfig.LoadBalancingConfig\n}\n\n// ErrBadResolverState may be returned by UpdateClientConnState to indicate a\n// problem with the provided name resolver data.\nvar ErrBadResolverState = errors.New(\"bad resolver state\")\n","sourceCodeStart":376,"sourceCodeEnd":395,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/balancer/balancer.go#L376-L395","documentation":"Thrown when the *anypb.Any override payload fails to unmarshal into *rpb.RBACPerRoute via UnmarshalTo. This means the type_url and/or the serialized bytes inside the Any do not correspond to a valid RBACPerRoute proto message — the wire payload is corrupt, truncated, or contains a different message type than advertised.","triggerScenarios":"The Any's type_url is set to RBACPerRoute but the bytes were serialized from a different proto (e.g., an RBAC message instead of RBACPerRoute). A truncated or corrupted protobuf payload reaching the filter after a buggy control-plane serialization. A schema version mismatch where the control plane serializes a newer RBACPerRoute field layout that the client's go-control-plane version cannot decode.","commonSituations":"Upgrading Envoy/go-control-plane on the control plane to a version that added new required fields to RBACPerRoute without upgrading grpc-go on the data plane. A network-level or serialization-level corruption of the LDS/RDS DiscoveryResponse. A control plane that mistakenly puts an RBAC (not RBACPerRoute) message inside the per-route override Any.","solutions":["Verify the Any's type_url is exactly type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute and the payload bytes are a serialized RBACPerRoute (which wraps an RBAC message in its 'rbac' field), not a bare RBAC.","Align the go-control-plane version used by the control plane with the one linked into grpc-go on the client so the proto schemas match.","Capture the full DiscoveryResponse from the control plane (e.g., via GRPC_XDS_DEBUG_V3=log) and validate the bytes deserialize standalone with protoc --decode_raw."],"exampleFix":"// before: control plane puts a bare RBAC into the per-route override\noverride_any, _ := anypb.New(&v3rbacpb.RBAC{Rules: rules})\n\n// after: wrap it in RBACPerRoute as the schema requires\noverride_any, _ := anypb.New(&rpb.RBACPerRoute{Rbac: &v3rbacpb.RBAC{Rules: rules}})","handlingStrategy":"validation","validationCode":"// Validate the Any can unmarshal into RBACPerRoute before calling ParseFilterConfigOverride:\nfunc validateRBACOverride(any *anypb.Any) error {\n    expectedURL := \"type.googleapis.com/envoy.extensions.filters.http.rbac.v3.RBACPerRoute\"\n    if any.TypeUrl != expectedURL {\n        return fmt.Errorf(\"type_url mismatch: want %s, got %s\", expectedURL, any.TypeUrl)\n    }\n    msg := new(rpb.RBACPerRoute)\n    if err := any.UnmarshalTo(msg); err != nil {\n        return fmt.Errorf(\"payload does not unmarshal to RBACPerRoute: %w\", err)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"// When constructing the chain engine from xDS, catch unmarshal failures and NACK:\ncfg, err := b.ParseFilterConfigOverride(overrideAny)\nif err != nil {\n    return fmt.Errorf(\"rejecting xDS resource: RBAC override parse failed: %w\", err)\n}","preventionTips":["Pin go-control-plane to the same version on control plane and data plane.","Run proto round-trip tests: marshal RBACPerRoute to Any, unmarshal back, assert equality.","Use xDS debug logging (GRPC_XDS_DEBUG_V3=log) to inspect DiscoveryResponses before they reach filter builders."],"tags":["xds","rbac","grpc","proto","serialization"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}