{"record":{"id":"f4b47a2af7096178","repo":"grpc/grpc-go","slug":"received-frame-with-size-v-which-is-shorter-than","errorCode":null,"errorMessage":"received frame with size %v which is shorter than message type field size %v","messagePattern":"received frame with size (.+?) which is shorter than message type field size (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/alts/internal/conn/record.go","lineNumber":269,"sourceCode":"\t\t\t\t}\n\t\t\t\tp.protectedHandle = newBuf\n\t\t\t\tprotected = (*newBuf)[:nRead]\n\t\t\t} else {\n\t\t\t\tnRead, err := p.Conn.Read(protected[len(protected):cap(protected)])\n\t\t\t\tif err != nil {\n\t\t\t\t\treturn nil, 0, err\n\t\t\t\t}\n\t\t\t\tprotected = protected[:len(protected)+nRead]\n\t\t\t}\n\t\t\tframedMsg, p.nextFrame, err = ParseFramedMsg(protected, altsRecordLengthLimit)\n\t\t\tif err != nil {\n\t\t\t\treturn nil, 0, err\n\t\t\t}\n\t\t}\n\t\t// Now we have a complete frame, decrypted it.\n\t\tmsg := framedMsg[MsgLenFieldSize:]\n\t\tif len(msg) < msgTypeFieldSize {\n\t\t\treturn nil, 0, fmt.Errorf(\"received frame with size %v which is shorter than message type field size %v\", len(msg), msgTypeFieldSize)\n\t\t}\n\t\tmsgType := binary.LittleEndian.Uint32(msg[:msgTypeFieldSize])\n\t\tif msgType&0xff != altsRecordMsgType {\n\t\t\treturn nil, 0, fmt.Errorf(\"received frame with incorrect message type %v, expected lower byte %v\",\n\t\t\t\tmsgType, altsRecordMsgType)\n\t\t}\n\t\tciphertext := msg[msgTypeFieldSize:]\n\n\t\t// Decrypt directly into the buffer, avoiding a copy from p.buf if\n\t\t// possible.\n\t\tif bufSize >= len(ciphertext) {\n\t\t\tallocatedBuf := pool.Get(bufSize)\n\t\t\tdec, err := p.crypto.Decrypt((*allocatedBuf)[:0], ciphertext)\n\t\t\tif err != nil {\n\t\t\t\tpool.Put(allocatedBuf)\n\t\t\t\treturn nil, 0, err\n\t\t\t}\n\t\t\tp.dropProtectedIfEmtpy()","sourceCodeStart":251,"sourceCodeEnd":287,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/alts/internal/conn/record.go#L251-L287","documentation":"Returned during ALTS record reading (conn.ReadOnReady) when a complete frame was received but the payload after the 4-byte length field is shorter than the 4-byte message-type field (msgTypeFieldSize). This means the frame is too small to even contain a message type, indicating a truncated or malformed frame.","triggerScenarios":"An ALTS-secured peer sends a frame whose declared length results in fewer than 4 bytes after the length header. Reached on every Read/ReadOnReady of an ALTS connection when a full frame is available.","commonSituations":"Memory corruption or bit-flips on the wire; a buggy or non-conformant ALTS peer; a man-in-the-middle injecting partial data; closing/tearing down the connection mid-frame in a way that produces a short final record.","solutions":["Verify the peer runs a compliant ALTS implementation and matching gRPC version.","Capture a packet trace to inspect the malformed frame.","Treat as connection-fatal: the ALTS conn is now in an inconsistent state, so close it and let gRPC establish a new one.","If reproducible only against one peer, focus the investigation on that peer's gRPC/ALTS build."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Short frames mean the connection is corrupted; close it.\n// Application code sees this as a transport error on the RPC; retry with backoff.\nif err != nil && strings.Contains(err.Error(), \"shorter than message type field size\") {\n    _ = conn.Close() // discard corrupted ALTS connection\n}","preventionTips":["Only connect ALTS endpoints to other legitimate ALTS endpoints on GCP.","Investigate persistent short-frame errors with a packet capture.","Do not attempt to recover a desynchronized ALTS connection; reconnect."],"tags":["grpc","alts","framing","corruption","parsing"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}