grpc/grpc-go · error

extauthz: error parsing override config

Error message

extauthz: error parsing override config %v: unknown type %T, want *anypb.Any

What it means

ParseFilterConfigOverride expected the override configuration wrapped as *anypb.Any but received a different concrete proto type (ext_authz.go:170-172). Per-route filter override configs are transported as Any-wrapped messages in the xDS protocol.

Solutions

  1. Ensure the httpfilter framework passes *anypb.Any to ParseFilterConfigOverride
  2. Wrap the override config proto with anypb.New() before calling the parser in test code
  3. Do not manually unwrap Any before dispatching to filter override parsers

Example fix

// before — bare proto passed
override := &v3extauthzpb.ExtAuthzPerRoute{}
fc, err := builder{}.ParseFilterConfigOverride(override)

// after — wrap in Any first
anyOverride, _ := anypb.New(override)
fc, err := builder{}.ParseFilterConfigOverride(anyOverride)
Defensive patterns

Strategy: type-guard

Type guard

// Ensure the override config is *anypb.Any before passing to the parser.
func isAnyProto(msg proto.Message) bool {
    _, ok := msg.(*anypb.Any)
    return ok
}

Prevention

When it happens

Trigger: The httpfilter framework calls ParseFilterConfigOverride with a proto.Message whose concrete type is not *anypb.Any (e.g. a bare ExtAuthzPerRoute proto passed by custom integration or test code).

Common situations: Custom httpfilter integration that unwraps Any before dispatching to the override parser; incorrect framework wiring; test code passing a bare ExtAuthzPerRoute proto instead of wrapping it.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/d15ef9a637c96778. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/ext_authz/ext_authz.go:172

		failureModeAllowHeaderAdd:  msg.GetFailureModeAllowHeaderAdd(),
		statusOnError:              statusOnError,
		allowedHeaders:             allowedHeaders,
		disallowedHeaders:          disallowedHeaders,
		decoderHeaderMutationRules: mutationRules,
		includePeerCertificate:     msg.GetIncludePeerCertificate(),
	}, nil
}

// ParseFilterConfigOverride parses the provided override configuration.
//
// Note that ExtAuthzPerRoute is unmarshaled to verify its syntax during xDS
// resource validation, no filter configuration object is returned. Per-route
// disabling is supported via the generic FilterConfig wrapper mechanism rather
// than the ExtAuthzPerRoute.disabled field directly.
func (builder) ParseFilterConfigOverride(overrideCfg proto.Message) (httpfilter.FilterConfig, error) {
	m, ok := overrideCfg.(*anypb.Any)
	if !ok {
		return nil, fmt.Errorf("extauthz: error parsing override config %v: unknown type %T, want *anypb.Any", overrideCfg, overrideCfg)
	}
	msg := new(v3extauthzpb.ExtAuthzPerRoute)
	if err := m.UnmarshalTo(msg); err != nil {
		return nil, fmt.Errorf("extauthz: failed to unmarshal override config %v: %v", overrideCfg, err)
	}
	return nil, nil
}

func (builder) IsTerminal() bool {
	return false
}

View on GitHub (pinned to 0c51461d27)