grpc/grpc-go · warning
grpc: credentials.Bundle must return non-nil transport…
Error message
grpc: credentials.Bundle must return non-nil transport credentials
What it means
Documented as thrown by convertCustomConfig when the typeURL split on '/' yields zero segments, but this code path is effectively unreachable: Go's strings.Split always returns at least one element (even for an empty string it returns [""]). Therefore len(urls) == 0 after strings.Split is always false. If it were reachable, it would indicate a typeURL that is not URL-like. In practice, the empty-name case is caught earlier at converter.go:43-44 (empty loggerName) rather than here.
Solutions
- If you encounter this error, investigate whether the grpc-go source or strings package has been modified; under standard Go it cannot fire.
- For the practical empty-typeURL problem, set the type_url to a non-empty URL-formatted string with a '/' separator (e.g., prefix/LoggerName).
- Report the error as a potential bug if it occurs with unmodified grpc-go, since the guard at line 87 is dead code.
Example fix
// This error is unreachable; strings.Split never returns a 0-length slice. // For empty-name issues, fix the type_url: // before: typeUrl: "" // after: typeUrl: "grpc.authz.audit_logging/mylogger"
Defensive patterns
Strategy: validation
Validate before calling
// This error is unreachable (strings.Split never returns 0 elements).
// Validate the type_url produces a non-empty name instead:
func validateTypeURLName(typeURL string) error {
name := typeURL
if idx := strings.LastIndex(typeURL, "/"); idx >= 0 {
name = typeURL[idx+1:]
}
if name == "" {
return fmt.Errorf("type_url %q produces empty logger name", typeURL)
}
return nil
} Prevention
- Do not rely on the len(urls)==0 guard; it is dead code. Validate for empty name via LastIndex instead.
- Always set type_url to a non-empty string with at least one '/' separator.
- Report encounters of this error as a potential bug, since the guard is unreachable under standard Go.
When it happens
Trigger: Effectively unreachable under normal Go semantics. The only theoretical trigger would be a non-standard strings.Split implementation or a future refactor that changes the splitting logic. If you see this error in the wild, it indicates a code-generation anomaly or memory corruption, not a configuration mistake.
Common situations: Not reproducible with standard Go. If encountered, likely a symptom of a patched/modified strings package or a different code path than the one analyzed. The practical equivalent — an empty typeURL producing an empty logger name — is handled by the loggerName empty check at line 43-44.
Related errors
- grpc: the connection is closing
- grpc: credentials.Bundle may not be used with individual…
- grpc: no transport security set (use…
- grpc: the connection is closing due to channel idleness
- grpc: the connection is drained
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/d2936028ec240f83.
Report an issue: GitHub.
Appendix: source
Thrown at clientconn.go:96
// invalidDefaultServiceConfigErrPrefix is used to prefix the json parsing error for the default
// service config.
invalidDefaultServiceConfigErrPrefix = "grpc: the provided default service config is invalid"
// PickFirstBalancerName is the name of the pick_first balancer.
PickFirstBalancerName = pickfirst.Name
)
// The following errors are returned from Dial and DialContext
var (
// errNoTransportSecurity indicates that there is no transport security
// being set for ClientConn. Users should either set one or explicitly
// call WithInsecure DialOption to disable security.
errNoTransportSecurity = errors.New("grpc: no transport security set (use grpc.WithTransportCredentials(insecure.NewCredentials()) explicitly or set credentials)")
// errTransportCredsAndBundle indicates that creds bundle is used together
// with other individual Transport Credentials.
errTransportCredsAndBundle = errors.New("grpc: credentials.Bundle may not be used with individual TransportCredentials")
// errNoTransportCredsInBundle indicated that the configured creds bundle
// returned a transport credentials which was nil.
errNoTransportCredsInBundle = errors.New("grpc: credentials.Bundle must return non-nil transport credentials")
// errTransportCredentialsMissing indicates that users want to transmit
// security information (e.g., OAuth2 token) which requires secure
// connection on an insecure connection.
errTransportCredentialsMissing = errors.New("grpc: the credentials require transport level security (use grpc.WithTransportCredentials() to set)")
)
var (
disconnectionsMetric = expstats.RegisterInt64Count(expstats.MetricDescriptor{
Name: "grpc.subchannel.disconnections",
Description: "EXPERIMENTAL. Number of times the selected subchannel becomes disconnected.",
Unit: "{disconnection}",
Labels: []string{"grpc.target"},
OptionalLabels: []string{"grpc.lb.backend_service", "grpc.lb.locality", "grpc.disconnect_error"},
Default: false,
})
connectionAttemptsSucceededMetric = expstats.RegisterInt64Count(expstats.MetricDescriptor{
Name: "grpc.subchannel.connection_attempts_succeeded",
Description: "EXPERIMENTAL. Number of successful connection attempts.",View on GitHub (pinned to 0c51461d27)