grpc/grpc-go · error
httpfilter
Error message
httpfilter: %v
What it means
The allow_expression regex in the ExtAuthz header mutation rules could not be compiled (extconfig.go:81-83). CompileSafeRegex first tries regexp.Compile to catch syntax errors, and this failed, meaning the regex pattern contains invalid RE2 syntax.
Solutions
- Test the allow_expression regex locally with Go's regexp.Compile before deploying to the xDS server
- Verify the regex uses only RE2-compatible syntax (no backreferences, no lookahead/lookbehind)
- Check for common syntax errors: unbalanced parentheses, invalid escape sequences, unterminated character classes
- If the regex works in Envoy's C++ regex engine but not Go's RE2, rewrite it in RE2-compatible syntax
Defensive patterns
Strategy: validation
Validate before calling
// Pre-validate the allow_expression regex before sending it via xDS.
if allowExpr := rules.GetAllowExpression(); allowExpr != nil {
if _, err := regexp.Compile(allowExpr.GetRegex().GetRegex()); err != nil {
return fmt.Errorf("invalid allow_expression regex: %w", err)
}
} Prevention
- Test all regex patterns with Go's regexp.Compile before deploying to the xDS server
- Ensure regex patterns use only RE2-compatible syntax (no backreferences, no lookahead)
- Add server-side config validation that rejects invalid regex patterns
- Keep a registry of tested regex patterns for reuse
When it happens
Trigger: HeaderMutationRulesFromProto receives a non-nil allow_expression whose GetRegex() pattern fails regexp.Compile — e.g. unbalanced parentheses, invalid escape sequences, invalid character classes.
Common situations: xDS server sends an invalid allow_expression regex pattern; Envoy RE2 regex syntax incompatibility with Go's regexp engine; typo in the regex configuration on the server side.
Related errors
- extauthz: empty grpc_service provided in config
- extauthz: missing default_value in deny_at_disable
- extauthz: missing default_value in filter_enabled
- invalid header mutation
- extauthz: error parsing config
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/3b73fb72b6de1871.
Report an issue: GitHub.
Appendix: source
Thrown at internal/xds/httpfilter/extconfig.go:83
if err != nil {
return nil, err
}
matchers = append(matchers, sm)
}
return matchers, nil
}
// HeaderMutationRulesFromProto converts a protobuf HeaderMutationRules proto
// message to a HeaderMutationRules struct.
func HeaderMutationRulesFromProto(mr *v3mutationpb.HeaderMutationRules) (HeaderMutationRules, error) {
var rules HeaderMutationRules
if mr == nil {
return rules, nil
}
if allowExpr := mr.GetAllowExpression(); allowExpr != nil {
re, err := matcher.CompileSafeRegex(allowExpr.GetRegex())
if err != nil {
return rules, fmt.Errorf("httpfilter: %v", err)
}
rules.AllowExpr = re
}
if disallowExpr := mr.GetDisallowExpression(); disallowExpr != nil {
re, err := matcher.CompileSafeRegex(disallowExpr.GetRegex())
if err != nil {
return rules, fmt.Errorf("httpfilter: %v", err)
}
rules.DisallowExpr = re
}
rules.DisallowAll = mr.GetDisallowAll().GetValue()
rules.DisallowIsError = mr.GetDisallowIsError().GetValue()
return rules, nil
}
// ApplyAdditions takes a set of header mutations (for additions and
// modifications) received from an external server and applies them to the
// provided metadata, subject to the rules defined in hmr.View on GitHub (pinned to 0c51461d27)