grpc/grpc-go · error

httpfilter

Error message

httpfilter: %v

What it means

The allow_expression regex in the ExtAuthz header mutation rules could not be compiled (extconfig.go:81-83). CompileSafeRegex first tries regexp.Compile to catch syntax errors, and this failed, meaning the regex pattern contains invalid RE2 syntax.

Solutions

  1. Test the allow_expression regex locally with Go's regexp.Compile before deploying to the xDS server
  2. Verify the regex uses only RE2-compatible syntax (no backreferences, no lookahead/lookbehind)
  3. Check for common syntax errors: unbalanced parentheses, invalid escape sequences, unterminated character classes
  4. If the regex works in Envoy's C++ regex engine but not Go's RE2, rewrite it in RE2-compatible syntax
Defensive patterns

Strategy: validation

Validate before calling

// Pre-validate the allow_expression regex before sending it via xDS.
if allowExpr := rules.GetAllowExpression(); allowExpr != nil {
    if _, err := regexp.Compile(allowExpr.GetRegex().GetRegex()); err != nil {
        return fmt.Errorf("invalid allow_expression regex: %w", err)
    }
}

Prevention

When it happens

Trigger: HeaderMutationRulesFromProto receives a non-nil allow_expression whose GetRegex() pattern fails regexp.Compile — e.g. unbalanced parentheses, invalid escape sequences, invalid character classes.

Common situations: xDS server sends an invalid allow_expression regex pattern; Envoy RE2 regex syntax incompatibility with Go's regexp engine; typo in the regex configuration on the server side.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/3b73fb72b6de1871. Report an issue: GitHub.

Appendix: source

Thrown at internal/xds/httpfilter/extconfig.go:83

		if err != nil {
			return nil, err
		}
		matchers = append(matchers, sm)
	}
	return matchers, nil
}

// HeaderMutationRulesFromProto converts a protobuf HeaderMutationRules proto
// message to a HeaderMutationRules struct.
func HeaderMutationRulesFromProto(mr *v3mutationpb.HeaderMutationRules) (HeaderMutationRules, error) {
	var rules HeaderMutationRules
	if mr == nil {
		return rules, nil
	}
	if allowExpr := mr.GetAllowExpression(); allowExpr != nil {
		re, err := matcher.CompileSafeRegex(allowExpr.GetRegex())
		if err != nil {
			return rules, fmt.Errorf("httpfilter: %v", err)
		}
		rules.AllowExpr = re
	}
	if disallowExpr := mr.GetDisallowExpression(); disallowExpr != nil {
		re, err := matcher.CompileSafeRegex(disallowExpr.GetRegex())
		if err != nil {
			return rules, fmt.Errorf("httpfilter: %v", err)
		}
		rules.DisallowExpr = re
	}
	rules.DisallowAll = mr.GetDisallowAll().GetValue()
	rules.DisallowIsError = mr.GetDisallowIsError().GetValue()
	return rules, nil
}

// ApplyAdditions takes a set of header mutations (for additions and
// modifications) received from an external server and applies them to the
// provided metadata, subject to the rules defined in hmr.

View on GitHub (pinned to 0c51461d27)