influxdata/influxdb · critical

Invalid metadata value

Error message

Invalid metadata value

What it means

A `panic!` via `.expect("Invalid metadata value")` in `FlightClient::new`: converting a connection header value into a tonic `MetadataValue` failed. gRPC metadata values must be valid ASCII (or valid binary-flagged) strings; a failing `try_into` aborts the process rather than returning an error.

Solutions

  1. Re-enter the header value ensuring pure visible ASCII (regenerate tokens if needed)
  2. Pre-validate values with `MetadataValue::try_from(...)` and handle the Result instead of expect
  3. Trim whitespace/newlines from values sourced from env vars or config files
  4. Check for and remove smart quotes or invisible Unicode from copied credentials

Example fix

// before
let value: MetadataValue<_> =
    value.as_bytes().try_into().expect("Invalid metadata value");
// after
let value: MetadataValue<_> = value.as_bytes().try_into()
    .map_err(|e| anyhow::anyhow!("invalid metadata value: {}", e))?;
Defensive patterns

Strategy: validation

Validate before calling

use tonic::metadata::MetadataValue;
fn valid_metadata_values(headers: &[(String, String)]) -> Result<(), String> {
    for (_, value) in headers {
        MetadataValue::try_from(value.as_bytes())
            .map_err(|e| format!("invalid metadata value: {}", e))?;
    }
    Ok(())
}

Type guard

fn is_valid_metadata_value(value: &str) -> bool {
    tonic::metadata::MetadataValue::try_from(value.as_bytes()).is_ok()
}

Prevention

When it happens

Trigger: Constructing a FlightClient from an IOx Connection whose headers map contains a value with non-ASCII or otherwise gRPC-illegal bytes — e.g. a token pasted with smart quotes, a UTF-8 header value, or binary junk.

Common situations: Auth tokens or secrets copied from documents/terminals containing non-ASCII characters; values containing newlines or control characters from multi-line env vars; encoding issues when values pass through shells or YAML config.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/bdcc8e960a68b34e. Report an issue: GitHub.

Appendix: source

Thrown at core/influxdb_iox_client/src/client/flight/mod.rs:213

}

impl Client {
    /// Creates a new client with the provided [`Connection`]. Panics
    /// if the metadata in connection is invalid for the underlying
    /// tonic library.
    pub fn new(connection: Connection) -> Self {
        // Extract headers to include with each request
        let (channel, headers) = connection.into_grpc_connection().into_parts();

        let mut inner = FlightClient::new(channel);

        // Copy any headers from IOx Connection
        for (name, value) in headers.iter() {
            let name = MetadataKey::<_>::from_bytes(name.as_str().as_bytes())
                .expect("Invalid metadata name");

            let value: MetadataValue<_> =
                value.as_bytes().try_into().expect("Invalid metadata value");
            inner.metadata_mut().insert(name, value);
        }

        Self { inner }
    }

    /// Return the inner arrow flight client
    pub fn into_inner(self) -> FlightClient {
        self.inner
    }

    /// Get a mutable reference to the inner arrow flight client
    pub fn inner(&mut self) -> &mut FlightClient {
        &mut self.inner
    }

    /// Return a reference to gRPC metadata included with each request
    pub fn metadata(&self) -> &MetadataMap {

View on GitHub (pinned to 06200ef96b)