xds: leaf clusters provide the handshake info instead of top level cluster (#8956) Fixes: https://github.com/grpc/grpc-go/issues/8599 This PR is part of gRFC A74. The changes in this PR are : 1. Ensures the handshake uses the security configuration defined at the leaf cluster level, rather than defaulting to the top-level aggregate cluster configuration. 2. Previously, errors returned by `priority.UpdateClientConnState` to update the clusterimpl's state were silently suppressed. This has been changed to ensure these errors are properly propagated, triggering a Transient Failure (TF) state when an error is returned. 3. Added a test case to verify that leaf cluster security configurations take precedence over the top-level aggregate cluster. The test uses a top-level cluster with an invalid SAN matcher (which passes xDS validation but fails at the handshake level) and a leaf cluster with a valid configuration. Confirmed that RPCs now succeed by correctly utilizing the leaf config; verified the test fails on master but passes with this PR. RELEASE NOTES: * xds: Fixed an issue where security config from the top-level aggregate cluster were used instead of the leaf cluster for handshake.
The Go implementation of gRPC: A high performance, open source, general RPC framework that puts mobile and HTTP/2 first. For more information see the Go gRPC docs, or jump directly into the quick start.
Simply add the following import to your code, and then go [build|run|test] will automatically fetch the necessary dependencies:
import "google.golang.org/grpc"
Note: If you are trying to access
grpc-gofrom China, see the FAQ below.
The golang.org domain may be blocked from some countries. go get usually produces an error like the following when this happens:
$ go get -u google.golang.org/grpc package google.golang.org/grpc: unrecognized import path "google.golang.org/grpc" (https fetch: Get https://google.golang.org/grpc?go-get=1: dial tcp 216.239.37.1:443: i/o timeout)
To build Go code, there are several options:
Set up a VPN and access google.golang.org through that.
With Go module support: it is possible to use the replace feature of go mod to create aliases for golang.org packages. In your project's directory:
go mod edit -replace=google.golang.org/grpc=github.com/grpc/grpc-go@latest go mod tidy go mod vendor go build -mod=vendor
Again, this will need to be done for all transitive dependencies hosted on golang.org as well. For details, refer to golang/go issue #28652.
Please update to the latest version of gRPC-Go using go get google.golang.org/grpc.
The default logger is controlled by environment variables. Turn everything on like this:
$ export GRPC_GO_LOG_VERBOSITY_LEVEL=99 $ export GRPC_GO_LOG_SEVERITY_LEVEL=info
"code = Unavailable desc = transport is closing"This error means the connection the RPC is using was closed, and there are many possible reasons, including:
It can be tricky to debug this because the error happens on the client side but the root cause of the connection being closed is on the server side. Turn on logging on both client and server, and see if there are any transport errors.