Skip to content

grpc-xds: add virtual-host domain matching - #2871

Open
YutaoMa wants to merge 8 commits into
grpc:masterfrom
YutaoMa:yutaoma/grpc-xds-virtual-host-match
Open

YutaoMa wants to merge 8 commits into
grpc:masterfrom
YutaoMa:yutaoma/grpc-xds-virtual-host-match

Conversation

@YutaoMa

@YutaoMa YutaoMa commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Motivation

Ref: #2754

For gRFC A74 XdsDependencyManager, to resolve the channel's virtual host, we'll need to run string matching per Envoy StringMatcher spec.

Solution

To reduce the size of the upcoming A74 PR, I'm sending this StringMatcher PR first. The implementation mostly follows the design we used in tonic-xds, with these highlights:

  1. Since the same string matching logic is shared between the virtual host selection and A29 SAN matching for mTLS, we extracted a common StringMatcher validated resource type and a pure matcher module.
  2. Used the Rust idiomatic "new type" pattern for DomainMatchScore and SafeRegex: the former encapsulate the match ordering semantics, and the latter to reject empty regex pattern and conform to the "only match the entire input" Envoy spec.

Prepare for the gRFC A74 XdsDependencyManager, which must select the
channel’s virtual host before resolving its cluster dependencies and
publishing an atomic XdsConfig snapshot.

Select virtual hosts using ASCII case-insensitive domain matching,
wildcard precedence, and longest-pattern ordering. Reject malformed
domain patterns during route configuration validation.

Separate validated string and full-match regex types from runtime
matching for reuse by routing and future SAN matching.
@YutaoMa
YutaoMa marked this pull request as ready for review September 17, 2026 17:01
@YutaoMa

YutaoMa commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Hi @dfawley @arjan-bal this is the first PR of the XdsDependencyManager work. Let me know if you have any thoughts and comments on it

Comment thread grpc-xds/src/lib.rs Outdated
Comment thread grpc-xds/src/matcher/mod.rs Outdated
Comment thread grpc-xds/src/resource/safe_regex.rs
Comment thread grpc-xds/src/resource/string_matcher.rs Outdated
Comment thread grpc-xds/src/resource/string_matcher.rs Outdated
Comment thread grpc-xds/src/resource/safe_regex.rs Outdated
Comment thread grpc-xds/src/matcher/string.rs Outdated
@arjan-bal arjan-bal assigned YutaoMa and unassigned arjan-bal Sep 23, 2026
@YutaoMa YutaoMa closed this Sep 23, 2026
@YutaoMa
YutaoMa deleted the yutaoma/grpc-xds-virtual-host-match branch September 23, 2026 22:01
@YutaoMa
YutaoMa restored the yutaoma/grpc-xds-virtual-host-match branch September 23, 2026 22:01
@YutaoMa

YutaoMa commented Sep 24, 2026

Copy link
Copy Markdown
Contributor Author

Accidentally closed when I'm cleaning up my fork's branches, reopening

@YutaoMa YutaoMa reopened this Sep 24, 2026

@arjan-bal arjan-bal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Took another pass. We use the assignee field to track whose turn it is to act (author or reviewer). Please assign this back to me when you're ready for another review.

Comment thread grpc-xds/src/resource/string_matcher.rs
Comment thread grpc-xds/src/resource/string_matcher.rs Outdated
Comment thread grpc-xds/src/resource/string_matcher.rs Outdated
Comment thread grpc-xds/src/resource/string_matcher.rs Outdated
Comment thread grpc-xds/src/routing/virtual_host.rs Outdated
Comment thread grpc-xds/src/routing/virtual_host.rs Outdated
Comment thread grpc-xds/src/routing/virtual_host.rs Outdated
Comment thread grpc-xds/src/routing/virtual_host.rs Outdated
Comment thread grpc-xds/src/resource/route.rs Outdated
Comment on lines 205 to 209
if domains_view.is_empty() {
return Err(Error::Validation(format!(
"virtual host '{name}' has no domains"
)));
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Go doesn't seem to fail validation for empty domains, and the proto field's docs don't mention any constraints on length. I think we should allow empty lists here unless there's a strong precedent to block them.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this validation rule in proto enforces it? https://github.com/envoyproxy/envoy/blob/main/api/envoy/config/route/v3/route_components.proto#L92
C++ does error on it: https://github.com/grpc/grpc/blob/48a59c06db710c6a536636fc7ddc99719cffd08e/src/core/xds/grpc/xds_route_config_parser.cc#L745-L748

Seems like gRPC Go and Java doesn't. I'm ok with either, let me know what's your opinion.

@YutaoMa YutaoMa assigned arjan-bal and unassigned YutaoMa Oct 1, 2026
@YutaoMa

YutaoMa commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Thanks @arjan-bal , I've addressed the above comments, ptal. Assigning back to you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants