apache/hadoop · error · IOException

Failed to update token in SQL secret manager

Error message

Failed to update token in SQL secret manager

What it means

Error "Failed to update token in SQL secret manager" thrown in apache/hadoop.

Source

Thrown at hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/security/token/delegation/SQLDelegationTokenSecretManager.java:144

  /**
   * Updates the TokenInformation of an existing TokenIdentifier in
   * the SQL database.
   * @param ident Existing TokenIdentifier in the SQL database.
   * @param tokenInfo Updated DelegationTokenInformation associated with the TokenIdentifier.
   */
  @Override
  protected void updateToken(TokenIdent ident,
      DelegationTokenInformation tokenInfo) throws IOException {
    try (ByteArrayOutputStream bos = new ByteArrayOutputStream()) {
      try (DataOutputStream dos = new DataOutputStream(bos)) {
        tokenInfo.write(dos);
        // Update token in SQL database
        updateToken(ident.getSequenceNumber(), ident.getBytes(), bos.toByteArray());
        // Update token in local cache
        super.updateToken(ident, tokenInfo);
      }
    } catch (SQLException e) {
      throw new IOException("Failed to update token in SQL secret manager", e);
    }
  }

  /**
   * Cancels a token by removing it from the SQL database. This will
   * call the corresponding method in {@link AbstractDelegationTokenSecretManager}
   * to perform validation and remove the token from the cache.
   * @return Identifier of the canceled token
   */
  @Override
  public synchronized TokenIdent cancelToken(Token<TokenIdent> token,
      String canceller) throws IOException {
    TokenIdent id = createTokenIdent(token.getIdentifier());

    // Calling getTokenInfo to load token into local cache if not present.
    // super.cancelToken() requires token to be present in local cache.
    getTokenInfo(id);

View on GitHub (pinned to 2add963021)

Solutions

  1. The SQL UPDATE of the token row failed. Verify the token row still exists, the database connection is healthy, and the schema matches the expected columns; see the chained SQLException.

When it happens

Trigger: Thrown at hadoop-common-project/hadoop-common/src/main/java/org/apache/hadoop/security/token/delegation/SQLDelegationTokenSecretManager.java:144 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of apache/hadoop@2add963021 (2026-08-22). Data as JSON: /api/errors/eaa6ea409a142f8a. Report an issue: GitHub.