apache/iceberg · warning

Full metadata integrity check skipped because no metadata…

Error message

Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}. Falling back to encryption property based check.

What it means

HiveTableOperations.checkIntegrityForEncryption (invoked from doRefresh) verifies table metadata integrity against a metadata hash stored in HMS table properties. When no hash was recorded, a full integrity check is impossible, so the code logs this warning and falls back to a weaker encryption-property-based check.

Solutions

  1. Refresh/rewrite table metadata once with a client that records the metadata hash property into HMS
  2. Confirm the expected metadata-hash table property is present via describe formatted <table> in Hive
  3. If the weaker property-based check is acceptable, no action needed — it is a warning only
  4. Avoid manually editing HMS table parameters; use Iceberg APIs to update properties

Example fix

// before
Table table = catalog.loadTable(id); // warns: no hash recorded
// after
Table table = catalog.loadTable(id);
table.updateProperties().set("write.metadata.hash.enabled", "true").commit(); // client records hash going forward
Defensive patterns

Strategy: fallback

Validate before calling

Map<String,String> props = ((HiveTable) table).properties(); // verify metadata hash property present before relying on integrity checks

Prevention

When it happens

Trigger: Refreshing a table whose HMS properties lack the metadata hash property — tables created before the hash feature existed, tables written by clients that don't record the hash, or hash manually removed from table properties.

Common situations: Upgrading older Iceberg tables to encryption-aware versions; mixed client versions writing to the same table; someone manually altering HMS table parameters.

Understand the failure class

Background: "missing required config value" errors: why libraries refuse to start when a configuration key is empty, unset, or blank — this error's family across 48 libraries.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/fc9115e0894674cc. Report an issue: GitHub.

Appendix: source

Thrown at hive-metastore/src/main/java/org/apache/iceberg/hive/HiveTableOperations.java:582

    if (tableKeyId != null && encryptionDekLength <= 0) {
      encryptionDekLength =
          PropertyUtil.propertyAsInt(
              tableProperties,
              TableProperties.ENCRYPTION_DEK_LENGTH,
              TableProperties.ENCRYPTION_DEK_LENGTH_DEFAULT);
    }
  }

  private void checkIntegrityForEncryption(
      String encryptionKeyIdFromHMS, String dekLengthFromHMS, String metadataHashFromHMS) {
    TableMetadata metadata = current();
    if (StringUtils.isNotEmpty(metadataHashFromHMS)) {
      HMSTablePropertyHelper.verifyMetadataHash(metadata, metadataHashFromHMS);
      return;
    }

    LOG.warn(
        "Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}."
            + " Falling back to encryption property based check.",
        tableName);

    Map<String, String> propertiesFromMetadata = metadata.properties();

    String encryptionKeyIdFromMetadata =
        propertiesFromMetadata.get(TableProperties.ENCRYPTION_TABLE_KEY);
    if (!Objects.equals(encryptionKeyIdFromHMS, encryptionKeyIdFromMetadata)) {
      String errMsg =
          String.format(
              "Metadata file might have been modified. Encryption key id %s differs from HMS value %s",
              encryptionKeyIdFromMetadata, encryptionKeyIdFromHMS);
      throw new RuntimeException(errMsg);
    }

    String dekLengthFromMetadata =
        propertiesFromMetadata.get(TableProperties.ENCRYPTION_DEK_LENGTH);

View on GitHub (pinned to 86d9c8fc54)