apache/iceberg · warning
Full metadata integrity check skipped because no metadata…
Error message
Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}. Falling back to encryption property based check. What it means
HiveTableOperations.checkIntegrityForEncryption (invoked from doRefresh) verifies table metadata integrity against a metadata hash stored in HMS table properties. When no hash was recorded, a full integrity check is impossible, so the code logs this warning and falls back to a weaker encryption-property-based check.
Solutions
- Refresh/rewrite table metadata once with a client that records the metadata hash property into HMS
- Confirm the expected metadata-hash table property is present via describe formatted <table> in Hive
- If the weaker property-based check is acceptable, no action needed — it is a warning only
- Avoid manually editing HMS table parameters; use Iceberg APIs to update properties
Example fix
// before
Table table = catalog.loadTable(id); // warns: no hash recorded
// after
Table table = catalog.loadTable(id);
table.updateProperties().set("write.metadata.hash.enabled", "true").commit(); // client records hash going forward Defensive patterns
Strategy: fallback
Validate before calling
Map<String,String> props = ((HiveTable) table).properties(); // verify metadata hash property present before relying on integrity checks
Prevention
- Migrate legacy tables with a client version that records the metadata hash
- Avoid manually editing HMS table parameters
- Monitor for this warning to detect mixed client versions writing to the table
When it happens
Trigger: Refreshing a table whose HMS properties lack the metadata hash property — tables created before the hash feature existed, tables written by clients that don't record the hash, or hash manually removed from table properties.
Common situations: Upgrading older Iceberg tables to encryption-aware versions; mixed client versions writing to the same table; someone manually altering HMS table parameters.
Understand the failure class
Background: "missing required config value" errors: why libraries refuse to start when a configuration key is empty, unset, or blank — this error's family across 48 libraries.
Related errors
- The current metadata file
- GCM tag check failed. Possible reasons: wrong decryption…
- Unable to produce hash of table metadata
- Avro does not support AAD prefix
- Avro does not support file encryption keys
AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12).
Data as JSON: /api/errors/fc9115e0894674cc.
Report an issue: GitHub.
Appendix: source
Thrown at hive-metastore/src/main/java/org/apache/iceberg/hive/HiveTableOperations.java:582
if (tableKeyId != null && encryptionDekLength <= 0) {
encryptionDekLength =
PropertyUtil.propertyAsInt(
tableProperties,
TableProperties.ENCRYPTION_DEK_LENGTH,
TableProperties.ENCRYPTION_DEK_LENGTH_DEFAULT);
}
}
private void checkIntegrityForEncryption(
String encryptionKeyIdFromHMS, String dekLengthFromHMS, String metadataHashFromHMS) {
TableMetadata metadata = current();
if (StringUtils.isNotEmpty(metadataHashFromHMS)) {
HMSTablePropertyHelper.verifyMetadataHash(metadata, metadataHashFromHMS);
return;
}
LOG.warn(
"Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}."
+ " Falling back to encryption property based check.",
tableName);
Map<String, String> propertiesFromMetadata = metadata.properties();
String encryptionKeyIdFromMetadata =
propertiesFromMetadata.get(TableProperties.ENCRYPTION_TABLE_KEY);
if (!Objects.equals(encryptionKeyIdFromHMS, encryptionKeyIdFromMetadata)) {
String errMsg =
String.format(
"Metadata file might have been modified. Encryption key id %s differs from HMS value %s",
encryptionKeyIdFromMetadata, encryptionKeyIdFromHMS);
throw new RuntimeException(errMsg);
}
String dekLengthFromMetadata =
propertiesFromMetadata.get(TableProperties.ENCRYPTION_DEK_LENGTH);View on GitHub (pinned to 86d9c8fc54)