apache/iceberg · error · UnsupportedOperationException

ORC does not support AAD prefix

Error message

ORC does not support AAD prefix

What it means

ORC does not support AAD (additional authenticated data) prefixes used by Parquet-style modular encryption. The ORC ModelWriteBuilder.withAADPrefix override always throws UnsupportedOperationException.

Solutions

  1. Remove AAD prefix configuration for ORC writes
  2. Use Parquet when AAD-based encryption metadata is required
  3. Guard the write path so encryption-related builder calls only run for Parquet

Example fix

// before
builder.withAADPrefix(encryption.aadPrefix()); // throws for ORC
// after
if (supportsEncryption(format)) { builder.withAADPrefix(encryption.aadPrefix()); }
Defensive patterns

Strategy: type-guard

Validate before calling

if (format == FileFormat.ORC && aadPrefix != null) {
  throw new IllegalArgumentException("AAD prefix is not supported for ORC");
}

Type guard

boolean aadSupported(FileFormat f) { return f == FileFormat.PARQUET; }

Try / catch

try {
  builder.withAADPrefix(aadPrefix);
} catch (UnsupportedOperationException e) {
  if (e.getMessage().contains("AAD prefix")) {
    log.warn("ORC does not support AAD prefix; skipping");
  } else throw e;
}

Prevention

When it happens

Trigger: Calling withAADPrefix(...) (or a generic writer configuration that sets an AAD prefix) when building an ORC FileAppender.

Common situations: Same as encryption keys: unified Parquet/ORC write code paths, tables migrated from Parquet with encryption properties still set.

Related errors


AI-assisted analysis of apache/iceberg@86d9c8fc54 (2026-09-12). Data as JSON: /api/errors/36840d45388b54b6. Report an issue: GitHub.

Appendix: source

Thrown at orc/src/main/java/org/apache/iceberg/orc/ORCFormatModel.java:165

      return this;
    }

    @Override
    public ModelWriteBuilder<D, S> overwrite() {
      internal.overwrite();
      return this;
    }

    @Override
    public ModelWriteBuilder<D, S> withFileEncryptionKey(ByteBuffer encryptionKey) {
      // ORC doesn't support file encryption
      throw new UnsupportedOperationException("ORC does not support file encryption keys");
    }

    @Override
    public ModelWriteBuilder<D, S> withAADPrefix(ByteBuffer aadPrefix) {
      // ORC doesn't support file encryption
      throw new UnsupportedOperationException("ORC does not support AAD prefix");
    }

    @Override
    public FileAppender<D> build() {
      switch (content) {
        case DATA:
          internal.createContextFunc(ORC.WriteBuilder.Context::dataContext);
          internal.createWriterFunc(
              (icebergSchema, typeDescription) ->
                  writerFunction.write(icebergSchema, typeDescription, engineSchema));
          break;
        case EQUALITY_DELETES:
          internal.createContextFunc(ORC.WriteBuilder.Context::deleteContext);
          internal.createWriterFunc(
              (icebergSchema, typeDescription) ->
                  writerFunction.write(icebergSchema, typeDescription, engineSchema));
          break;
        case POSITION_DELETES:

View on GitHub (pinned to 86d9c8fc54)