apache/seatunnel · error · EdgeSocketConnectorException

DECRYPT_FAILED

DECRYPT_FAILED

Error message

Decryption failed for batchId={}, check secret_key configuration

What it means

WARN log in handleBatchRecord's EdgeSocketConnectorException branch when isDecryptionError() matched, meaning the batch payload could not be decrypted — almost always a secret_key mismatch between the edge sender and the connector. The batch is rejected with the DECRYPT_FAILED response code rather than failing the task, since it is a per-batch data error.

Solutions

  1. Verify secret_key in the EdgeSocket source config exactly matches the key used by the sending device (byte-for-byte, no stray whitespace)
  2. Roll out coordinated key rotation: update devices and connector together, or support overlap of old/new keys temporarily
  3. Confirm the device encryption algorithm/mode matches what the connector's decryptor implements
  4. Test with an unencrypted batch (device encryption disabled) to isolate whether decryption or encoding is at fault
  5. Inspect the logged connectorException stack trace for the precise crypto error (bad key size vs bad padding)

Example fix

# before: mismatched key
secret_key = "st-old-shared-key"
# after: key matching the edge device's current key
secret_key = "st-current-shared-key-2024"
Defensive patterns

Strategy: validation

Validate before calling

// sender-side sanity: key configured and non-empty, same length as receiver key
if (secretKey == null || secretKey.isEmpty()) throw new IllegalStateException("secret_key not set");
if (secretKey.length() != expectedKeyLength) throw new IllegalStateException("key size mismatch");

Try / catch

// sender: treat DECRYPT_FAILED as fatal config error, stop retrying with same key
if ("DECRYPT_FAILED".equals(responseCode)) {
    log.error("Receiver rejected key; verify secret_key parity before resending");
    throw new ConfigurationException("secret_key mismatch with connector");
}

Prevention

When it happens

Trigger: handleBatchRecord -> decode path throws EdgeSocketConnectorException classified as a decryption error (wrong/rotated AES key, corrupted ciphertext, key not configured while payload is encrypted).

Common situations: secret_key changed on the connector but edge devices still use the old key (or vice versa); different devices provisioned with different keys; payload encrypted with a different algorithm/IV scheme than the connector expects; secret_key whitespace/encoding differences between config and device.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/88115a740ddfb9c9. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceReader.java:203

                if (offerResult == QueueOfferResult.ACCEPTED) {
                    sourceState.markRecordReceived(batchId);
                    return EdgeSocketResponseCode.RECEIVED.getCode();
                }
            }
            queueFullCount++;
            if (queueFullCount == 1 || queueFullCount % 100 == 0) {
                log.warn(
                        "Ingress queue physically full, returning RETRY "
                                + "(capacity={}, rejectCount={}, batchId={})",
                        config.getLocalQueueCapacity(),
                        queueFullCount,
                        batchId);
            }
            return EdgeSocketResponseCode.RETRY.getCode();
        } catch (EdgeSocketConnectorException connectorException) {
            if (isDecryptionError(connectorException)) {
                log.warn(
                        "Decryption failed for batchId={}, check secret_key configuration",
                        batchId,
                        connectorException);
                return EdgeSocketResponseCode.DECRYPT_FAILED.getCode();
            }
            log.warn("Decode ingress packet failed for batchId={}", batchId, connectorException);
            return EdgeSocketResponseCode.DECODE_FAILED.getCode();
        } catch (Exception decodeException) {
            log.warn("Decode or enqueue ingress packet failed", decodeException);
            return EdgeSocketResponseCode.DECODE_FAILED.getCode();
        }
    }

    @Override
    public String handleCommitRequest(long batchId) {
        synchronized (stateLock) {
            return sourceState.resolveCommitResponse(batchId);
        }
    }

View on GitHub (pinned to cf67b549a7)