apache/seatunnel · error · EdgeSocketConnectorException

PACKET_UNSUPPORTED_ENCRYPTION

PACKET_UNSUPPORTED_ENCRYPTION

Error message

Unsupported packet encryption type: 

What it means

In EdgeSocketPacketRecordDeserializer.decodeEncryption(), only NONE and AES_GCM encryption types are supported. If the packet declares any other encryption type, the method throws EdgeSocketConnectorException with code PACKET_UNSUPPORTED_ENCRYPTION and message 'Unsupported packet encryption type: ' + the type.

Solutions

  1. Set the producer's encryption to 'none' or 'aes_gcm' to match this consumer.
  2. Upgrade the consumer connector to a build that supports the packet's encryption type.
  3. Check for packet corruption or a sender emitting a wrong encryption field.

Example fix

// before (producer)
encryption = "chacha20"
// after (producer)
encryption = "aes_gcm"
Defensive patterns

Strategy: try-catch

Validate before calling

if (encryptionType != EdgeSocketEncryptionType.NONE && encryptionType != EdgeSocketEncryptionType.AES_GCM) {
    throw new IllegalArgumentException("Only NONE and AES_GCM are supported, got " + encryptionType);
}

Try / catch

try {
    byte[] payload = decryptedPayload(payloadBytes, packet, encryptionType);
} catch (EdgeSocketConnectorException e) {
    if (e.getErrorCode() == EdgeSocketConnectorErrorCode.PACKET_UNSUPPORTED_ENCRYPTION) {
        // reconfigure producer to aes_gcm or upgrade consumer
    }
}

Prevention

When it happens

Trigger: decodeEncryption() (via decryptedPayload) receives a packet whose encryption field resolves to a non-NONE, non-AES_GCM value — e.g. a packet from a newer producer build supporting an additional cipher.

Common situations: Version skew between producer and consumer, packets from a third-party emitter using a different cipher scheme, or a corrupted encryption header value.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/fd9818936d085a91. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/serialize/record/EdgeSocketPacketRecordDeserializer.java:93

    }

    /**
     * Decode payload encryption according to packet metadata.
     *
     * @param payloadBytes base64-decoded payload bytes from packet
     * @param packet ingress packet metadata
     * @param encryptionType resolved encryption type
     * @return decrypted payload bytes (or original bytes when encryption is NONE)
     */
    private byte[] decodeEncryption(
            byte[] payloadBytes,
            EdgeSocketIngressPacket packet,
            EdgeSocketEncryptionType encryptionType) {
        if (encryptionType == EdgeSocketEncryptionType.NONE) {
            return payloadBytes;
        }
        if (encryptionType != EdgeSocketEncryptionType.AES_GCM) {
            throw new EdgeSocketConnectorException(
                    EdgeSocketConnectorErrorCode.PACKET_UNSUPPORTED_ENCRYPTION,
                    "Unsupported packet encryption type: " + encryptionType);
        }
        if (config.getSecretKeyBytes() == null || config.getSecretKeyBytes().length == 0) {
            throw new EdgeSocketConnectorException(
                    EdgeSocketConnectorErrorCode.PACKET_AES_KEY_MISSING,
                    "Missing secret_key when packet encryption is AES_GCM");
        }
        if (packet.getIv() == null || packet.getIv().isEmpty()) {
            throw new EdgeSocketConnectorException(
                    EdgeSocketConnectorErrorCode.PACKET_DECODE_ERROR,
                    "Missing iv in AES_GCM packet");
        }
        try {
            byte[] iv = Base64.getDecoder().decode(packet.getIv());
            Cipher cipher = Cipher.getInstance("AES/GCM/NoPadding");
            SecretKeySpec key = new SecretKeySpec(config.getSecretKeyBytes(), "AES");
            cipher.init(

View on GitHub (pinned to cf67b549a7)