apache/seatunnel · error · IOException

SHA-256 is not supported by this JVM

Error message

SHA-256 is not supported by this JVM

What it means

BinaryReadStrategy.createSha256Digest requests a SHA-256 MessageDigest from the JVM. SHA-256 is mandatory in every modern JDK, so an NoSuchAlgorithmException here means a broken/restricted JCA provider configuration. It is rethrown as an IOException that propagates as a read failure while hashing binary content.

Solutions

  1. Run on a standard JDK (8/11/17) where SHA-256 is always available.
  2. Inspect java.security and JCA provider list; re-add the SUN provider or install a FIPS provider supporting SHA-256.
  3. Check the 'Caused by' NoSuchAlgorithmException and the JVM's Security.getProviders() output.
Defensive patterns

Strategy: try-catch

Validate before calling

// Java, runtime pre-check
if (java.security.Security.getAlgorithms("MessageDigest").stream()
        .noneMatch(a -> a.equalsIgnoreCase("SHA-256"))) {
    throw new IllegalStateException("JVM does not support SHA-256");
}

Try / catch

try {
    String hash = sha256Hex(data);
} catch (IOException e) {
    if (e.getMessage().contains("SHA-256")) {
        throw new IllegalStateException("Broken JCA provider config: no SHA-256", e);
    }
    throw e;
}

Prevention

When it happens

Trigger: Calling digest/sha256Hex on binary data when MessageDigest.getInstance("SHA-256") fails — e.g. running on a stripped JRE, an unusual runtime (certain embedded/Android-like environments), or a security policy removing the provider.

Common situations: Running SeaTunnel on a minimal/custom JRE without the standard SUN providers; java.security file modified to deregister providers; FIPS-only setups without a SHA-256-capable provider installed.

Understand the failure class

Background: "unsupported platform" / "not supported on this platform" errors: what they mean and how to fix them — this error's family across 47 libraries.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/105ac7f57042d694. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-file/connector-file-base/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/source/reader/BinaryReadStrategy.java:188

     * Returns a fixed SeaTunnelRowType used to store file fragments.
     *
     * <p>`data`: Holds the binary data of the file fragment. When the data is empty, it indicates
     * the end of the file.
     *
     * <p>`relativePath`: Represents the sub-path of the file.
     *
     * <p>`partIndex`: Indicates the order of the file fragment.
     */
    @Override
    public SeaTunnelRowType getSeaTunnelRowTypeInfo(String path) throws FileConnectorException {
        return binaryRowType;
    }

    private static MessageDigest createSha256Digest() throws IOException {
        try {
            return MessageDigest.getInstance("SHA-256");
        } catch (NoSuchAlgorithmException e) {
            throw new IOException("SHA-256 is not supported by this JVM", e);
        }
    }

    private static String sha256Hex(byte[] bytes) {
        char[] digits = "0123456789abcdef".toCharArray();
        char[] encoded = new char[bytes.length * 2];
        for (int i = 0; i < bytes.length; i++) {
            int current = bytes[i] & 0xff;
            encoded[i * 2] = digits[current >>> 4];
            encoded[i * 2 + 1] = digits[current & 0x0f];
        }
        return new String(encoded);
    }

    private static final class DigestTrackingInputStream extends FilterInputStream {
        private final MessageDigest digest;

        private DigestTrackingInputStream(InputStream in, MessageDigest digest) {

View on GitHub (pinned to cf67b549a7)