apache/seatunnel · error · IOException
SHA-256 is not supported by this JVM
Error message
SHA-256 is not supported by this JVM
What it means
BinaryReadStrategy.createSha256Digest requests a SHA-256 MessageDigest from the JVM. SHA-256 is mandatory in every modern JDK, so an NoSuchAlgorithmException here means a broken/restricted JCA provider configuration. It is rethrown as an IOException that propagates as a read failure while hashing binary content.
Solutions
- Run on a standard JDK (8/11/17) where SHA-256 is always available.
- Inspect java.security and JCA provider list; re-add the SUN provider or install a FIPS provider supporting SHA-256.
- Check the 'Caused by' NoSuchAlgorithmException and the JVM's Security.getProviders() output.
Defensive patterns
Strategy: try-catch
Validate before calling
// Java, runtime pre-check
if (java.security.Security.getAlgorithms("MessageDigest").stream()
.noneMatch(a -> a.equalsIgnoreCase("SHA-256"))) {
throw new IllegalStateException("JVM does not support SHA-256");
} Try / catch
try {
String hash = sha256Hex(data);
} catch (IOException e) {
if (e.getMessage().contains("SHA-256")) {
throw new IllegalStateException("Broken JCA provider config: no SHA-256", e);
}
throw e;
} Prevention
- Use a standard JDK distribution (Temurin, Oracle, etc.).
- Do not strip providers from java.security in restricted environments.
- Smoke-test MessageDigest.getInstance("SHA-256") on target runtime images.
When it happens
Trigger: Calling digest/sha256Hex on binary data when MessageDigest.getInstance("SHA-256") fails — e.g. running on a stripped JRE, an unusual runtime (certain embedded/Android-like environments), or a security policy removing the provider.
Common situations: Running SeaTunnel on a minimal/custom JRE without the standard SUN providers; java.security file modified to deregister providers; FIPS-only setups without a SHA-256-capable provider installed.
Understand the failure class
Background: "unsupported platform" / "not supported on this platform" errors: what they mean and how to fix them — this error's family across 47 libraries.
Related errors
- bucketCount must be greater than zero, but was
- DECRYPT_FAILED
- GET /overview slow: costMs=
- GET /running-jobs slow diagnostics: full=
- Invalid Deep Lake workspace
AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10).
Data as JSON: /api/errors/105ac7f57042d694.
Report an issue: GitHub.
Appendix: source
Thrown at seatunnel-connectors-v2/connector-file/connector-file-base/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/source/reader/BinaryReadStrategy.java:188
* Returns a fixed SeaTunnelRowType used to store file fragments.
*
* <p>`data`: Holds the binary data of the file fragment. When the data is empty, it indicates
* the end of the file.
*
* <p>`relativePath`: Represents the sub-path of the file.
*
* <p>`partIndex`: Indicates the order of the file fragment.
*/
@Override
public SeaTunnelRowType getSeaTunnelRowTypeInfo(String path) throws FileConnectorException {
return binaryRowType;
}
private static MessageDigest createSha256Digest() throws IOException {
try {
return MessageDigest.getInstance("SHA-256");
} catch (NoSuchAlgorithmException e) {
throw new IOException("SHA-256 is not supported by this JVM", e);
}
}
private static String sha256Hex(byte[] bytes) {
char[] digits = "0123456789abcdef".toCharArray();
char[] encoded = new char[bytes.length * 2];
for (int i = 0; i < bytes.length; i++) {
int current = bytes[i] & 0xff;
encoded[i * 2] = digits[current >>> 4];
encoded[i * 2 + 1] = digits[current & 0x0f];
}
return new String(encoded);
}
private static final class DigestTrackingInputStream extends FilterInputStream {
private final MessageDigest digest;
private DigestTrackingInputStream(InputStream in, MessageDigest digest) {View on GitHub (pinned to cf67b549a7)