apache/seatunnel · error · IOException

Unexpected auth response

Error message

Unexpected auth response: ${reply} (expected ACK or REJECTED)

What it means

handleAuthResponse expects the collector's auth reply to be exactly ACK or REJECTED (AUTH_FAILED handled separately). Any other line is thrown as this IOException with the raw reply, meaning the authentication channel returned a response outside the known protocol.

Solutions

  1. Inspect the reply text in the exception message to see what was actually received
  2. Confirm the target address/port is the EdgeSocket collector and no proxy intercepts the plain-text protocol
  3. Align agent and collector to the same SeaTunnel/protocol version
  4. If the collector sends extra banner lines, remove the banner or update the client to skip it
Defensive patterns

Strategy: try-catch

Try / catch

try { client.probeReachable(); } catch (IOException e) { if (e.getMessage().startsWith("Unexpected auth response:")) { log.error("Auth channel returned: {}", e.getMessage()); } throw e; }

Prevention

When it happens

Trigger: The first reply line after the AUTH line is not ACK, REJECTED, or AUTH_FAILED — e.g. a proxy/gateway banner, TLS plaintext error, wrong-port HTTP response, or protocol version mismatch.

Common situations: Connecting through a load balancer or proxy that injects a banner; pointing at a non-EdgeSocket service; collector crash mid-handshake emitting a stack trace line; version skew between agent and collector protocol.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/e70c9934d60c04a4. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java:101

        }
        throw new IOException(
                "Exceeded maxBatchSendAttempts="
                        + config.getMaxBatchSendAttempts()
                        + " without RECEIVED for batch "
                        + batchId);
    }

    private static void handleAuthResponse(String reply) throws IOException {
        if (EdgeSocketProtocol.RESP_REJECTED.equals(reply)) {
            throw new EdgeSocketCollectorRejectedException();
        }
        if (EdgeSocketProtocol.RESP_AUTH_FAILED.equals(reply)) {
            throw new EdgeSocketCollectorRejectedException(
                    "Edge socket authentication rejected (AUTH_FAILED): check output token matches"
                            + " EdgeSocket source secret_key");
        }
        if (!EdgeSocketProtocol.RESP_ACK.equals(reply)) {
            throw new IOException(
                    "Unexpected auth response: "
                            + reply
                            + " (expected "
                            + EdgeSocketProtocol.RESP_ACK
                            + " or "
                            + EdgeSocketProtocol.RESP_REJECTED
                            + ")");
        }
    }

    private static long parseQueueFullBackoffMs(String reply) {
        String suffix = reply.substring(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX.length());
        try {
            long ms = Long.parseLong(suffix.trim());
            return ms > 0 ? ms : EdgeSocketProtocol.DEFAULT_QUEUE_FULL_BACKOFF_MS;
        } catch (NumberFormatException ex) {
            return EdgeSocketProtocol.DEFAULT_QUEUE_FULL_BACKOFF_MS;
        }

View on GitHub (pinned to cf67b549a7)