{"record":{"id":"0416f772db16fe06","repo":"apache/iceberg","slug":"failed-to-create-message-digest-needed-for-s3-chec","errorCode":null,"errorMessage":"Failed to create message digest needed for s3 checksum checks","messagePattern":"Failed to create message digest needed for s3 checksum checks","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"aws/src/main/java/org/apache/iceberg/aws/s3/S3OutputStream.java","lineNumber":143,"sourceCode":"    }\n\n    this.s3 = s3;\n    this.location = location;\n    this.s3FileIOProperties = s3FileIOProperties;\n    this.writeTags = s3FileIOProperties.writeTags();\n\n    this.createStack = Thread.currentThread().getStackTrace();\n\n    this.multiPartSize = s3FileIOProperties.multiPartSize();\n    this.multiPartThresholdSize =\n        (int) (multiPartSize * s3FileIOProperties.multipartThresholdFactor());\n    this.stagingDirectory = new File(s3FileIOProperties.stagingDirectory());\n    this.isChecksumEnabled = s3FileIOProperties.isChecksumEnabled();\n    try {\n      this.completeMessageDigest =\n          isChecksumEnabled ? MessageDigest.getInstance(DIGEST_ALGORITHM) : null;\n    } catch (NoSuchAlgorithmException e) {\n      throw new RuntimeException(\n          \"Failed to create message digest needed for s3 checksum checks\", e);\n    }\n\n    this.writeBytes = metrics.counter(FileIOMetricsContext.WRITE_BYTES, Unit.BYTES);\n    this.writeOperations = metrics.counter(FileIOMetricsContext.WRITE_OPERATIONS);\n\n    newStream();\n  }\n\n  @Override\n  public long getPos() {\n    return pos;\n  }\n\n  @Override\n  public void flush() throws IOException {\n    stream.flush();\n  }","sourceCodeStart":125,"sourceCodeEnd":161,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/aws/src/main/java/org/apache/iceberg/aws/s3/S3OutputStream.java#L125-L161","documentation":"S3OutputStream's constructor eagerly creates a MessageDigest for full-object checksum verification when s3.checksum-enabled is true, and wraps NoSuchAlgorithmException in a RuntimeException. It means the configured digest algorithm is unavailable in the JVM.","triggerScenarios":"Setting s3.checksum-enabled=true in a JVM that lacks the DIGEST_ALGORITHM provider (rare, e.g. stripped JDK/security provider misconfiguration).","commonSituations":"See trigger scenarios.","solutions":["Restore the standard JCE security providers (check java.security config).","Use a full JDK instead of a stripped/minimal runtime image.","Disable s3.checksum-enabled if checksums are not required.","Inspect the NoSuchAlgorithmException cause to identify the missing algorithm name."],"exampleFix":"// before\nprops.put(\"s3.checksum-enabled\", \"true\"); // on minimal JRE\n// after\n// either use full JDK or disable checksums\nprops.put(\"s3.checksum-enabled\", \"false\");","handlingStrategy":"validation","validationCode":"// Java\ntry {\n  MessageDigest.getInstance(\"SHA-256\");\n} catch (NoSuchAlgorithmException e) {\n  throw new IllegalStateException(\"JVM lacks digest support; disable s3.checksum-enabled\", e);\n}","typeGuard":null,"tryCatchPattern":"// Java\ntry {\n  S3OutputStream s = new S3OutputStream(...);\n} catch (RuntimeException e) {\n  if (e.getMessage().contains(\"message digest\")) {\n    // fall back to checksum-disabled configuration\n  }\n}","preventionTips":["Run full JDK images; avoid stripped minimal runtimes for write-heavy jobs","Keep java.security provider configuration intact","Only enable s3.checksum-enabled when the runtime provably supports the digest"],"tags":["s3","checksum","crypto","jvm"],"backgroundTag":"module-init-failed","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}