{"record":{"id":"105ac7f57042d694","repo":"apache/seatunnel","slug":"sha-256-is-not-supported-by-this-jvm","errorCode":null,"errorMessage":"SHA-256 is not supported by this JVM","messagePattern":"SHA-256 is not supported by this JVM","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-file/connector-file-base/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/source/reader/BinaryReadStrategy.java","lineNumber":188,"sourceCode":"     * Returns a fixed SeaTunnelRowType used to store file fragments.\n     *\n     * <p>`data`: Holds the binary data of the file fragment. When the data is empty, it indicates\n     * the end of the file.\n     *\n     * <p>`relativePath`: Represents the sub-path of the file.\n     *\n     * <p>`partIndex`: Indicates the order of the file fragment.\n     */\n    @Override\n    public SeaTunnelRowType getSeaTunnelRowTypeInfo(String path) throws FileConnectorException {\n        return binaryRowType;\n    }\n\n    private static MessageDigest createSha256Digest() throws IOException {\n        try {\n            return MessageDigest.getInstance(\"SHA-256\");\n        } catch (NoSuchAlgorithmException e) {\n            throw new IOException(\"SHA-256 is not supported by this JVM\", e);\n        }\n    }\n\n    private static String sha256Hex(byte[] bytes) {\n        char[] digits = \"0123456789abcdef\".toCharArray();\n        char[] encoded = new char[bytes.length * 2];\n        for (int i = 0; i < bytes.length; i++) {\n            int current = bytes[i] & 0xff;\n            encoded[i * 2] = digits[current >>> 4];\n            encoded[i * 2 + 1] = digits[current & 0x0f];\n        }\n        return new String(encoded);\n    }\n\n    private static final class DigestTrackingInputStream extends FilterInputStream {\n        private final MessageDigest digest;\n\n        private DigestTrackingInputStream(InputStream in, MessageDigest digest) {","sourceCodeStart":170,"sourceCodeEnd":206,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-file/connector-file-base/src/main/java/org/apache/seatunnel/connectors/seatunnel/file/source/reader/BinaryReadStrategy.java#L170-L206","documentation":"BinaryReadStrategy.createSha256Digest requests a SHA-256 MessageDigest from the JVM. SHA-256 is mandatory in every modern JDK, so an NoSuchAlgorithmException here means a broken/restricted JCA provider configuration. It is rethrown as an IOException that propagates as a read failure while hashing binary content.","triggerScenarios":"Calling digest/sha256Hex on binary data when MessageDigest.getInstance(\"SHA-256\") fails — e.g. running on a stripped JRE, an unusual runtime (certain embedded/Android-like environments), or a security policy removing the provider.","commonSituations":"Running SeaTunnel on a minimal/custom JRE without the standard SUN providers; java.security file modified to deregister providers; FIPS-only setups without a SHA-256-capable provider installed.","solutions":["Run on a standard JDK (8/11/17) where SHA-256 is always available.","Inspect java.security and JCA provider list; re-add the SUN provider or install a FIPS provider supporting SHA-256.","Check the 'Caused by' NoSuchAlgorithmException and the JVM's Security.getProviders() output."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Java, runtime pre-check\nif (java.security.Security.getAlgorithms(\"MessageDigest\").stream()\n        .noneMatch(a -> a.equalsIgnoreCase(\"SHA-256\"))) {\n    throw new IllegalStateException(\"JVM does not support SHA-256\");\n}","typeGuard":null,"tryCatchPattern":"try {\n    String hash = sha256Hex(data);\n} catch (IOException e) {\n    if (e.getMessage().contains(\"SHA-256\")) {\n        throw new IllegalStateException(\"Broken JCA provider config: no SHA-256\", e);\n    }\n    throw e;\n}","preventionTips":["Use a standard JDK distribution (Temurin, Oracle, etc.).","Do not strip providers from java.security in restricted environments.","Smoke-test MessageDigest.getInstance(\"SHA-256\") on target runtime images."],"tags":["jvm","crypto","hashing"],"backgroundTag":"unsupported-platform","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}