{"record":{"id":"88115a740ddfb9c9","repo":"apache/seatunnel","slug":"decrypt-failed","errorCode":"DECRYPT_FAILED","errorMessage":"Decryption failed for batchId={}, check secret_key configuration","messagePattern":"Decryption failed for batchId=(.+?), check secret_key configuration","errorType":"console","errorClass":"EdgeSocketConnectorException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceReader.java","lineNumber":203,"sourceCode":"                if (offerResult == QueueOfferResult.ACCEPTED) {\n                    sourceState.markRecordReceived(batchId);\n                    return EdgeSocketResponseCode.RECEIVED.getCode();\n                }\n            }\n            queueFullCount++;\n            if (queueFullCount == 1 || queueFullCount % 100 == 0) {\n                log.warn(\n                        \"Ingress queue physically full, returning RETRY \"\n                                + \"(capacity={}, rejectCount={}, batchId={})\",\n                        config.getLocalQueueCapacity(),\n                        queueFullCount,\n                        batchId);\n            }\n            return EdgeSocketResponseCode.RETRY.getCode();\n        } catch (EdgeSocketConnectorException connectorException) {\n            if (isDecryptionError(connectorException)) {\n                log.warn(\n                        \"Decryption failed for batchId={}, check secret_key configuration\",\n                        batchId,\n                        connectorException);\n                return EdgeSocketResponseCode.DECRYPT_FAILED.getCode();\n            }\n            log.warn(\"Decode ingress packet failed for batchId={}\", batchId, connectorException);\n            return EdgeSocketResponseCode.DECODE_FAILED.getCode();\n        } catch (Exception decodeException) {\n            log.warn(\"Decode or enqueue ingress packet failed\", decodeException);\n            return EdgeSocketResponseCode.DECODE_FAILED.getCode();\n        }\n    }\n\n    @Override\n    public String handleCommitRequest(long batchId) {\n        synchronized (stateLock) {\n            return sourceState.resolveCommitResponse(batchId);\n        }\n    }","sourceCodeStart":185,"sourceCodeEnd":221,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/source/EdgeSocketSourceReader.java#L185-L221","documentation":"WARN log in handleBatchRecord's EdgeSocketConnectorException branch when isDecryptionError() matched, meaning the batch payload could not be decrypted — almost always a secret_key mismatch between the edge sender and the connector. The batch is rejected with the DECRYPT_FAILED response code rather than failing the task, since it is a per-batch data error.","triggerScenarios":"handleBatchRecord -> decode path throws EdgeSocketConnectorException classified as a decryption error (wrong/rotated AES key, corrupted ciphertext, key not configured while payload is encrypted).","commonSituations":"secret_key changed on the connector but edge devices still use the old key (or vice versa); different devices provisioned with different keys; payload encrypted with a different algorithm/IV scheme than the connector expects; secret_key whitespace/encoding differences between config and device.","solutions":["Verify secret_key in the EdgeSocket source config exactly matches the key used by the sending device (byte-for-byte, no stray whitespace)","Roll out coordinated key rotation: update devices and connector together, or support overlap of old/new keys temporarily","Confirm the device encryption algorithm/mode matches what the connector's decryptor implements","Test with an unencrypted batch (device encryption disabled) to isolate whether decryption or encoding is at fault","Inspect the logged connectorException stack trace for the precise crypto error (bad key size vs bad padding)"],"exampleFix":"# before: mismatched key\nsecret_key = \"st-old-shared-key\"\n# after: key matching the edge device's current key\nsecret_key = \"st-current-shared-key-2024\"","handlingStrategy":"validation","validationCode":"// sender-side sanity: key configured and non-empty, same length as receiver key\nif (secretKey == null || secretKey.isEmpty()) throw new IllegalStateException(\"secret_key not set\");\nif (secretKey.length() != expectedKeyLength) throw new IllegalStateException(\"key size mismatch\");","typeGuard":null,"tryCatchPattern":"// sender: treat DECRYPT_FAILED as fatal config error, stop retrying with same key\nif (\"DECRYPT_FAILED\".equals(responseCode)) {\n    log.error(\"Receiver rejected key; verify secret_key parity before resending\");\n    throw new ConfigurationException(\"secret_key mismatch with connector\");\n}","preventionTips":["Keep device and connector keys in one source of truth / secret store","Test decryption with a canary batch after any key rotation","Avoid trailing whitespace/encoding drift in key config values"],"tags":["decryption","secret-key","crypto","socket-source"],"backgroundTag":"invalid-config-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}