{"record":{"id":"d686a17458fe9303","repo":"apache/iceberg","slug":"failed-to-create-message-digest-needed-for-s3-chec-d686a1","errorCode":null,"errorMessage":"Failed to create message digest needed for s3 checksum checks.","messagePattern":"Failed to create message digest needed for s3 checksum checks\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"aws/src/main/java/org/apache/iceberg/aws/s3/S3OutputStream.java","lineNumber":224,"sourceCode":"    // switch to multipart upload\n    if (multipartUploadId == null && pos >= multiPartThresholdSize) {\n      initializeMultiPartUpload();\n      uploadParts();\n    }\n  }\n\n  private void newStream() throws IOException {\n    if (stream != null) {\n      stream.close();\n    }\n\n    createStagingDirectoryIfNotExists();\n    currentStagingFile = File.createTempFile(\"s3fileio-\", \".tmp\", stagingDirectory);\n    try {\n      currentPartMessageDigest =\n          isChecksumEnabled ? MessageDigest.getInstance(DIGEST_ALGORITHM) : null;\n    } catch (NoSuchAlgorithmException e) {\n      throw new RuntimeException(\n          \"Failed to create message digest needed for s3 checksum checks.\", e);\n    }\n\n    stagingFiles.add(new FileAndDigest(currentStagingFile, currentPartMessageDigest));\n    OutputStream outputStream = Files.newOutputStream(currentStagingFile.toPath());\n\n    if (isChecksumEnabled) {\n      DigestOutputStream digestOutputStream;\n\n      // if switched over to multipart threshold already, no need to update complete message digest\n      if (multipartUploadId != null) {\n        digestOutputStream =\n            new DigestOutputStream(\n                new BufferedOutputStream(outputStream), currentPartMessageDigest);\n      } else {\n        digestOutputStream =\n            new DigestOutputStream(\n                new DigestOutputStream(","sourceCodeStart":206,"sourceCodeEnd":242,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/aws/src/main/java/org/apache/iceberg/aws/s3/S3OutputStream.java#L206-L242","documentation":"newStream() creates a per-part MessageDigest for multipart checksum tracking and throws a RuntimeException if the digest algorithm cannot be instantiated. Same root cause as the constructor variant but raised lazily when a new multipart part stream is opened.","triggerScenarios":"Writing enough data to roll into a new multipart part while s3.checksum-enabled=true and the JVM cannot supply the digest algorithm.","commonSituations":"Same minimal/stripped JRE or broken security-provider environments as error 363; surfaces mid-write instead of at stream construction.","solutions":["Fix the JVM's security provider configuration so MessageDigest.getInstance succeeds.","Run on a standard full JDK.","Disable s3.checksum-enabled if digest support is unavailable.","Check for JVM-wide security policy restrictions on JCE algorithms."],"exampleFix":"// before\nprops.put(\"s3.checksum-enabled\", \"true\"); // fails at part rollover\n// after\nprops.put(\"s3.checksum-enabled\", \"false\");","handlingStrategy":"validation","validationCode":"// Java\ntry {\n  MessageDigest.getInstance(\"SHA-256\");\n} catch (NoSuchAlgorithmException e) {\n  props.setChecksumEnabled(false); // avoid mid-write failure at part rollover\n}","typeGuard":null,"tryCatchPattern":"// Java\ntry {\n  out.write(largeBuffer); // triggers newStream at part boundary\n} catch (RuntimeException e) {\n  LOG.error(\"Digest init failed mid-write: {}\", e.getCause());\n  throw e;\n}","preventionTips":["Validate digest availability at job startup, not lazily","Use standard JDK distributions on executor nodes","Avoid custom security policies that restrict JCE algorithms"],"tags":["s3","checksum","crypto","multipart"],"backgroundTag":"module-init-failed","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}