{"record":{"id":"da601bb6887297ad","repo":"apache/iceberg","slug":"failed-to-create-gcm-cipher","errorCode":null,"errorMessage":"Failed to create GCM cipher","messagePattern":"Failed to create GCM cipher","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"core/src/main/java/org/apache/iceberg/encryption/Ciphers.java","lineNumber":202,"sourceCode":"      return plaintextLength;\n    }\n  }\n\n  private static SecretKeySpec newKey(byte[] keyBytes) {\n    Preconditions.checkArgument(keyBytes != null, \"Invalid key: null\");\n    int keyLength = keyBytes.length;\n    Preconditions.checkArgument(\n        (keyLength == 16 || keyLength == 24 || keyLength == 32),\n        \"Invalid key length: %s (must be 16, 24, or 32 bytes)\",\n        keyLength);\n    return new SecretKeySpec(keyBytes, \"AES\");\n  }\n\n  private static Cipher newCipher() {\n    try {\n      return Cipher.getInstance(\"AES/GCM/NoPadding\");\n    } catch (GeneralSecurityException e) {\n      throw new RuntimeException(\"Failed to create GCM cipher\", e);\n    }\n  }\n\n  static byte[] streamBlockAAD(byte[] fileAadPrefix, int currentBlockIndex) {\n    byte[] blockAAD =\n        ByteBuffer.allocate(4).order(ByteOrder.LITTLE_ENDIAN).putInt(currentBlockIndex).array();\n\n    if (null == fileAadPrefix) {\n      return blockAAD;\n    } else {\n      byte[] aad = new byte[fileAadPrefix.length + 4];\n      System.arraycopy(fileAadPrefix, 0, aad, 0, fileAadPrefix.length);\n      System.arraycopy(blockAAD, 0, aad, fileAadPrefix.length, 4);\n      return aad;\n    }\n  }\n}\n","sourceCodeStart":184,"sourceCodeEnd":220,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/core/src/main/java/org/apache/iceberg/encryption/Ciphers.java#L184-L220","documentation":"Ciphers.newCipher requests a Cipher instance for 'AES/GCM/NoPadding' and wraps any GeneralSecurityException (NoSuchAlgorithmException, NoSuchPaddingException) in a RuntimeException. This is a static failure of the JVM's crypto environment, not of user input.","triggerScenarios":"First use of any Ciphers encrypt/decrypt path on a JVM that has no provider implementing AES/GCM/NoPadding, or where provider initialization throws.","commonSituations":"Highly restricted/custom JVMs or exotic runtimes (some stripped-down embedded JREs) without AES-GCM; broken java.security configuration; a custom Provider list that removed the SunJCE.","solutions":["Run on a standard JDK 8+ where SunJCE provides AES/GCM/NoPadding","Inspect java.security configuration and registered security.providers","Re-add or fix the missing JCE provider; check the chained cause"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"static boolean gcmAvailable() {\n  try { javax.crypto.Cipher.getInstance(\"AES/GCM/NoPadding\"); return true; }\n  catch (GeneralSecurityException e) { return false; }\n}","typeGuard":null,"tryCatchPattern":"try {\n  useEncryption();\n} catch (RuntimeException e) {\n  if (\"Failed to create GCM cipher\".equals(e.getMessage())) {\n    throw new EnvironmentException(\"JVM lacks AES/GCM provider; check java.security and providers\", e);\n  }\n  throw e;\n}","preventionTips":["Smoke-test Cipher.getInstance(\"AES/GCM/NoPadding\") at startup when encryption is required","Don't strip SunJCE from java.security providers","Use a standard JDK distribution, not a minimal/stripped JRE"],"tags":["encryption","crypto","jvm","provider"],"backgroundTag":"module-init-failed","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}