{"record":{"id":"e70c9934d60c04a4","repo":"apache/seatunnel","slug":"unexpected-auth-response-reply-expected-ack-o","errorCode":null,"errorMessage":"Unexpected auth response: ${reply} (expected ACK or REJECTED)","messagePattern":"Unexpected auth response: (.+?) \\(expected ACK or REJECTED\\)","errorType":"exception","errorClass":"IOException","httpStatus":null,"severity":"error","filePath":"seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java","lineNumber":101,"sourceCode":"        }\n        throw new IOException(\n                \"Exceeded maxBatchSendAttempts=\"\n                        + config.getMaxBatchSendAttempts()\n                        + \" without RECEIVED for batch \"\n                        + batchId);\n    }\n\n    private static void handleAuthResponse(String reply) throws IOException {\n        if (EdgeSocketProtocol.RESP_REJECTED.equals(reply)) {\n            throw new EdgeSocketCollectorRejectedException();\n        }\n        if (EdgeSocketProtocol.RESP_AUTH_FAILED.equals(reply)) {\n            throw new EdgeSocketCollectorRejectedException(\n                    \"Edge socket authentication rejected (AUTH_FAILED): check output token matches\"\n                            + \" EdgeSocket source secret_key\");\n        }\n        if (!EdgeSocketProtocol.RESP_ACK.equals(reply)) {\n            throw new IOException(\n                    \"Unexpected auth response: \"\n                            + reply\n                            + \" (expected \"\n                            + EdgeSocketProtocol.RESP_ACK\n                            + \" or \"\n                            + EdgeSocketProtocol.RESP_REJECTED\n                            + \")\");\n        }\n    }\n\n    private static long parseQueueFullBackoffMs(String reply) {\n        String suffix = reply.substring(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX.length());\n        try {\n            long ms = Long.parseLong(suffix.trim());\n            return ms > 0 ? ms : EdgeSocketProtocol.DEFAULT_QUEUE_FULL_BACKOFF_MS;\n        } catch (NumberFormatException ex) {\n            return EdgeSocketProtocol.DEFAULT_QUEUE_FULL_BACKOFF_MS;\n        }","sourceCodeStart":83,"sourceCodeEnd":119,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java#L83-L119","documentation":"handleAuthResponse expects the collector's auth reply to be exactly ACK or REJECTED (AUTH_FAILED handled separately). Any other line is thrown as this IOException with the raw reply, meaning the authentication channel returned a response outside the known protocol.","triggerScenarios":"The first reply line after the AUTH line is not ACK, REJECTED, or AUTH_FAILED — e.g. a proxy/gateway banner, TLS plaintext error, wrong-port HTTP response, or protocol version mismatch.","commonSituations":"Connecting through a load balancer or proxy that injects a banner; pointing at a non-EdgeSocket service; collector crash mid-handshake emitting a stack trace line; version skew between agent and collector protocol.","solutions":["Inspect the reply text in the exception message to see what was actually received","Confirm the target address/port is the EdgeSocket collector and no proxy intercepts the plain-text protocol","Align agent and collector to the same SeaTunnel/protocol version","If the collector sends extra banner lines, remove the banner or update the client to skip it"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try { client.probeReachable(); } catch (IOException e) { if (e.getMessage().startsWith(\"Unexpected auth response:\")) { log.error(\"Auth channel returned: {}\", e.getMessage()); } throw e; }","preventionTips":["Connect directly to the collector, avoiding banner-injecting middleboxes","Keep protocol versions aligned between agent and collector","Probe reachability at startup to catch protocol skew early","Check for collector crash output corrupting the handshake reply"],"tags":["protocol","authentication","socket","unexpected-response"],"backgroundTag":"unexpected-response-shape","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}