{"record":{"id":"fc9115e0894674cc","repo":"apache/iceberg","slug":"full-metadata-integrity-check-skipped-because-no-m","errorCode":null,"errorMessage":"Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}. Falling back to encryption property based check.","messagePattern":"Full metadata integrity check skipped because no metadata hash was recorded in HMS for table (.+?)\\. Falling back to encryption property based check\\.","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"hive-metastore/src/main/java/org/apache/iceberg/hive/HiveTableOperations.java","lineNumber":582,"sourceCode":"\n    if (tableKeyId != null && encryptionDekLength <= 0) {\n      encryptionDekLength =\n          PropertyUtil.propertyAsInt(\n              tableProperties,\n              TableProperties.ENCRYPTION_DEK_LENGTH,\n              TableProperties.ENCRYPTION_DEK_LENGTH_DEFAULT);\n    }\n  }\n\n  private void checkIntegrityForEncryption(\n      String encryptionKeyIdFromHMS, String dekLengthFromHMS, String metadataHashFromHMS) {\n    TableMetadata metadata = current();\n    if (StringUtils.isNotEmpty(metadataHashFromHMS)) {\n      HMSTablePropertyHelper.verifyMetadataHash(metadata, metadataHashFromHMS);\n      return;\n    }\n\n    LOG.warn(\n        \"Full metadata integrity check skipped because no metadata hash was recorded in HMS for table {}.\"\n            + \" Falling back to encryption property based check.\",\n        tableName);\n\n    Map<String, String> propertiesFromMetadata = metadata.properties();\n\n    String encryptionKeyIdFromMetadata =\n        propertiesFromMetadata.get(TableProperties.ENCRYPTION_TABLE_KEY);\n    if (!Objects.equals(encryptionKeyIdFromHMS, encryptionKeyIdFromMetadata)) {\n      String errMsg =\n          String.format(\n              \"Metadata file might have been modified. Encryption key id %s differs from HMS value %s\",\n              encryptionKeyIdFromMetadata, encryptionKeyIdFromHMS);\n      throw new RuntimeException(errMsg);\n    }\n\n    String dekLengthFromMetadata =\n        propertiesFromMetadata.get(TableProperties.ENCRYPTION_DEK_LENGTH);","sourceCodeStart":564,"sourceCodeEnd":600,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/hive-metastore/src/main/java/org/apache/iceberg/hive/HiveTableOperations.java#L564-L600","documentation":"HiveTableOperations.checkIntegrityForEncryption (invoked from doRefresh) verifies table metadata integrity against a metadata hash stored in HMS table properties. When no hash was recorded, a full integrity check is impossible, so the code logs this warning and falls back to a weaker encryption-property-based check.","triggerScenarios":"Refreshing a table whose HMS properties lack the metadata hash property — tables created before the hash feature existed, tables written by clients that don't record the hash, or hash manually removed from table properties.","commonSituations":"Upgrading older Iceberg tables to encryption-aware versions; mixed client versions writing to the same table; someone manually altering HMS table parameters.","solutions":["Refresh/rewrite table metadata once with a client that records the metadata hash property into HMS","Confirm the expected metadata-hash table property is present via describe formatted <table> in Hive","If the weaker property-based check is acceptable, no action needed — it is a warning only","Avoid manually editing HMS table parameters; use Iceberg APIs to update properties"],"exampleFix":"// before\nTable table = catalog.loadTable(id); // warns: no hash recorded\n// after\nTable table = catalog.loadTable(id);\ntable.updateProperties().set(\"write.metadata.hash.enabled\", \"true\").commit(); // client records hash going forward","handlingStrategy":"fallback","validationCode":"Map<String,String> props = ((HiveTable) table).properties(); // verify metadata hash property present before relying on integrity checks","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Migrate legacy tables with a client version that records the metadata hash","Avoid manually editing HMS table parameters","Monitor for this warning to detect mixed client versions writing to the table"],"tags":["hive","encryption","integrity","metadata"],"backgroundTag":"missing-config-value","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}