{"record":{"id":"fd9818936d085a91","repo":"apache/seatunnel","slug":"packet-unsupported-encryption","errorCode":"PACKET_UNSUPPORTED_ENCRYPTION","errorMessage":"Unsupported packet encryption type: ","messagePattern":"Unsupported packet encryption type: ","errorType":"error_code","errorClass":"EdgeSocketConnectorException","httpStatus":null,"severity":"error","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/serialize/record/EdgeSocketPacketRecordDeserializer.java","lineNumber":93,"sourceCode":"    }\n\n    /**\n     * Decode payload encryption according to packet metadata.\n     *\n     * @param payloadBytes base64-decoded payload bytes from packet\n     * @param packet ingress packet metadata\n     * @param encryptionType resolved encryption type\n     * @return decrypted payload bytes (or original bytes when encryption is NONE)\n     */\n    private byte[] decodeEncryption(\n            byte[] payloadBytes,\n            EdgeSocketIngressPacket packet,\n            EdgeSocketEncryptionType encryptionType) {\n        if (encryptionType == EdgeSocketEncryptionType.NONE) {\n            return payloadBytes;\n        }\n        if (encryptionType != EdgeSocketEncryptionType.AES_GCM) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_UNSUPPORTED_ENCRYPTION,\n                    \"Unsupported packet encryption type: \" + encryptionType);\n        }\n        if (config.getSecretKeyBytes() == null || config.getSecretKeyBytes().length == 0) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_AES_KEY_MISSING,\n                    \"Missing secret_key when packet encryption is AES_GCM\");\n        }\n        if (packet.getIv() == null || packet.getIv().isEmpty()) {\n            throw new EdgeSocketConnectorException(\n                    EdgeSocketConnectorErrorCode.PACKET_DECODE_ERROR,\n                    \"Missing iv in AES_GCM packet\");\n        }\n        try {\n            byte[] iv = Base64.getDecoder().decode(packet.getIv());\n            Cipher cipher = Cipher.getInstance(\"AES/GCM/NoPadding\");\n            SecretKeySpec key = new SecretKeySpec(config.getSecretKeyBytes(), \"AES\");\n            cipher.init(","sourceCodeStart":75,"sourceCodeEnd":111,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/serialize/record/EdgeSocketPacketRecordDeserializer.java#L75-L111","documentation":"In EdgeSocketPacketRecordDeserializer.decodeEncryption(), only NONE and AES_GCM encryption types are supported. If the packet declares any other encryption type, the method throws EdgeSocketConnectorException with code PACKET_UNSUPPORTED_ENCRYPTION and message 'Unsupported packet encryption type: ' + the type.","triggerScenarios":"decodeEncryption() (via decryptedPayload) receives a packet whose encryption field resolves to a non-NONE, non-AES_GCM value — e.g. a packet from a newer producer build supporting an additional cipher.","commonSituations":"Version skew between producer and consumer, packets from a third-party emitter using a different cipher scheme, or a corrupted encryption header value.","solutions":["Set the producer's encryption to 'none' or 'aes_gcm' to match this consumer.","Upgrade the consumer connector to a build that supports the packet's encryption type.","Check for packet corruption or a sender emitting a wrong encryption field."],"exampleFix":"// before (producer)\nencryption = \"chacha20\"\n// after (producer)\nencryption = \"aes_gcm\"","handlingStrategy":"try-catch","validationCode":"if (encryptionType != EdgeSocketEncryptionType.NONE && encryptionType != EdgeSocketEncryptionType.AES_GCM) {\n    throw new IllegalArgumentException(\"Only NONE and AES_GCM are supported, got \" + encryptionType);\n}","typeGuard":null,"tryCatchPattern":"try {\n    byte[] payload = decryptedPayload(payloadBytes, packet, encryptionType);\n} catch (EdgeSocketConnectorException e) {\n    if (e.getErrorCode() == EdgeSocketConnectorErrorCode.PACKET_UNSUPPORTED_ENCRYPTION) {\n        // reconfigure producer to aes_gcm or upgrade consumer\n    }\n}","preventionTips":["Standardize on aes_gcm (or none) across all emitters.","Upgrade consumer and producer together when adding ciphers.","Reject unknown encryption types at the ingress gateway."],"tags":["encryption","deserialization","connector-edge-socket"],"backgroundTag":"unsupported-enum-value","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}