risingwavelabs/risingwave · error
User not found
Error message
User not found
What it means
The `iceberg_tables` system catalog table lists hosted Iceberg tables for the current session. After listing tables it resolves the authenticated user via `user_info_reader.get_user_by_name(auth_context.user_name)`; if the user recorded in the auth context cannot be found in the user catalog, it returns the generic `anyhow!("User not found")`.
Solutions
- Reconnect so the auth context is re-established with a currently existing user.
- Verify the user exists (`SELECT * FROM rw_users;`) and recreate it if it was dropped.
- Check frontend logs for user-info cache sync issues and restart the frontend node if the cache is stale.
Example fix
-- before (connected as dropped user) SELECT * FROM iceberg_tables; -- after CREATE USER report_reader WITH PASSWORD '...'; -- recreate, then reconnect as that user SELECT * FROM iceberg_tables;
Defensive patterns
Strategy: try-catch
Validate before calling
const users = await client.query("SELECT name FROM rw_users WHERE name = $1", [userName]);
if (users.rows.length === 0) throw new Error("user does not exist; reconnect as a valid user"); Type guard
function userExists(rows) { return Array.isArray(rows) && rows.length > 0; } Try / catch
try {
const res = await client.query("SELECT * FROM iceberg_tables");
} catch (e) {
if (String(e.message) === "User not found") {
// reconnect to refresh the auth context
} else throw e;
} Prevention
- Do not drop users with active long-lived connections, or reconnect afterwards
- After DROP USER, recycle connection pools that authenticated as that user
- Monitor frontend user-info cache consistency if using replicated frontends
When it happens
Trigger: Querying `rw_catalog.iceberg_tables` (e.g. `SELECT * FROM iceberg_tables`) while the session's `auth_context.user_name` no longer exists in the user info catalog — e.g. the user was dropped after the connection was established.
Common situations: Long-lived connections surviving a `DROP USER`; replication or auth-cache staleness where the frontend's user info snapshot lacks the user; querying system catalogs through a service account that was removed.
Understand the failure class
Background: "User not found", "Invalid user", and "does not exist": what missing-user lookup errors mean across Rocket.Chat, LiteLLM, Phabricator, rustfs, and pnpm — this error's family across 10 libraries.
Related errors
- adlsgen2.authority_host does not parse as a URL
- adlsgen2.authority_host must not contain a path component
- adlsgen2.authority_host must not contain a query or fragment
- adlsgen2.authority_host must not contain userinfo
- adlsgen2.authority_host must use the https scheme, got
AI-assisted analysis of risingwavelabs/risingwave@6469eb736d (2026-09-11).
Data as JSON: /api/errors/d41d0c67afa856d2.
Report an issue: GitHub.
Appendix: source
Thrown at src/frontend/src/catalog/system_catalog/rw_catalog/iceberg_tables.rs:48
#[primary_key(catalog_name, table_namespace, table_name)]
struct IcebergTables {
pub catalog_name: String,
pub table_namespace: String,
pub table_name: String,
pub metadata_location: Option<String>,
pub previous_metadata_location: Option<String>,
pub iceberg_type: Option<String>,
}
#[system_catalog(table, "rw_catalog.iceberg_tables")]
async fn read(reader: &SysCatalogReaderImpl) -> Result<Vec<IcebergTables>> {
let rows = reader.meta_client.list_hosted_iceberg_tables().await?;
let catalog_reader = reader.catalog_reader.read_guard();
let user_reader = reader.user_info_reader.read_guard();
let user = user_reader
.get_user_by_name(&reader.auth_context.user_name)
.ok_or_else(|| anyhow!("User not found"))?;
let mut res = Vec::new();
for row in rows {
let record = IcebergTables {
catalog_name: row.catalog_name,
table_namespace: row.table_namespace,
table_name: row.table_name,
metadata_location: row.metadata_location,
previous_metadata_location: row.previous_metadata_location,
iceberg_type: row.iceberg_type,
};
let table = catalog_reader
.get_created_table_by_name(
&record.catalog_name,
SchemaPath::Name(&record.table_namespace),
&record.table_name,
)?
.0;View on GitHub (pinned to 6469eb736d)