{"record":{"id":"921dc7b35dbd8835","repo":"siyuan-note/siyuan","slug":"invalid-encrypted-notebook-key-envelope-w","errorCode":null,"errorMessage":"invalid encrypted notebook key envelope: %w","messagePattern":"invalid encrypted notebook key envelope: %w","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/crypto.go","lineNumber":1644,"sourceCode":"}\n\nfunc decryptWrappedDEK(boxID string, enc *conf.BoxEncryption, kek []byte) ([]byte, error) {\n\tif err := validateWrappedDEKEnvelope(enc); err != nil {\n\t\treturn nil, err\n\t}\n\treturn util.DecryptWithAAD(kek, enc.WrappedDEK, wrappedDEKAAD(boxID))\n}\n\nfunc validateWrappedDEKEnvelope(enc *conf.BoxEncryption) error {\n\tif enc == nil || enc.Spec != boxEncryptionSpec {\n\t\treturn errors.New(\"unsupported encrypted notebook key envelope\")\n\t}\n\tif enc.CreatedAt <= 0 {\n\t\treturn errors.New(\"encrypted notebook key envelope creation time is missing\")\n\t}\n\tnonce, err := util.EncryptionNonce(enc.WrappedDEK)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"invalid encrypted notebook key envelope: %w\", err)\n\t}\n\tif !bytes.Equal(nonce, enc.WrapNonce) {\n\t\treturn errors.New(\"encrypted notebook key envelope nonce mismatch\")\n\t}\n\treturn nil\n}\n\nfunc validateBoxEncryption(enc *conf.BoxEncryption) error {\n\tif err := validateWrappedDEKEnvelope(enc); err != nil {\n\t\treturn err\n\t}\n\tif _, err := util.EncryptionNonce(enc.Metadata); err != nil {\n\t\treturn fmt.Errorf(\"invalid encrypted notebook metadata envelope: %w\", err)\n\t}\n\treturn nil\n}\n\n// mustEncryptionNonce 从刚刚成功生成的密文中提取 nonce。生成密文格式错误属于内部不变量被破坏，直接终止执行。","sourceCodeStart":1626,"sourceCodeEnd":1662,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/crypto.go#L1626-L1662","documentation":"The WrappedDEK ciphertext could not be parsed by util.EncryptionNonce — i.e. the wrapped-DEK blob is not in the expected encrypted format (nonce+payload). The underlying parse error is wrapped with this prefix for context. This indicates the stored envelope payload is malformed, not merely stale.","triggerScenarios":"Enc.BoxEncryption.WrappedDEK is empty, truncated, base64/corrupted, or written by an incompatible format; util.EncryptionNonce returns an error during validateWrappedDEKEnvelope.","commonSituations":"Incomplete file write (power loss/sync conflict) of notebook conf; copying only part of the envelope between workspaces; data corrupted by editing the config as plain text.","solutions":["Read the wrapped %w cause to determine whether the payload was empty or badly framed","Restore BoxEncryption.WrappedDEK from a backup of the notebook conf","If a sync conflict produced partial files, resolve in favor of the kernel-written conf","Never regenerate MasterSalt or hand-craft WrappedDEK; recovery must go through documented key-recovery material"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"if _, err := util.EncryptionNonce(enc.WrappedDEK); err != nil { return fmt.Errorf(\"wrapped DEK malformed, restore backup: %w\", err) }","typeGuard":null,"tryCatchPattern":"if err := unlockBox(boxID); err != nil { var cause string; if strings.Contains(err.Error(), \"invalid encrypted notebook key envelope\") { cause = errors.Unwrap(err).Error() /* inspect and restore */ } }","preventionTips":["Avoid interrupting writes to notebook conf (sync conflicts, power loss)","Restore full conf files from backups instead of reassembling fields","Never hand-craft WrappedDEK values; use documented recovery material only"],"tags":["encryption","corruption","key-envelope","format"],"backgroundTag":"schema-validation-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}