{"record":{"id":"9ffd4e881c045d8f","repo":"siyuan-note/siyuan","slug":"decryption-failed-incorrect-key-or-corrupted-data","errorCode":null,"errorMessage":"Decryption failed: incorrect key or corrupted data","messagePattern":"Decryption failed: incorrect key or corrupted data","errorType":"http","errorClass":null,"httpStatus":200,"severity":"error","filePath":"kernel/model/crypto.go","lineNumber":1188,"sourceCode":"func deriveNotebookCryptoBackupCandidate(password string) (backup *conf.NotebookCrypto, kek []byte, err error) {\n\tbackup, err = loadNotebookCryptoBackup()\n\tif err != nil || backup == nil || len(backup.MasterSalt) == 0 || len(backup.KEKVerifier) == 0 {\n\t\treturn nil, nil, errors.New(Conf.Language(310))\n\t}\n\tparams, validErr := util.ValidateArgon2Params(backup.KDFParams)\n\tif validErr != nil {\n\t\treturn nil, nil, errors.New(Conf.Language(317))\n\t}\n\tkek = util.DeriveKey(password, backup.MasterSalt, params)\n\tdecrypted, decryptErr := util.DecryptWithAAD(kek, backup.KEKVerifier, []byte(\"siyuan:kek-verifier\"))\n\tif decryptErr != nil || string(decrypted) != string(kekVerifierMagic) {\n\t\tzeroAndClear(kek)\n\t\treturn nil, nil, errors.New(Conf.Language(311))\n\t}\n\tif backup.Spec != conf.CurrentNotebookCryptoSpec || backup.Checksum == \"\" ||\n\t\tlen(backup.KEKMAC) == 0 || !verifyKEKMAC(backup, kek) {\n\t\tzeroAndClear(kek)\n\t\treturn nil, nil, errors.New(Conf.Language(316))\n\t}\n\tif !verifyKEKAgainstExistingBoxes(kek) || !verifyKEKAgainstEncryptedHistory(kek) {\n\t\tzeroAndClear(kek)\n\t\treturn nil, nil, errors.New(Conf.Language(316))\n\t}\n\tbackup.KDFParams = params\n\treturn backup, kek, nil\n}\n\n// deriveKEK 从主密码派生 KEK 并校验。校验失败返回错误。KEK 仅在函数作用域内有效，调用方负责使用。\nfunc deriveKEK(password string) ([]byte, error) {\n\tConf.m.RLock()\n\tnc := *Conf.NotebookCrypto\n\tConf.m.RUnlock()\n\n\tif !nc.Enabled {\n\t\t// 本机未启用：可能是数据同步到新设备后本机 conf.json 还没有加密配置。\n\t\t// 尝试从 DataDir 备份恢复（备份会随 DataDir 同步过来）；恢复成功时直接复用其派生的 KEK。","sourceCodeStart":1170,"sourceCodeEnd":1206,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/afa823b6b4e4f183511e0bc0a3be93caa94c7c97/kernel/model/crypto.go#L1170-L1206","documentation":"Error \"Decryption failed: incorrect key or corrupted data\" thrown in siyuan-note/siyuan.","triggerScenarios":"Thrown at kernel/model/crypto.go:1188 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Re-enter the master password; the KEK verifier decryption failed, which usually means the password is incorrect.","If the password is correct, the backup data is corrupted or was replaced; restore the original backup file and retry.","Check that the backup was not truncated by an interrupted sync; re-sync or restore from a known-good device."],"exampleFix":null,"handlingStrategy":null,"validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"afa823b6b4e4f183511e0bc0a3be93caa94c7c97","analyzedAt":"2026-08-18T17:04:10.865Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}