{"record":{"id":"cb9a1c255b1f2ec8","repo":"siyuan-note/siyuan","slug":"invalid-encrypted-notebook-metadata-envelope-w","errorCode":null,"errorMessage":"invalid encrypted notebook metadata envelope: %w","messagePattern":"invalid encrypted notebook metadata envelope: %w","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/crypto.go","lineNumber":1657,"sourceCode":"\tif enc.CreatedAt <= 0 {\n\t\treturn errors.New(\"encrypted notebook key envelope creation time is missing\")\n\t}\n\tnonce, err := util.EncryptionNonce(enc.WrappedDEK)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"invalid encrypted notebook key envelope: %w\", err)\n\t}\n\tif !bytes.Equal(nonce, enc.WrapNonce) {\n\t\treturn errors.New(\"encrypted notebook key envelope nonce mismatch\")\n\t}\n\treturn nil\n}\n\nfunc validateBoxEncryption(enc *conf.BoxEncryption) error {\n\tif err := validateWrappedDEKEnvelope(enc); err != nil {\n\t\treturn err\n\t}\n\tif _, err := util.EncryptionNonce(enc.Metadata); err != nil {\n\t\treturn fmt.Errorf(\"invalid encrypted notebook metadata envelope: %w\", err)\n\t}\n\treturn nil\n}\n\n// mustEncryptionNonce 从刚刚成功生成的密文中提取 nonce。生成密文格式错误属于内部不变量被破坏，直接终止执行。\nfunc mustEncryptionNonce(ciphertext []byte) []byte {\n\tnonce, err := util.EncryptionNonce(ciphertext)\n\tif err != nil {\n\t\tpanic(\"extract encryption nonce failed: \" + err.Error())\n\t}\n\treturn nonce\n}\n\n// GetDEK 取已缓存的 DEK。返回副本，避免外部零化影响缓存。\n// filesys/assets/db 加解密时调用。\nfunc GetDEK(boxID string) ([]byte, error) {\n\tif !ast.IsNodeIDPattern(boxID) {\n\t\treturn nil, errors.New(\"invalid notebook ID\")","sourceCodeStart":1639,"sourceCodeEnd":1675,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/crypto.go#L1639-L1675","documentation":"The notebook's metadata ciphertext (conf.BoxEncryption.Metadata) could not be parsed as a valid encrypted envelope by util.EncryptionNonce, so its nonce could not be extracted. The DEK envelope itself validated, but the encrypted notebook metadata blob is malformed.","triggerScenarios":"validateBoxEncryption calls util.EncryptionNonce(enc.Metadata) after the wrapped-DEK checks pass; Metadata is empty, truncated, or in an unknown format.","commonSituations":"Partial/corrupted write of the box conf; a third-party tool rewrote the conf and mangled the metadata field; copying fields between notebooks incorrectly.","solutions":["Check the wrapped %w cause for specifics (empty vs malformed payload)","Restore the notebook conf (or the Metadata field) from a backup taken while the notebook worked","Re-sync the workspace from a replica that has an intact conf","Do not bypass authentication or fall back to plaintext; derived indexes may only be rebuilt after the source ciphertext authenticates"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"if _, err := util.EncryptionNonce(enc.Metadata); err != nil { return errors.New(\"metadata envelope malformed; restore conf backup\") }","typeGuard":null,"tryCatchPattern":"if err := openBox(boxID); err != nil { if strings.Contains(err.Error(), \"invalid encrypted notebook metadata envelope\") { /* restore Metadata/conf from backup; never fall back to plaintext */ } }","preventionTips":["Treat the box conf as a single atomic artifact when copying/restoring","Resolve sync conflicts in favor of the kernel-written conf","Validate envelope integrity after any third-party migration tooling"],"tags":["encryption","metadata","corruption"],"backgroundTag":"schema-validation-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}