{"record":{"id":"dcfa6b449fc2c6d2","repo":"siyuan-note/siyuan","slug":"unsupported-encrypted-notebook-key-envelope","errorCode":null,"errorMessage":"unsupported encrypted notebook key envelope","messagePattern":"unsupported encrypted notebook key envelope","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/crypto.go","lineNumber":1637,"sourceCode":"\t\tWrapNonce:  mustEncryptionNonce(wrapped),\n\t\tCreatedAt:  time.Now().UnixMilli(),\n\t}, dek, nil\n}\n\nfunc wrappedDEKAAD(boxID string) []byte {\n\treturn []byte(\"siyuan:wrapped-dek:\" + boxID)\n}\n\nfunc decryptWrappedDEK(boxID string, enc *conf.BoxEncryption, kek []byte) ([]byte, error) {\n\tif err := validateWrappedDEKEnvelope(enc); err != nil {\n\t\treturn nil, err\n\t}\n\treturn util.DecryptWithAAD(kek, enc.WrappedDEK, wrappedDEKAAD(boxID))\n}\n\nfunc validateWrappedDEKEnvelope(enc *conf.BoxEncryption) error {\n\tif enc == nil || enc.Spec != boxEncryptionSpec {\n\t\treturn errors.New(\"unsupported encrypted notebook key envelope\")\n\t}\n\tif enc.CreatedAt <= 0 {\n\t\treturn errors.New(\"encrypted notebook key envelope creation time is missing\")\n\t}\n\tnonce, err := util.EncryptionNonce(enc.WrappedDEK)\n\tif err != nil {\n\t\treturn fmt.Errorf(\"invalid encrypted notebook key envelope: %w\", err)\n\t}\n\tif !bytes.Equal(nonce, enc.WrapNonce) {\n\t\treturn errors.New(\"encrypted notebook key envelope nonce mismatch\")\n\t}\n\treturn nil\n}\n\nfunc validateBoxEncryption(enc *conf.BoxEncryption) error {\n\tif err := validateWrappedDEKEnvelope(enc); err != nil {\n\t\treturn err\n\t}","sourceCodeStart":1619,"sourceCodeEnd":1655,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/crypto.go#L1619-L1655","documentation":"This error means the notebook's stored key envelope (conf.BoxEncryption.Spec) does not match the encryption spec version this build of SiYuan expects (boxEncryptionSpec). The KEK->DEK wrapping step refuses to unwrap a DEK whose envelope format is unknown, protecting against decrypting with a wrong/incompatible scheme. It is thrown from validateWrappedDEKEnvelope during notebook unlock/decryption setup.","triggerScenarios":"Calling unlock/decrypt paths (e.g. MountEncryptedBox / decrypt operations that wrap/unwrap DEKs) when enc is nil or enc.Spec differs from the current boxEncryptionSpec constant — e.g. data written by a newer build with a different spec, a downgraded kernel, or a corrupted/partially written conf.","commonSituations":"Restoring an old workspace backup produced by a different envelope spec; upgrading the kernel and then downgrading; a notebook whose .si/config or box conf lost the encryption metadata; manual edits to the box config.","solutions":["Check enc.Spec (conf.BoxEncryption) and compare with boxEncryptionSpec in kernel/model/crypto.go; identify which build wrote the data","Upgrade (or restore) to the kernel version that wrote the notebook so the spec matches","Restore the notebook conf from a known-good backup; do not hand-edit Spec","If data is unrecoverable via the envelope, use documented recovery material; never bypass authentication or fall back to plaintext"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"func isUnlockableBox(enc *conf.BoxEncryption) bool { return enc != nil && enc.Spec == boxEncryptionSpec }","typeGuard":"if enc == nil || enc.Spec != boxEncryptionSpec { return fmt.Errorf(\"box envelope spec %q unsupported; upgrade the kernel\", specString(enc)) }","tryCatchPattern":"if err := unlockBox(boxID); err != nil { if strings.Contains(err.Error(), \"unsupported encrypted notebook key envelope\") { /* surface upgrade/backup-recovery guidance */ } }","preventionTips":["Pin the kernel version that matches the envelope spec that wrote your notebooks","Never hand-edit BoxEncryption fields in the conf","Keep conf backups before upgrading or migrating workspaces","Check enc.Spec before calling decryption APIs in custom tooling"],"tags":["encryption","notebook","key-envelope","compatibility"],"backgroundTag":"unsupported-config-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}