siyuan-note/siyuan · error
CLI does not support files in encrypted notebooks
Error message
CLI does not support files in encrypted notebooks
What it means
For commands under the `file` subcommand, the CLI checks positional arguments against isEncryptedNotebookWorkspacePath, which resolves a path (relative paths against the workspace) into data/<boxID>/... and tests whether that box ID is an encrypted notebook. If any positional argument lies inside an encrypted notebook directory, the command aborts.
Solutions
- Remove or replace arguments that point inside the encrypted notebook directory.
- Perform the file operation in the SiYuan app, which supports encrypted notebooks natively.
- Temporarily relocate the encrypted notebook (app-supported) or exclude its box directory from your script's path list.
Example fix
// before SiYuan-Kernel file get "data/20240101120000-enc1/foo.sy" // after: use a path in a normal notebook SiYuan-Kernel file get "data/20240101120000-plain/foo.sy"
Defensive patterns
Strategy: validation
Validate before calling
// Go: ensure a data path's top-level box directory is not an encrypted notebook
box := strings.SplitN(relToData, string(filepath.Separator), 2)[0]
if isEncryptedBox(box) { return skip } Try / catch
if err := runKernelCLI(args); err != nil && strings.Contains(err.Error(), "files in encrypted notebooks") {
// exclude that path from the argument list and retry
} Prevention
- Enumerate only non-encrypted box directories when generating file arguments.
- Never feed raw data/ listings to file subcommands without filtering by notebook.
- Audit paths after any notebook is converted to an encrypted notebook.
When it happens
Trigger: Running any `SiYuan-Kernel file ...` subcommand with a positional argument that resolves to a path under data/<encrypted-box-id>/ — e.g. passing data/20240101120000-enc1/foo.sy as an argument.
Common situations: Scripting file operations over data/ contents without excluding encrypted notebook directories; reusing old scripts written before notebooks were encrypted; tab-completed paths that include encrypted notebook folders.
Understand the failure class
Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.
Related errors
- CLI does not support encrypted notebook history
- CLI does not support encrypted notebook
- path belongs to encrypted notebook
- 26
- Access to encrypted notebook data is not supported via this…
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/8d2826460811c2d8.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/cli/cmd/root.go:176
if flag == nil {
continue
}
values := []string{flag.Value.String()}
if flag.Value.Type() == "stringArray" {
values, _ = cmd.Flags().GetStringArray(flagName)
}
for _, value := range values {
for id := range strings.SplitSeq(value, ",") {
if checkID(strings.TrimSpace(id)) {
return fmt.Errorf("CLI does not support encrypted notebook [%s]", encryptedTarget)
}
}
}
}
if cmd.Parent() == fileCmd {
if slices.ContainsFunc(args, isEncryptedNotebookWorkspacePath) {
return fmt.Errorf("CLI does not support files in encrypted notebooks")
}
if pathFlag := cmd.Flags().Lookup("path"); pathFlag != nil && pathFlag.Value.String() != "" && isEncryptedNotebookWorkspacePath(pathFlag.Value.String()) {
return fmt.Errorf("CLI does not support files in encrypted notebooks")
}
}
if cmd.Parent() == assetCmd {
if pathFlag := cmd.Flags().Lookup("path"); pathFlag != nil && pathFlag.Value.String() != "" {
assetPath := pathFlag.Value.String()
if !filepath.IsAbs(assetPath) {
assetPath = filepath.Join("data", assetPath)
}
if isEncryptedNotebookWorkspacePath(assetPath) {
return fmt.Errorf("CLI does not support files in encrypted notebooks")
}
}
}
if cmd == historyGetCmd || cmd == historyRollbackCmd {
historyPath, _ := cmd.Flags().GetString("path")View on GitHub (pinned to 9f775e8a12)