siyuan-note/siyuan · error

CLI does not support files in encrypted notebooks

Error message

CLI does not support files in encrypted notebooks

What it means

For commands under the `file` subcommand, the CLI checks positional arguments against isEncryptedNotebookWorkspacePath, which resolves a path (relative paths against the workspace) into data/<boxID>/... and tests whether that box ID is an encrypted notebook. If any positional argument lies inside an encrypted notebook directory, the command aborts.

Solutions

  1. Remove or replace arguments that point inside the encrypted notebook directory.
  2. Perform the file operation in the SiYuan app, which supports encrypted notebooks natively.
  3. Temporarily relocate the encrypted notebook (app-supported) or exclude its box directory from your script's path list.

Example fix

// before
SiYuan-Kernel file get "data/20240101120000-enc1/foo.sy"
// after: use a path in a normal notebook
SiYuan-Kernel file get "data/20240101120000-plain/foo.sy"
Defensive patterns

Strategy: validation

Validate before calling

// Go: ensure a data path's top-level box directory is not an encrypted notebook
box := strings.SplitN(relToData, string(filepath.Separator), 2)[0]
if isEncryptedBox(box) { return skip }

Try / catch

if err := runKernelCLI(args); err != nil && strings.Contains(err.Error(), "files in encrypted notebooks") {
    // exclude that path from the argument list and retry
}

Prevention

When it happens

Trigger: Running any `SiYuan-Kernel file ...` subcommand with a positional argument that resolves to a path under data/<encrypted-box-id>/ — e.g. passing data/20240101120000-enc1/foo.sy as an argument.

Common situations: Scripting file operations over data/ contents without excluding encrypted notebook directories; reusing old scripts written before notebooks were encrypted; tab-completed paths that include encrypted notebook folders.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/8d2826460811c2d8. Report an issue: GitHub.

Appendix: source

Thrown at kernel/cli/cmd/root.go:176

		if flag == nil {
			continue
		}
		values := []string{flag.Value.String()}
		if flag.Value.Type() == "stringArray" {
			values, _ = cmd.Flags().GetStringArray(flagName)
		}
		for _, value := range values {
			for id := range strings.SplitSeq(value, ",") {
				if checkID(strings.TrimSpace(id)) {
					return fmt.Errorf("CLI does not support encrypted notebook [%s]", encryptedTarget)
				}
			}
		}
	}

	if cmd.Parent() == fileCmd {
		if slices.ContainsFunc(args, isEncryptedNotebookWorkspacePath) {
			return fmt.Errorf("CLI does not support files in encrypted notebooks")
		}
		if pathFlag := cmd.Flags().Lookup("path"); pathFlag != nil && pathFlag.Value.String() != "" && isEncryptedNotebookWorkspacePath(pathFlag.Value.String()) {
			return fmt.Errorf("CLI does not support files in encrypted notebooks")
		}
	}
	if cmd.Parent() == assetCmd {
		if pathFlag := cmd.Flags().Lookup("path"); pathFlag != nil && pathFlag.Value.String() != "" {
			assetPath := pathFlag.Value.String()
			if !filepath.IsAbs(assetPath) {
				assetPath = filepath.Join("data", assetPath)
			}
			if isEncryptedNotebookWorkspacePath(assetPath) {
				return fmt.Errorf("CLI does not support files in encrypted notebooks")
			}
		}
	}
	if cmd == historyGetCmd || cmd == historyRollbackCmd {
		historyPath, _ := cmd.Flags().GetString("path")

View on GitHub (pinned to 9f775e8a12)