siyuan-note/siyuan · error
encrypted asset metadata is too large
Error message
encrypted asset metadata is too large
What it means
EncryptAsset builds an encrypted asset container whose metadata (original name, size, chunk count, container ID) is encrypted as one AAD-bound blob and length-prefixed with a uint32. The kernel throws this error when the encrypted metadata exceeds encryptedAssetMetadataMaxSize (1 MiB), which would make the length prefix and parsing invariants unsatisfiable.
Solutions
- Reduce the metadata content (shorter original name, no extra fields) below the 1 MiB encrypted-size cap
- Check len(plaintext metadata) before calling EncryptAsset and reject inputs that could exceed encryptedAssetMetadataMaxSize after encryption overhead (~16-byte tag + nonce)
- If larger metadata is genuinely needed, bump the format limit in a versioned container-format change, not ad hoc
Example fix
// before
enc, err := model.EncryptAsset(boxID, diskName, originalName, data)
// after
if len(originalName) > 255 { return errors.New("original name too long") }
enc, err := model.EncryptAsset(boxID, diskName, originalName, data) Defensive patterns
Strategy: validation
Validate before calling
if len(metadataJSON) > 1<<20-64 {
return errors.New("asset metadata would exceed the 1 MiB encrypted limit")
}
enc, err := model.EncryptAsset(boxID, diskName, name, data) Try / catch
enc, err := model.EncryptAsset(boxID, diskName, name, data)
if err != nil && strings.Contains(err.Error(), "metadata is too large") {
return shrinkMetadataAndRetry(name, data)
} Prevention
- Keep asset original names short (e.g. cap at 255 bytes) before encryption
- Never append custom fields to the encrypted metadata struct without checking the size budget
- Remember ciphertext adds nonce+tag overhead (~28+ bytes) to plaintext size
When it happens
Trigger: Calling model.EncryptAsset with a metadata payload whose ciphertext is larger than 1 MiB — practically only via abnormally huge original-name or metadata fields, since the struct is small; tampered/oversized metadata input to the encryption helper.
Common situations: Uploading an asset whose recorded metadata was extended or crafted to exceed the limit; future format extensions inflating metadata; pathological file names from a modified client.
Understand the failure class
Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.
Related errors
- accessing assets in encrypted notebook
- Conf.Language(316) + " [box=" + id + "]"
- decrypt box [ ] failed: incorrect key or corrupted data
- encrypted attribute view snapshot has no matching notebook
- encrypted attribute view snapshot is missing notebook…
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/d712f8d0b66cf5fb.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/crypto.go:2268
metadata, err := json.Marshal(&encryptedAssetMetadata{
Spec: encryptedAssetSpec,
ContainerID: containerID,
OriginalName: originalName,
Size: int64(len(plaintext)),
Chunks: chunkCount,
})
if err != nil {
return nil, err
}
assetKey := util.DeriveSubKey(dek, "siyuan/asset")
defer zeroAndClear(assetKey)
aadPrefix := "siyuan:asset:" + boxID + ":assets/" + diskName
encryptedMetadata, err := util.EncryptWithAAD(assetKey, metadata, []byte(aadPrefix+":metadata"))
if err != nil {
return nil, err
}
if len(encryptedMetadata) > encryptedAssetMetadataMaxSize {
return nil, errors.New("encrypted asset metadata is too large")
}
ret := bytes.NewBuffer(make([]byte, 0, len(plaintext)+len(encryptedMetadata)+int(chunkCount)*64+12))
ret.Write(encryptedAssetMagic)
if err = binary.Write(ret, binary.BigEndian, uint32(len(encryptedMetadata))); err != nil {
return nil, err
}
ret.Write(encryptedMetadata)
for chunkIndex := uint64(0); chunkIndex < chunkCount; chunkIndex++ {
start := int(chunkIndex) * encryptedAssetChunkSize
end := start + encryptedAssetChunkSize
if end > len(plaintext) {
end = len(plaintext)
}
encryptedChunk, encryptErr := util.EncryptWithAAD(
assetKey,
plaintext[start:end],
encryptedAssetChunkAAD(aadPrefix, containerID, chunkIndex),
)View on GitHub (pinned to 9f775e8a12)