siyuan-note/siyuan · error

encrypted assets are not supported

Error message

encrypted assets are not supported

What it means

The relink engine does not support encrypted assets. After path resolution and escape checks, resolveRelinkAsset calls IsEncryptedAssetPath(real) on the resolved path and rejects it if the asset is in an encrypted-asset envelope. Encryption of assets is out of scope for reference relinking.

Solutions

  1. Relink only ordinary (non-encrypted) assets; manage encrypted assets through the encrypted-notebook workflows instead.
  2. Exclude encrypted asset files (detect with IsEncryptedAssetPath) from bulk relink mappings before calling the API.
  3. If the asset must be renamed, decrypt or re-create it through the supported app flow, then relink the plain copy if applicable.
  4. Run dryRun=true to identify which mapping is encrypted before the real operation.

Example fix

// before
for _, m := range mappings {
    RelinkAsset(m.OldPath, m.NewPath, false) // may hit encrypted asset
}
// after
for _, m := range mappings {
    if model.IsEncryptedAssetPath(m.OldPath) {
        continue
    }
    RelinkAsset(m.OldPath, m.NewPath, false)
}
Defensive patterns

Strategy: validation

Validate before calling

if model.IsEncryptedAssetPath(realPath) {
    return errors.New("skip encrypted asset")
}

Type guard

func isRelinkableAsset(p string) bool {
    return !model.IsEncryptedAssetPath(p)
}

Try / catch

if err != nil && err.Error() == "encrypted assets are not supported" {
    // route the asset to the encrypted-notebook workflow instead
}

Prevention

When it happens

Trigger: Relinking an asset whose resolved real path is recognized by IsEncryptedAssetPath — i.e. the file is stored in the encrypted-asset format; triggered via RelinkAsset/FindAssetReferences mappings from scanMetadata; also referenced by the related query/fragment rejection in newAssetRelinker.

Common situations: Users of encrypted notebooks attempting to rename encrypted assets through the relink API; automated scripts iterating an assets directory that includes encrypted-envelope files; confusing ordinary assets with encrypted ones after enabling encryption features.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/b925e81c3ecc1832. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/asset_relink.go:266

		if err != nil {
			return "", err
		}
		if !info.Mode().IsRegular() {
			return "", fmt.Errorf("asset must be a regular file: %s", assetPath)
		}
		real, err := filepath.EvalSymlinks(candidate)
		if err != nil {
			return "", err
		}
		realRoot, err := filepath.EvalSymlinks(root)
		if err != nil || !gulu.File.IsSubPath(realRoot, real) {
			return "", fmt.Errorf("asset escapes its directory: %s", assetPath)
		}
		if err = validateRelinkStoragePath(real); err != nil {
			return "", err
		}
		if IsEncryptedAssetPath(real) {
			return "", errors.New("encrypted assets are not supported")
		}
		if found != "" && found != candidate {
			return "", fmt.Errorf("ambiguous asset path: %s", assetPath)
		}
		found = candidate
	}
	if required && found == "" {
		return "", fmt.Errorf("target asset does not exist locally: %s", assetPath)
	}
	return found, nil
}

func (p *assetRelinkPlan) scanViews() error {
	dir := filepath.Join(util.DataDir, "storage", "av")
	if err := p.observe(dir); err != nil {
		return err
	}
	entries, err := os.ReadDir(dir)

View on GitHub (pinned to 9f775e8a12)