siyuan-note/siyuan · critical
encrypted document in ordinary notebook
Error message
encrypted document in ordinary notebook: %s
What it means
While scanning an ordinary (non-encrypted) notebook, the walker reads a .sy document and detects ciphertext via util.IsCiphertext(data). Encrypted documents are only valid inside encrypted notebooks, so the relink scan aborts rather than parsing data it cannot authenticate or correctly index.
Solutions
- Move the encrypted document back into its encrypted notebook (via the app's move feature, not manual file copies).
- Unlock/decrypt the document in the encrypted notebook using its key, then relocate the decrypted version if a plain copy is needed.
- Restore notebook metadata so the notebook is correctly recognized as encrypted if that is its true state.
- Do not attempt to hand-edit or strip the ciphertext — that breaks authentication and recovery guarantees.
Defensive patterns
Strategy: try-catch
Try / catch
_, err := model.RelinkAsset(old, new, dry)
if err != nil && strings.HasPrefix(err.Error(), "encrypted document in ordinary notebook") {
// move the document back to its encrypted notebook or decrypt via the app
} Prevention
- Move documents between notebooks only via the app, not the filesystem
- Do not toggle a notebook between encrypted and ordinary while documents remain encrypted
- Keep notebook metadata intact in backups
When it happens
Trigger: A .sy file inside a regular notebook contains encrypted content — typically because the document was moved/copied out of an encrypted notebook, the notebook was switched from encrypted to ordinary, or an encryption envelope was applied but the notebook is not registered as encrypted; the scan calls filelock.ReadFile then util.IsCiphertext and fails with the absolute path.
Common situations: Copying documents between an encrypted notebook and a normal notebook via the filesystem instead of the app; restoring a partial backup that mixed encrypted and plain documents; misconfigured workspace where notebook metadata marking encryption was lost.
Understand the failure class
Background: "is not a compatible type" / "cannot merge" errors: when a value's type doesn't match what the library requires — this error's family across 65 libraries.
Related errors
- encrypted assets are not supported
- 26
- Access to encrypted notebook data is not supported via this…
- accessing assets in encrypted notebook
- Argon2id KeyLength must be 32
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/11eb09e7f8661877.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/asset_relink.go:164
}
if strings.HasPrefix(entry.Name(), ".") || entry.Name() == "storage" {
return filepath.SkipDir
}
return nil
}
if !strings.HasSuffix(entry.Name(), ".sy") {
return nil
}
if err := p.observe(absPath); err != nil {
return err
}
p.reportProgress(absPath)
data, readErr := filelock.ReadFile(absPath)
if readErr != nil {
return readErr
}
if util.IsCiphertext(data) {
return fmt.Errorf("encrypted document in ordinary notebook: %s", absPath)
}
if readErr = treenode.CheckSpecJSON(data); readErr != nil {
return readErr
}
if !json.Valid(data) {
return fmt.Errorf("invalid document JSON: %s", absPath)
}
var header struct {
ID string `json:"ID"`
Properties struct {
Title string `json:"title"`
} `json:"Properties"`
}
if readErr = json.Unmarshal(data, &header); readErr != nil {
return readErr
}
titles[header.ID] = header.Properties.Title
if !p.mayContainReferences(data) && !bytes.Contains(data, []byte("NodeAttributeView")) {View on GitHub (pinned to 9f775e8a12)