siyuan-note/siyuan · error
Encrypted notebooks already exist but the master key backup…
Error message
Encrypted notebooks already exist but the master key backup is missing. Restore the original conf.json or backup file to re-enable
What it means
Error "Encrypted notebooks already exist but the master key backup is missing. Restore the original conf.json or backup file to re-enable" thrown in siyuan-note/siyuan.
Solutions
- Restore the original conf.json or the notebook crypto backup file into the workspace data directory, then retry enabling with the original master password.
- The backup file lives in the data directory; recover it from a system backup, another synced device, or a snapshot.
- If the key material is unrecoverable, delete the orphaned encrypted notebooks/history and enable encryption fresh (existing encrypted data will be lost).
Example fix
Restore the original conf.json or the notebook crypto backup file from before the feature was disabled, then re-enable; without the backup the existing encrypted notebooks cannot be unlocked.
When it happens
Trigger: Thrown at kernel/model/crypto.go:1009 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of siyuan-note/siyuan@afa823b6b4 (2026-08-18).
Data as JSON: /api/errors/3dcdb5f31a6bde53.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/crypto.go:1009
if listErr != nil {
return fmt.Errorf("list encrypted notebooks failed: %w", listErr)
}
hasHistory, historyErr := scanEncryptedNotebookHistory()
if historyErr != nil {
return fmt.Errorf("check encrypted notebook history failed: %w", historyErr)
}
hasBackup := filelock.IsExist(dataCryptoBackupPath())
if hasEncrypted || hasHistory || hasBackup {
// 现存笔记本、已删除笔记本历史或全局备份均表示已有密钥域,必须恢复并认证,不能生成新 MasterSalt。
kek, restoreErr := tryRestoreNotebookCryptoFromBackupLocked(password)
if kek != nil {
zeroAndClear(kek)
}
if restoreErr != nil {
if strings.Contains(restoreErr.Error(), Conf.Language(311)) {
return errors.New(Conf.Language(311))
}
return errors.New(Conf.Language(315))
}
logging.LogInfof("encrypted notebook re-enabled with authenticated recovery key material")
return nil
}
// 不存在任何密钥依赖或备份时生成新的 MasterSalt。
salt, err := util.GenerateSalt()
if err != nil {
return err
}
Conf.m.RLock()
kdfParams := Conf.NotebookCrypto.KDFParams
Conf.m.RUnlock()
params, validErr := util.ValidateArgon2Params(kdfParams)
if validErr != nil {
return validErr
}
kek := util.DeriveKey(password, salt, params)View on GitHub (pinned to afa823b6b4)