siyuan-note/siyuan · error

encrypted resources are not supported

Error message

encrypted resources are not supported

What it means

Encrypted notebooks (protected by SiYuan's data encryption) are explicitly excluded from asset relinking. If the first path segment of the asset's workspace-relative location matches a notebook ID that is an encrypted box, the operation refuses to proceed rather than risk corrupting or bypassing the encryption envelope semantics.

Solutions

  1. Exclude encrypted notebooks from the mapping list and relink only assets under non-encrypted notebooks
  2. Move the asset and its references out of the encrypted notebook into a normal notebook first, then relink
  3. Disable/convert encryption on that notebook only if your recovery plan permits it, then retry

Example fix

// before
mappings := allNotebookAssetMappings() // includes encrypted boxes
// after
var filtered []apicontract.AssetRelinkMapping
for _, m := range mappings {
	box := firstPathSegment(m.OldPath)
	if ast.IsNodeIDPattern(box) && model.IsEncryptedBox(box) {
		continue // skip encrypted notebooks
	}
	filtered = append(filtered, m)
}
Defensive patterns

Strategy: validation

Validate before calling

func mappingTargetsEncryptedBox(oldPath string) bool {
	first := firstSegment(filepath.ToSlash(oldPath))
	return ast.IsNodeIDPattern(first) && model.IsEncryptedBox(first)
}

Type guard

if mappingTargetsEncryptedBox(m.OldPath) { skip(m) }

Prevention

When it happens

Trigger: Running RelinkAssetWithContext/RelinkAssets or a scan where the oldPath (or scanned reference) resolves under a data/<notebookID>/ directory whose ID satisfies ast.IsNodeIDPattern && IsEncryptedBox(first).

Common situations: Batch relinking assets across all notebooks when some notebooks use encrypted-notebook mode; automation scripts iterating every notebook folder under data/; migrating content from an encrypted notebook into a normal one while relinking asset paths.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/e9cb797da9e71f1a. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/asset_relink.go:497

	return "", errors.New("cannot allocate a replacement history directory")
}

func validateRelinkStoragePath(abs string) error {
	real, err := filepath.EvalSymlinks(abs)
	if err != nil {
		return err
	}
	dataRoot, err := filepath.EvalSymlinks(util.DataDir)
	if err != nil || !gulu.File.IsSubPath(dataRoot, real) {
		return fmt.Errorf("resource escapes the data directory: %s", abs)
	}
	rel, err := filepath.Rel(dataRoot, real)
	if err != nil {
		return err
	}
	first, _, _ := strings.Cut(filepath.ToSlash(rel), "/")
	if ast.IsNodeIDPattern(first) && IsEncryptedBox(first) {
		return errors.New("encrypted resources are not supported")
	}
	return nil
}

View on GitHub (pinned to 9f775e8a12)