siyuan-note/siyuan · error
imported notebook [ ] contains encrypted payload without…
Error message
imported notebook [%s] contains encrypted payload without identity
What it means
ImportData validates each notebook inside an imported data.zip before merging it. If a notebook's payload on disk is encrypted (hasEncryptedNotebookPayloadAtPath returns true) but no valid encryption identity (BoxEncryption salt/verifier config or crypto backup file) could be resolved for that notebook, the import is aborted. Without the identity the kernel cannot authenticate or decrypt the payload, so importing it would produce an unreadable notebook.
Solutions
- Re-export the data.zip from the original SiYuan workspace so the notebook's .siyuan/conf.json and crypto backup file are included
- Verify the archive contains the hidden .siyuan directory for each notebook and that conf.json has "encrypted": true plus a valid boxCrypt object
- If you intentionally do not want encryption, remove the encrypted payload (decrypt the notebook in the source workspace first) and re-export
- Import into the original workspace where the notebook identity is already configured, rather than a fresh workspace
Example fix
// before: zip built manually without .siyuan metadata
// data.zip
// notebook-20240102150405-xxx/*.sy (encrypted payload, no .siyuan/)
// after: export via SiYuan 'Export data.zip' so metadata ships
// data.zip
// notebook-20240102150405-xxx/*.sy
// notebook-20240102150405-xxx/.siyuan/conf.json (encrypted:true, boxCrypt:{...})
// notebook-20240102150405-xxx/.siyuan/<crypto backup file> Defensive patterns
Strategy: validation
Validate before calling
// Go: before calling ImportData, inspect the archive for encrypted notebooks missing identity
for _, boxID := range listNotebookDirsInZip(zipPath) {
hasPayload := zipContainsEncryptedPayload(zipPath, boxID) // .siyuan payload markers present
hasIdentity := zipContainsFile(zipPath, boxID+"/.siyuan/") && confHasBoxCrypt(zipPath, boxID)
if hasPayload && !hasIdentity {
return fmt.Errorf("archive notebook %s lacks encryption identity; re-export from source workspace", boxID)
}
} Prevention
- Always export data.zip via SiYuan's built-in export so .siyuan metadata is included
- Never strip hidden .siyuan directories when repacking archives
- Before importing into a fresh workspace, confirm encrypted notebooks ship their crypto backup files
- Document that encrypted notebooks cannot be migrated by manually copying payload files only
When it happens
Trigger: Calling ImportData (or the /api/import/importData endpoint) with a data.zip whose notebook directory contains encrypted .sy payloads, while the notebook's .siyuan/conf.json lacks boxConf.Encrypted/BoxCrypt and no notebook crypto backup file exists inside the archive.
Common situations: Hand-assembled or partially edited data.zip backups where the .siyuan metadata directory was stripped; archives produced by older tooling before the crypto backup file existed; users manually copying notebook data folders without the hidden .siyuan directory.
Related errors
- cannot replay block swap across encrypted notebook…
- cannot swap blocks across encrypted notebook boundaries
- CLI does not support encrypted notebook
- Conf.Language(0)
- Conf.Language(314)
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/d4a49597ab7981b6.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/import.go:1373
boxCrypt = boxConf.BoxCrypt
} else {
boxCrypt = backup
}
if boxCrypt == nil {
return nil, fmt.Errorf("encrypted notebook [%s] has no valid identity", boxID)
}
} else if boxConf != nil && backup != nil {
return nil, fmt.Errorf("notebook [%s] has conflicting normal and encrypted identities", boxID)
} else if backup != nil {
boxCrypt = backup
}
payloadFound, payloadErr := hasEncryptedNotebookPayloadAtPath(boxDir)
if payloadErr != nil {
return nil, fmt.Errorf("inspect imported notebook [%s] failed: %w", boxID, payloadErr)
}
if boxCrypt == nil && payloadFound {
return nil, fmt.Errorf("imported notebook [%s] contains encrypted payload without identity", boxID)
}
if boxCrypt == nil {
continue
}
if err = validateBoxEncryption(boxCrypt); err != nil {
return nil, fmt.Errorf("invalid imported notebook identity [%s]: %w", boxID, err)
}
if filelock.IsExist(filepath.Join(util.DataDir, boxID)) && IsEncryptedBox(boxID) {
return nil, fmt.Errorf("refuse to overwrite existing encrypted notebook [%s]", boxID)
}
encryptedBoxIDs = append(encryptedBoxIDs, boxID)
}
return encryptedBoxIDs, nil
}
func ImportData(zipPath string) (err error) {
util.PushEndlessProgress(Conf.Language(73))View on GitHub (pinned to 9f775e8a12)