siyuan-note/siyuan · error

Incorrect master password

Error message

Incorrect master password

What it means

Error "Incorrect master password" thrown in siyuan-note/siyuan.

Solutions

  1. Enter the original master password that was used when the encrypted notebook feature was first enabled.
  2. If you forgot it, restore the data from a device or backup that still has the correct key material; the password cannot be recovered.

Example fix

Re-enter the master password carefully; the KEK verifier check failed, which means the password is wrong or the backup was replaced. Restore the original backup if the password is believed correct.

When it happens

Trigger: Thrown at kernel/model/crypto.go:1007 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of siyuan-note/siyuan@afa823b6b4 (2026-08-18). Data as JSON: /api/errors/c54163611167b141. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/crypto.go:1007

	hasEncrypted, listErr := hasEncryptedNotebook()
	if listErr != nil {
		return fmt.Errorf("list encrypted notebooks failed: %w", listErr)
	}
	hasHistory, historyErr := scanEncryptedNotebookHistory()
	if historyErr != nil {
		return fmt.Errorf("check encrypted notebook history failed: %w", historyErr)
	}
	hasBackup := filelock.IsExist(dataCryptoBackupPath())
	if hasEncrypted || hasHistory || hasBackup {
		// 现存笔记本、已删除笔记本历史或全局备份均表示已有密钥域,必须恢复并认证,不能生成新 MasterSalt。
		kek, restoreErr := tryRestoreNotebookCryptoFromBackupLocked(password)
		if kek != nil {
			zeroAndClear(kek)
		}
		if restoreErr != nil {
			if strings.Contains(restoreErr.Error(), Conf.Language(311)) {
				return errors.New(Conf.Language(311))
			}
			return errors.New(Conf.Language(315))
		}
		logging.LogInfof("encrypted notebook re-enabled with authenticated recovery key material")
		return nil
	}

	// 不存在任何密钥依赖或备份时生成新的 MasterSalt。
	salt, err := util.GenerateSalt()
	if err != nil {
		return err
	}
	Conf.m.RLock()
	kdfParams := Conf.NotebookCrypto.KDFParams
	Conf.m.RUnlock()
	params, validErr := util.ValidateArgon2Params(kdfParams)
	if validErr != nil {
		return validErr

View on GitHub (pinned to afa823b6b4)