siyuan-note/siyuan · warning
path contains invalid character
Error message
path contains invalid character [%s]
What it means
`validateExclusionPath` rejects a path destined for a Windows Defender exclusion because it contains a character that is a cmd.exe or PowerShell metacharacter (`&|<>^%!"'$` + backtick). This prevents command injection when the path is passed to an elevated shell command.
Solutions
- Move/rename the SiYuan install directory or workspace so the path contains no shell metacharacters (letters, digits, spaces, hyphens, underscores only).
- Identify the offending character from the error message and rename just that path segment.
- Add the Defender exclusion manually via Windows Security settings instead of the in-app flow.
- Keep installs under simple paths like C:\SiYuan or %LOCALAPPDATA%\SiYuan to avoid recurrence.
Example fix
// before // workspace at C:\tools&apps\SiYuan -> error: path contains invalid character [&] // after // move workspace to C:\toolsapps\SiYuan (or add exclusion manually in Windows Security)
Defensive patterns
Strategy: validation
Validate before calling
// Go: pre-check a candidate install/workspace path for shell metacharacters
func safePath(p string) bool {
return !strings.ContainsAny(p, "&|<>^%!\"'$`")
} Prevention
- Install SiYuan and place workspaces in paths without shell metacharacters.
- Avoid folder names containing &, %, $, quotes, or carets on Windows.
- If a path cannot be renamed, add the Defender exclusion via Windows Security UI.
When it happens
Trigger: Calling AddMicrosoftDefenderExclusion when either the install path (filepath.Dir(util.WorkingDir)) or the user-configured workspace path contains one of the rejected characters.
Common situations: Users installing SiYuan into directories like `C:\apps&tools\` or under paths with `%VAR%`, `$`, quotes, or carets; unusual but legal Windows folder names.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- invalid history source path
- invalid skill path
- resource escapes the data directory
- access to private/internal IP is prohibited
- access to sensitive workspace file is forbidden
AI-assisted analysis of siyuan-note/siyuan@8641553a1f (2026-09-11).
Data as JSON: /api/errors/9106e77d78272f22.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/model/elevator_windows.go:136
util.PushMsg(Conf.language(252), 0)
}
func isUsingMicrosoftDefender() bool {
if !gulu.OS.IsWindows() {
return false
}
cmd := exec.Command("powershell", "-Command", "Get-MpPreference")
gulu.CmdAttr(cmd)
return cmd.Run() == nil
}
// validateExclusionPath 校验用于添加到 Windows Defender 排除项的路径,
// 拒绝包含 cmd.exe 或 PowerShell 元字符的路径,防止通过未转义的路径字符串实现命令注入
func validateExclusionPath(path string) error {
for _, c := range path {
if strings.ContainsRune("&|<>^%!\"'$`", c) {
return fmt.Errorf("path contains invalid character [%s]", string(c))
}
}
return nil
}
func getElevatorBin() string {
elevator := filepath.Join(util.WorkingDir, "kernel", "elevator.exe")
if "dev" == util.Mode || !gulu.File.IsExist(elevator) {
elevator = filepath.Join(util.WorkingDir, "elevator", "elevator-"+runtime.GOARCH+".exe")
}
return elevator
}
View on GitHub (pinned to 8641553a1f)