{"record":{"id":"b4cfe3a62f9be5c6","repo":"jdx/mise","slug":"dotfiles-cannot-enroll-encrypted-paths-while-history-is","errorCode":null,"errorMessage":"dotfiles: cannot enroll encrypted paths while history is disabled","messagePattern":"dotfiles: cannot enroll encrypted paths while history is disabled","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/cli/dotfiles/track.rs","lineNumber":60,"sourceCode":"    #[usage(long)]\n    no_autosave: bool,\n\n    /// Encrypt contents before saving them to history (requires `[history.encryption].recipients`)\n    #[usage(long)]\n    encrypt: bool,\n\n    /// Accept without prompting\n    #[usage(long, short)]\n    yes: bool,\n}\n\nimpl DotfilesTrack {\n    /// Write the requested declarations and capture their initial history baseline.\n    pub(crate) async fn run(self) -> Result<()> {\n        let _declarations = declaration_lock()?;\n        let config = Config::get().await?;\n        if self.encrypt && !Settings::get().history.enabled {\n            bail!(\"dotfiles: cannot enroll encrypted paths while history is disabled\");\n        }\n        if self.encrypt && inside_capture()? {\n            bail!(\n                \"dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified\"\n            );\n        }\n        let managed = crate::system::files::composed_files_from_config(&config)?;\n        let global = declaration_file(false)?;\n        let mut edits: BTreeMap<PathBuf, DeclarationEdit> = BTreeMap::new();\n        let mut locations = BTreeMap::new();\n        let mut declared: Vec<(String, PathBuf)> = vec![];\n        let mut manual = vec![];\n        for target_raw in &self.targets {\n            let target = crate::system::files::resolve_target_arg(target_raw)\n                .components()\n                .collect::<PathBuf>();\n            if target.is_relative() {\n                bail!(\"{target_raw}: target must be absolute or start with ~/\");","sourceCodeStart":42,"sourceCodeEnd":78,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/cli/dotfiles/track.rs#L42-L78","documentation":"Enrolling a path with `mise dot track --encrypt` requires the history subsystem, because encrypted enrollment must capture and verify an initial baseline checkpoint. If history.enabled is false, encrypted tracking is refused outright.","triggerScenarios":"Running `mise dot track --encrypt` while `history.enabled = false` in mise settings.","commonSituations":"Users with dotfile history disabled trying to adopt encrypted tracking; CI or hardened configs where history is off; misunderstanding that --encrypt works independently of history.","solutions":["Enable history first: `mise settings set history.enabled true`, then run `mise dot track --encrypt`","Track without --encrypt if you do not need encrypted enrollment and history stays disabled"],"exampleFix":"// before\nmise dot track --encrypt ~/.ssh/config  // history disabled\n// after\nmise settings set history.enabled true\nmise dot track --encrypt ~/.ssh/config","handlingStrategy":"validation","validationCode":"enabled=$(mise settings get history.enabled)\n[ \"$enabled\" = \"true\" ] || { echo 'dot track --encrypt requires history.enabled = true'; exit 1; }","typeGuard":null,"tryCatchPattern":"mise dot track --encrypt \"$p\" || {\n  mise settings set history.enabled true\n  mise dot track --encrypt \"$p\"\n}","preventionTips":["Enable history before using --encrypt enrollment","Keep encrypted enrollment out of scripted runs when history is off","Verify settings after applying shared/hardened configs"],"tags":["cli","config","dotfiles","encryption","history-disabled"],"backgroundTag":"feature-not-enabled","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}