{"record":{"id":"bb210c92ad3e58fe","repo":"jdx/mise","slug":"dotfiles-cannot-enroll-encrypted-paths-inside-an-active","errorCode":null,"errorMessage":"dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified","messagePattern":"dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/cli/dotfiles/track.rs","lineNumber":63,"sourceCode":"    /// Encrypt contents before saving them to history (requires `[history.encryption].recipients`)\n    #[usage(long)]\n    encrypt: bool,\n\n    /// Accept without prompting\n    #[usage(long, short)]\n    yes: bool,\n}\n\nimpl DotfilesTrack {\n    /// Write the requested declarations and capture their initial history baseline.\n    pub(crate) async fn run(self) -> Result<()> {\n        let _declarations = declaration_lock()?;\n        let config = Config::get().await?;\n        if self.encrypt && !Settings::get().history.enabled {\n            bail!(\"dotfiles: cannot enroll encrypted paths while history is disabled\");\n        }\n        if self.encrypt && inside_capture()? {\n            bail!(\n                \"dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified\"\n            );\n        }\n        let managed = crate::system::files::composed_files_from_config(&config)?;\n        let global = declaration_file(false)?;\n        let mut edits: BTreeMap<PathBuf, DeclarationEdit> = BTreeMap::new();\n        let mut locations = BTreeMap::new();\n        let mut declared: Vec<(String, PathBuf)> = vec![];\n        let mut manual = vec![];\n        for target_raw in &self.targets {\n            let target = crate::system::files::resolve_target_arg(target_raw)\n                .components()\n                .collect::<PathBuf>();\n            if target.is_relative() {\n                bail!(\"{target_raw}: target must be absolute or start with ~/\");\n            }\n            crate::system::history::tracked::ensure_portable_ancestors(&target)?;\n            let target_key = normalized_target(&target);","sourceCodeStart":45,"sourceCodeEnd":81,"githubUrl":"https://github.com/jdx/mise/blob/533346cc374382b41ec5ff70536252b2e96e725c/src/cli/dotfiles/track.rs#L45-L81","documentation":"mise's `dot track --encrypt` enrolls dotfile paths into managed tracking with encryption of the captured baseline. When the command runs inside an active history capture wrapper, the encrypted baseline cannot be verified against the capture, so the operation is refused up front. The user must run the encrypted enrollment as a separate, standalone invocation.","triggerScenarios":"Running `mise dot track --encrypt` (encrypt=true) while the process is detected by inside_capture() to be executing within a live history capture session (e.g. inside `mise history capture ...` or a capture-wrapped command).","commonSituations":"A user wraps an interactive shell or script in a history capture and then tries to enroll new encrypted dotfiles from within that session; or an automation script chains track --encrypt inside a capture-wrapped setup step.","solutions":["Exit the history capture session and run `mise dot track --encrypt <targets>` as a standalone command","Split the script so the encrypted enrollment happens before entering the capture wrapper","If only non-encrypted paths are needed inside the capture, drop the --encrypt flag"],"exampleFix":"// before (inside a capture wrapper)\nmise history capture -- mise dot track --encrypt ~/.ssh/config\n// after\nmise dot track --encrypt ~/.ssh/config\nmise history capture -- <command>","handlingStrategy":"validation","validationCode":"if [[ -n \"$MISE_HISTORY_CAPTURE\" ]]; then echo 'defer `mise dot track --encrypt` until after the capture ends'; exit 1; fi","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Never nest `dot track --encrypt` inside `mise history capture` or capture-wrapped shells","Keep encrypted enrollment as a discrete setup step","Automate enrollments in scripts that run outside capture sessions"],"tags":["dotfiles","history","encryption","invalid-state"],"backgroundTag":"invalid-state-transition","analyzedSha":"533346cc374382b41ec5ff70536252b2e96e725c","analyzedAt":"2026-09-17T13:35:38.149Z","contentChangedAt":"2026-09-17T13:35:38.149Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}