jdx/mise · error

dotfiles: cannot enroll encrypted paths inside an active…

Error message

dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified

What it means

mise's `dot track --encrypt` enrolls dotfile paths into managed tracking with encryption of the captured baseline. When the command runs inside an active history capture wrapper, the encrypted baseline cannot be verified against the capture, so the operation is refused up front. The user must run the encrypted enrollment as a separate, standalone invocation.

Solutions

  1. Exit the history capture session and run `mise dot track --encrypt <targets>` as a standalone command
  2. Split the script so the encrypted enrollment happens before entering the capture wrapper
  3. If only non-encrypted paths are needed inside the capture, drop the --encrypt flag

Example fix

// before (inside a capture wrapper)
mise history capture -- mise dot track --encrypt ~/.ssh/config
// after
mise dot track --encrypt ~/.ssh/config
mise history capture -- <command>
Defensive patterns

Strategy: validation

Validate before calling

if [[ -n "$MISE_HISTORY_CAPTURE" ]]; then echo 'defer `mise dot track --encrypt` until after the capture ends'; exit 1; fi

Prevention

When it happens

Trigger: Running `mise dot track --encrypt` (encrypt=true) while the process is detected by inside_capture() to be executing within a live history capture session (e.g. inside `mise history capture ...` or a capture-wrapped command).

Common situations: A user wraps an interactive shell or script in a history capture and then tries to enroll new encrypted dotfiles from within that session; or an automation script chains track --encrypt inside a capture-wrapped setup step.

Understand the failure class

Background: "Invalid state transition" errors: "status must be X, actually Y", "already rejected/charging/uninstalled", "cannot ... while running" — what they mean when a library rejects your call — this error's family across 31 libraries.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/bb210c92ad3e58fe. Report an issue: GitHub.

Appendix: source

Thrown at src/cli/dotfiles/track.rs:63

    /// Encrypt contents before saving them to history (requires `[history.encryption].recipients`)
    #[usage(long)]
    encrypt: bool,

    /// Accept without prompting
    #[usage(long, short)]
    yes: bool,
}

impl DotfilesTrack {
    /// Write the requested declarations and capture their initial history baseline.
    pub(crate) async fn run(self) -> Result<()> {
        let _declarations = declaration_lock()?;
        let config = Config::get().await?;
        if self.encrypt && !Settings::get().history.enabled {
            bail!("dotfiles: cannot enroll encrypted paths while history is disabled");
        }
        if self.encrypt && inside_capture()? {
            bail!(
                "dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified"
            );
        }
        let managed = crate::system::files::composed_files_from_config(&config)?;
        let global = declaration_file(false)?;
        let mut edits: BTreeMap<PathBuf, DeclarationEdit> = BTreeMap::new();
        let mut locations = BTreeMap::new();
        let mut declared: Vec<(String, PathBuf)> = vec![];
        let mut manual = vec![];
        for target_raw in &self.targets {
            let target = crate::system::files::resolve_target_arg(target_raw)
                .components()
                .collect::<PathBuf>();
            if target.is_relative() {
                bail!("{target_raw}: target must be absolute or start with ~/");
            }
            crate::system::history::tracked::ensure_portable_ancestors(&target)?;
            let target_key = normalized_target(&target);

View on GitHub (pinned to 533346cc37)