jdx/mise · error
dotfiles: cannot enroll encrypted paths inside an active…
Error message
dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified
What it means
mise's `dot track --encrypt` enrolls dotfile paths into managed tracking with encryption of the captured baseline. When the command runs inside an active history capture wrapper, the encrypted baseline cannot be verified against the capture, so the operation is refused up front. The user must run the encrypted enrollment as a separate, standalone invocation.
Solutions
- Exit the history capture session and run `mise dot track --encrypt <targets>` as a standalone command
- Split the script so the encrypted enrollment happens before entering the capture wrapper
- If only non-encrypted paths are needed inside the capture, drop the --encrypt flag
Example fix
// before (inside a capture wrapper) mise history capture -- mise dot track --encrypt ~/.ssh/config // after mise dot track --encrypt ~/.ssh/config mise history capture -- <command>
Defensive patterns
Strategy: validation
Validate before calling
if [[ -n "$MISE_HISTORY_CAPTURE" ]]; then echo 'defer `mise dot track --encrypt` until after the capture ends'; exit 1; fi
Prevention
- Never nest `dot track --encrypt` inside `mise history capture` or capture-wrapped shells
- Keep encrypted enrollment as a discrete setup step
- Automate enrollments in scripts that run outside capture sessions
When it happens
Trigger: Running `mise dot track --encrypt` (encrypt=true) while the process is detected by inside_capture() to be executing within a live history capture session (e.g. inside `mise history capture ...` or a capture-wrapped command).
Common situations: A user wraps an interactive shell or script in a history capture and then tries to enroll new encrypted dotfiles from within that session; or an automation script chains track --encrypt inside a capture-wrapped setup step.
Understand the failure class
Background: "Invalid state transition" errors: "status must be X, actually Y", "already rejected/charging/uninstalled", "cannot ... while running" — what they mean when a library rejects your call — this error's family across 31 libraries.
Related errors
- cannot retain an unreadable plaintext version of newly…
- checkpoint has no content snapshot
- checkpoint is not an operation
- checkpoint is unavailable; cannot find the state before…
- dotfiles: cannot enroll encrypted paths while history is…
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/bb210c92ad3e58fe.
Report an issue: GitHub.
Appendix: source
Thrown at src/cli/dotfiles/track.rs:63
/// Encrypt contents before saving them to history (requires `[history.encryption].recipients`)
#[usage(long)]
encrypt: bool,
/// Accept without prompting
#[usage(long, short)]
yes: bool,
}
impl DotfilesTrack {
/// Write the requested declarations and capture their initial history baseline.
pub(crate) async fn run(self) -> Result<()> {
let _declarations = declaration_lock()?;
let config = Config::get().await?;
if self.encrypt && !Settings::get().history.enabled {
bail!("dotfiles: cannot enroll encrypted paths while history is disabled");
}
if self.encrypt && inside_capture()? {
bail!(
"dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified"
);
}
let managed = crate::system::files::composed_files_from_config(&config)?;
let global = declaration_file(false)?;
let mut edits: BTreeMap<PathBuf, DeclarationEdit> = BTreeMap::new();
let mut locations = BTreeMap::new();
let mut declared: Vec<(String, PathBuf)> = vec![];
let mut manual = vec![];
for target_raw in &self.targets {
let target = crate::system::files::resolve_target_arg(target_raw)
.components()
.collect::<PathBuf>();
if target.is_relative() {
bail!("{target_raw}: target must be absolute or start with ~/");
}
crate::system::history::tracked::ensure_portable_ancestors(&target)?;
let target_key = normalized_target(&target);View on GitHub (pinned to 533346cc37)