jdx/mise · error

dotfiles: cannot enroll encrypted paths while history is…

Error message

dotfiles: cannot enroll encrypted paths while history is disabled

What it means

Enrolling a path with `mise dot track --encrypt` requires the history subsystem, because encrypted enrollment must capture and verify an initial baseline checkpoint. If history.enabled is false, encrypted tracking is refused outright.

Solutions

  1. Enable history first: `mise settings set history.enabled true`, then run `mise dot track --encrypt`
  2. Track without --encrypt if you do not need encrypted enrollment and history stays disabled

Example fix

// before
mise dot track --encrypt ~/.ssh/config  // history disabled
// after
mise settings set history.enabled true
mise dot track --encrypt ~/.ssh/config
Defensive patterns

Strategy: validation

Validate before calling

enabled=$(mise settings get history.enabled)
[ "$enabled" = "true" ] || { echo 'dot track --encrypt requires history.enabled = true'; exit 1; }

Try / catch

mise dot track --encrypt "$p" || {
  mise settings set history.enabled true
  mise dot track --encrypt "$p"
}

Prevention

When it happens

Trigger: Running `mise dot track --encrypt` while `history.enabled = false` in mise settings.

Common situations: Users with dotfile history disabled trying to adopt encrypted tracking; CI or hardened configs where history is off; misunderstanding that --encrypt works independently of history.

Related errors


AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17). Data as JSON: /api/errors/b4cfe3a62f9be5c6. Report an issue: GitHub.

Appendix: source

Thrown at src/cli/dotfiles/track.rs:60

    #[usage(long)]
    no_autosave: bool,

    /// Encrypt contents before saving them to history (requires `[history.encryption].recipients`)
    #[usage(long)]
    encrypt: bool,

    /// Accept without prompting
    #[usage(long, short)]
    yes: bool,
}

impl DotfilesTrack {
    /// Write the requested declarations and capture their initial history baseline.
    pub(crate) async fn run(self) -> Result<()> {
        let _declarations = declaration_lock()?;
        let config = Config::get().await?;
        if self.encrypt && !Settings::get().history.enabled {
            bail!("dotfiles: cannot enroll encrypted paths while history is disabled");
        }
        if self.encrypt && inside_capture()? {
            bail!(
                "dotfiles: cannot enroll encrypted paths inside an active history capture; run `mise dot track --encrypt` separately so its baseline can be verified"
            );
        }
        let managed = crate::system::files::composed_files_from_config(&config)?;
        let global = declaration_file(false)?;
        let mut edits: BTreeMap<PathBuf, DeclarationEdit> = BTreeMap::new();
        let mut locations = BTreeMap::new();
        let mut declared: Vec<(String, PathBuf)> = vec![];
        let mut manual = vec![];
        for target_raw in &self.targets {
            let target = crate::system::files::resolve_target_arg(target_raw)
                .components()
                .collect::<PathBuf>();
            if target.is_relative() {
                bail!("{target_raw}: target must be absolute or start with ~/");

View on GitHub (pinned to 533346cc37)