pilotctl config --set happily saves nonsense, and setting encrypt in the config does nothing.
Environment: macOS 15 (Darwin 24.5, arm64), node upgraded from a March v1.2.x build to v1.13.10 via curl -fsSL https://pilotprotocol.network/install.sh | sh on 2026-09-24. Daemon managed by launchd.
What happened
Every one of these returned status: ok and was written to config.json:
pilotctl config --set transport=bogus
pilotctl config --set proxy=notaurl
pilotctl config --set encrypt=maybe # the boolean becomes the string "maybe"
pilotctl config --set socket=
pilotctl config --set registry=notanaddr
pilotctl config --set nonsense_key=1
pilotctl config --set proxy=http://user:secret@proxy.example:3128 # echoed back unredacted
cmdConfig at v1.13.10 is cfg[parts[0]] = parts[1] with no key list, type or format check.
Main (#470) now validates transport and proxy and redacts the proxy URL, but encrypt, registry, beacon, socket, unknown keys and empty values are still accepted.
Second problem
pilotctl config displays encrypt, and --set encrypt=false saves it, but buildDaemonArgs never reads cfg["encrypt"]; encryption is only controlled by the --no-encrypt flag on daemon start. So a user who turns encryption off (or on) via config gets no effect and no warning.
Expected
Reject unknown keys, validate types (encrypt must be a bool), validate addresses, refuse empty values for path/address keys, and either honour encrypt from config or refuse to set it.
pilotctl config --sethappily saves nonsense, and settingencryptin the config does nothing.Environment: macOS 15 (Darwin 24.5, arm64), node upgraded from a March v1.2.x build to v1.13.10 via
curl -fsSL https://pilotprotocol.network/install.sh | shon 2026-09-24. Daemon managed by launchd.What happened
Every one of these returned
status: okand was written toconfig.json:cmdConfigat v1.13.10 iscfg[parts[0]] = parts[1]with no key list, type or format check.Main (#470) now validates
transportandproxyand redacts the proxy URL, butencrypt,registry,beacon,socket, unknown keys and empty values are still accepted.Second problem
pilotctl configdisplaysencrypt, and--set encrypt=falsesaves it, butbuildDaemonArgsnever readscfg["encrypt"]; encryption is only controlled by the--no-encryptflag ondaemon start. So a user who turns encryption off (or on) via config gets no effect and no warning.Expected
Reject unknown keys, validate types (
encryptmust be a bool), validate addresses, refuse empty values for path/address keys, and either honourencryptfrom config or refuse to set it.