Skip to content

pilotctl config --set accepts invalid values, and encrypt in config.json has no effect #477

Description

@artemiia

pilotctl config --set happily saves nonsense, and setting encrypt in the config does nothing.

Environment: macOS 15 (Darwin 24.5, arm64), node upgraded from a March v1.2.x build to v1.13.10 via curl -fsSL https://pilotprotocol.network/install.sh | sh on 2026-09-24. Daemon managed by launchd.

What happened
Every one of these returned status: ok and was written to config.json:

pilotctl config --set transport=bogus
pilotctl config --set proxy=notaurl
pilotctl config --set encrypt=maybe        # the boolean becomes the string "maybe"
pilotctl config --set socket=
pilotctl config --set registry=notanaddr
pilotctl config --set nonsense_key=1
pilotctl config --set proxy=http://user:secret@proxy.example:3128   # echoed back unredacted

cmdConfig at v1.13.10 is cfg[parts[0]] = parts[1] with no key list, type or format check.

Main (#470) now validates transport and proxy and redacts the proxy URL, but encrypt, registry, beacon, socket, unknown keys and empty values are still accepted.

Second problem
pilotctl config displays encrypt, and --set encrypt=false saves it, but buildDaemonArgs never reads cfg["encrypt"]; encryption is only controlled by the --no-encrypt flag on daemon start. So a user who turns encryption off (or on) via config gets no effect and no warning.

Expected
Reject unknown keys, validate types (encrypt must be a bool), validate addresses, refuse empty values for path/address keys, and either honour encrypt from config or refuse to set it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions