Skip to content

bug: YAML parse error in config is silently swallowed, login overwrites all other contexts #572

Description

@gyanranjanpanda

A tab instead of spaces — or any YAML syntax error — in the config file causes ReadLocalConfig to return an empty config with no error, making every command behave as if the user has never logged in.

The dangerous part: login sees the empty config, treats it as a fresh install, and writes a brand-new file over it. Every other context, server, user and refresh token in the file is gone with no warning.

Root cause

localconfig.go line 103:

err = configUtil.UnmarshalLocalFile(path, &config)
if os.IsNotExist(err) {
    return nil, nil
}
err = ValidateLocalConfig(config)  // parse error is silently overwritten here

Only os.IsNotExist is handled. A YAML parse error falls through and gets immediately overwritten by ValidateLocalConfig. Same bug in ReadLocalWatchConfig.

To reproduce

  1. Put a tab on any indented line in ~/.config/microcks/config
  2. Run microcks context → reports "no contexts defined" instead of a parse error
  3. Run microcks login <any-server> → the file is truncated and rewritten. All previous contexts are gone.

Fix

if err != nil {
    return nil, fmt.Errorf("reading config %s: %w", path, err)
}

Same in ReadLocalWatchConfig. After this, nil, nil keeps its only meaning — file doesn't exist — and fresh-install logic stays untouched.

There is no test for malformed input in config_test.go, which is how this went unnoticed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions