A tab instead of spaces — or any YAML syntax error — in the config file causes ReadLocalConfig to return an empty config with no error, making every command behave as if the user has never logged in.
The dangerous part: login sees the empty config, treats it as a fresh install, and writes a brand-new file over it. Every other context, server, user and refresh token in the file is gone with no warning.
Root cause
localconfig.go line 103:
err = configUtil.UnmarshalLocalFile(path, &config)
if os.IsNotExist(err) {
return nil, nil
}
err = ValidateLocalConfig(config) // parse error is silently overwritten here
Only os.IsNotExist is handled. A YAML parse error falls through and gets immediately overwritten by ValidateLocalConfig. Same bug in ReadLocalWatchConfig.
To reproduce
- Put a tab on any indented line in
~/.config/microcks/config
- Run
microcks context → reports "no contexts defined" instead of a parse error
- Run
microcks login <any-server> → the file is truncated and rewritten. All previous contexts are gone.
Fix
if err != nil {
return nil, fmt.Errorf("reading config %s: %w", path, err)
}
Same in ReadLocalWatchConfig. After this, nil, nil keeps its only meaning — file doesn't exist — and fresh-install logic stays untouched.
There is no test for malformed input in config_test.go, which is how this went unnoticed.
A tab instead of spaces — or any YAML syntax error — in the config file causes
ReadLocalConfigto return an empty config with no error, making every command behave as if the user has never logged in.The dangerous part:
loginsees the empty config, treats it as a fresh install, and writes a brand-new file over it. Every other context, server, user and refresh token in the file is gone with no warning.Root cause
localconfig.goline 103:Only
os.IsNotExistis handled. A YAML parse error falls through and gets immediately overwritten byValidateLocalConfig. Same bug inReadLocalWatchConfig.To reproduce
~/.config/microcks/configmicrocks context→ reports "no contexts defined" instead of a parse errormicrocks login <any-server>→ the file is truncated and rewritten. All previous contexts are gone.Fix
Same in
ReadLocalWatchConfig. After this,nil, nilkeeps its only meaning — file doesn't exist — and fresh-install logic stays untouched.There is no test for malformed input in
config_test.go, which is how this went unnoticed.