Repository navigation
fix: preserve explicit MCP stdio environment values over inherited parent defaults - #21435
Conversation
Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
Bugfix reviewOutcome: approved Reproduction replayStatus: no-longer-reproduces The exact original reproduction completed successfully and the original bug signal did not appear. Fixes issueStatus: fully-addresses Explicit environment keys now prevent corresponding inherited defaults from being applied, with case-insensitive matching on Windows covering native Path casing. Side effectsRisk: low The only behavioral change is the documented and intended precedence of caller-provided environment values; unrelated inherited defaults remain unchanged. PerformanceRisk: low The change creates one set of custom environment keys and performs constant-time lookups over a fixed list of inherited defaults, adding negligible time and memory overhead. Backwards compatibilityRisk: low No stored or persisted data is read, written, or migrated; the change only affects environment construction when starting a new MCP child process. Breaking changesRisk: none Public exports, types, accepted inputs, outputs, errors, configuration shape, and defaults remain intact; the corrected precedence aligns env behavior with its documented meaning. ArchitectureRisk: low The fix remains localized to the MCP stdio transport's existing internal environment helper and introduces no new dependencies, cross-package source imports, exports, or inappropriate abstractions. Change scopeStatus: minimal The final diff contains only the localized implementation change, focused regression tests, and the required patch changeset. SecurityRisk: low Honoring explicitly supplied PATH, home, and temporary-directory values restores caller control without exposing new data or capabilities beyond the existing env option. TestingStatus: appropriate Regression tests cover exact-case precedence, Windows case-insensitive Path handling, and input immutability; the exact public-API reproduction, full MCP Node and Edge suites, type-checking, linting, and formatting checks all passed. VerificationReviewed the complete merge-base diff, MCP stdio call path, public exports and configuration type, documentation, changeset, and architecture guidance. The full @ai-sdk/mcp Node and Edge test suites each passed 330 tests, package type-checking passed, focused lint and formatting checks passed, and the authoritative reproduction replay confirmed the bug no longer occurs. Relevant Documentation |
|
🚀 Published in:
|
…ited parent defaults (#21465) ## Background Explicit MCP stdio environment values such as PATH, HOME, TEMP, and USERPROFILE were replaced by parent-process values, preventing sandboxed homes, private temp directories, and pinned executable paths. ## Root Cause getEnvironment copied custom values before unconditionally assigning inherited defaults from process.env; the original public-API reproduction confirmed those later assignments reached the child instead of explicit values. ## Summary Inherited defaults are now skipped when a matching custom key exists, including case-insensitive key matching on Windows, while unrelated defaults remain inherited. Added a patch changeset for @ai-sdk/mcp. ## Testing Added regression tests for explicit inherited-key overrides and Windows Path casing while retaining the existing immutability coverage. ## End-to-end Validation - `replay_original_reproduction`: passed with `no-longer-reproduces`; the MCP child received every explicit environment value. ## Related Issues Fixes #21430 Closes #21462 Backport of #21435 Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com> Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com> Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
…ited parent defaults (#21470) ## Background Explicit MCP stdio environment values such as PATH, HOME, TEMP, and USERPROFILE were replaced by parent-process values, preventing sandboxed homes, private temp directories, and pinned executable paths. ## Root Cause getEnvironment copied custom values before unconditionally assigning inherited defaults from process.env; the original public-API reproduction confirmed those later assignments reached the child instead of explicit values. ## Summary Inherited defaults are now skipped when a matching custom key exists, including case-insensitive key matching on Windows, while unrelated defaults remain inherited. Added a patch changeset for @ai-sdk/mcp. ## Testing Added regression tests for explicit inherited-key overrides and Windows Path casing while retaining the existing immutability coverage. ## End-to-end Validation - `replay_original_reproduction`: passed with `no-longer-reproduces`; the MCP child received every explicit environment value. ## Related Issues Fixes #21430 Closes #21461 Backport of #21435 Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com> Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com> Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com> Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Background
Explicit MCP stdio environment values such as PATH, HOME, TEMP, and USERPROFILE were replaced by parent-process values, preventing sandboxed homes, private temp directories, and pinned executable paths.
Root Cause
getEnvironment copied custom values before unconditionally assigning inherited defaults from process.env; the original public-API reproduction confirmed those later assignments reached the child instead of explicit values.
Summary
Inherited defaults are now skipped when a matching custom key exists, including case-insensitive key matching on Windows, while unrelated defaults remain inherited. Added a patch changeset for @ai-sdk/mcp.
Testing
Added regression tests for explicit inherited-key overrides and Windows Path casing while retaining the existing immutability coverage.
End-to-end Validation
replay_original_reproduction: passed withno-longer-reproduces; the MCP child received every explicit environment value.Related Issues
Fixes #21430
Closes #21432