Skip to content

fix: preserve explicit MCP stdio environment values over inherited parent defaults - #21435

Merged
gr2m merged 3 commits into
mainfrom
bugfix-21430-20260924142444238968
Sep 24, 2026
Merged

gr2m merged 3 commits into
mainfrom
bugfix-21430-20260924142444238968

Conversation

@ai-sdk-factory

Copy link
Copy Markdown
Contributor

Background

Explicit MCP stdio environment values such as PATH, HOME, TEMP, and USERPROFILE were replaced by parent-process values, preventing sandboxed homes, private temp directories, and pinned executable paths.

Root Cause

getEnvironment copied custom values before unconditionally assigning inherited defaults from process.env; the original public-API reproduction confirmed those later assignments reached the child instead of explicit values.

Summary

Inherited defaults are now skipped when a matching custom key exists, including case-insensitive key matching on Windows, while unrelated defaults remain inherited. Added a patch changeset for @ai-sdk/mcp.

Testing

Added regression tests for explicit inherited-key overrides and Windows Path casing while retaining the existing immutability coverage.

End-to-end Validation

  • replay_original_reproduction: passed with no-longer-reproduces; the MCP child received every explicit environment value.

Related Issues

Fixes #21430

Closes #21432

ai-sdk-factory and others added 3 commits September 24, 2026 14:30
Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
@ai-sdk-factory

Copy link
Copy Markdown
Contributor Author

Bugfix review

Outcome: approved

Reproduction replay

Status: no-longer-reproduces

The exact original reproduction completed successfully and the original bug signal did not appear.

Fixes issue

Status: fully-addresses

Explicit environment keys now prevent corresponding inherited defaults from being applied, with case-insensitive matching on Windows covering native Path casing.

Side effects

Risk: low

The only behavioral change is the documented and intended precedence of caller-provided environment values; unrelated inherited defaults remain unchanged.

Performance

Risk: low

The change creates one set of custom environment keys and performs constant-time lookups over a fixed list of inherited defaults, adding negligible time and memory overhead.

Backwards compatibility

Risk: low

No stored or persisted data is read, written, or migrated; the change only affects environment construction when starting a new MCP child process.

Breaking changes

Risk: none

Public exports, types, accepted inputs, outputs, errors, configuration shape, and defaults remain intact; the corrected precedence aligns env behavior with its documented meaning.

Architecture

Risk: low

The fix remains localized to the MCP stdio transport's existing internal environment helper and introduces no new dependencies, cross-package source imports, exports, or inappropriate abstractions.

Change scope

Status: minimal

The final diff contains only the localized implementation change, focused regression tests, and the required patch changeset.

Security

Risk: low

Honoring explicitly supplied PATH, home, and temporary-directory values restores caller control without exposing new data or capabilities beyond the existing env option.

Testing

Status: appropriate

Regression tests cover exact-case precedence, Windows case-insensitive Path handling, and input immutability; the exact public-API reproduction, full MCP Node and Edge suites, type-checking, linting, and formatting checks all passed.

Verification

Reviewed the complete merge-base diff, MCP stdio call path, public exports and configuration type, documentation, changeset, and architecture guidance. The full @ai-sdk/mcp Node and Edge test suites each passed 330 tests, package type-checking passed, focused lint and formatting checks passed, and the authoritative reproduction replay confirmed the bug no longer occurs.

Relevant Documentation

@gr2m
gr2m merged commit 1ffd453 into main Sep 24, 2026
69 checks passed
@gr2m
gr2m deleted the bugfix-21430-20260924142444238968 branch September 24, 2026 18:38
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Published in:

Package Version
ai 7.0.114 github npm
@ai-sdk/amazon-bedrock 5.0.94 github npm
@ai-sdk/angular 3.0.114 github npm
@ai-sdk/anthropic 4.0.63 github npm
@ai-sdk/anthropic-aws 2.0.55 github npm
@ai-sdk/azure 4.0.79 github npm
@ai-sdk/code-mode 1.0.71 github npm
@ai-sdk/gateway 4.0.92 github npm
@ai-sdk/google 4.0.80 github npm
@ai-sdk/google-vertex 5.0.93 github npm
@ai-sdk/harness 1.0.124 github npm
@ai-sdk/harness-acp 1.0.62 github npm
@ai-sdk/harness-claude-code 1.0.128 github npm
@ai-sdk/harness-cline 1.0.51 github npm
@ai-sdk/harness-codex 1.0.126 github npm
@ai-sdk/harness-cursor 1.0.37 github npm
@ai-sdk/harness-deepagents 1.0.124 github npm
@ai-sdk/harness-fx 1.0.37 github npm
@ai-sdk/harness-github-copilot 1.0.19 github npm
@ai-sdk/harness-grok-build 1.0.61 github npm
@ai-sdk/harness-opencode 1.0.126 github npm
@ai-sdk/harness-pi 1.0.126 github npm
@ai-sdk/langchain 3.0.114 github npm
@ai-sdk/llamaindex 3.0.114 github npm
@ai-sdk/mcp 2.0.58 github npm
@ai-sdk/minimax 3.0.40 github npm
@ai-sdk/open-responses 2.0.52 github npm
@ai-sdk/openai 4.0.75 github npm
@ai-sdk/otel 1.0.114 github npm
@ai-sdk/policy-opa 1.0.114 github npm
@ai-sdk/quiverai 2.0.48 github npm
@ai-sdk/react 4.0.117 github npm
@ai-sdk/rsc 3.0.114 github npm
@ai-sdk/sandbox-just-bash 1.0.124 github npm
@ai-sdk/sandbox-vercel 1.0.124 github npm
@ai-sdk/svelte 5.0.114 github npm
@ai-sdk/tui 1.0.115 github npm
@ai-sdk/vue 4.0.114 github npm
@ai-sdk/workflow 2.0.45 github npm
@ai-sdk/workflow-harness 1.0.124 github npm
@ai-sdk/xai 5.0.8 github npm

gr2m pushed a commit that referenced this pull request Sep 24, 2026
…ited parent defaults (#21465)

## Background

Explicit MCP stdio environment values such as PATH, HOME, TEMP, and
USERPROFILE were replaced by parent-process values, preventing sandboxed
homes, private temp directories, and pinned executable paths.

## Root Cause

getEnvironment copied custom values before unconditionally assigning
inherited defaults from process.env; the original public-API
reproduction confirmed those later assignments reached the child instead
of explicit values.

## Summary

Inherited defaults are now skipped when a matching custom key exists,
including case-insensitive key matching on Windows, while unrelated
defaults remain inherited. Added a patch changeset for @ai-sdk/mcp.

## Testing

Added regression tests for explicit inherited-key overrides and Windows
Path casing while retaining the existing immutability coverage.

## End-to-end Validation

- `replay_original_reproduction`: passed with `no-longer-reproduces`;
the MCP child received every explicit environment value.

## Related Issues

Fixes #21430

Closes #21462

Backport of #21435

Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com>
Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
gr2m added a commit that referenced this pull request Sep 24, 2026
…ited parent defaults (#21470)

## Background

Explicit MCP stdio environment values such as PATH, HOME, TEMP, and
USERPROFILE were replaced by parent-process values, preventing sandboxed
homes, private temp directories, and pinned executable paths.

## Root Cause

getEnvironment copied custom values before unconditionally assigning
inherited defaults from process.env; the original public-API
reproduction confirmed those later assignments reached the child instead
of explicit values.

## Summary

Inherited defaults are now skipped when a matching custom key exists,
including case-insensitive key matching on Windows, while unrelated
defaults remain inherited. Added a patch changeset for @ai-sdk/mcp.

## Testing

Added regression tests for explicit inherited-key overrides and Windows
Path casing while retaining the existing immutability coverage.

## End-to-end Validation

- `replay_original_reproduction`: passed with `no-longer-reproduces`;
the MCP child received every explicit environment value.

## Related Issues

Fixes #21430

Closes #21461

Backport of #21435

Co-authored-by: ai-sdk-factory[bot] <305873210+ai-sdk-factory[bot]@users.noreply.github.com>
Co-authored-by: ai-sdk-factory <308175966+ai-sdk-factory@users.noreply.github.com>
Co-authored-by: ohad6k <190882507+ohad6k@users.noreply.github.com>
Co-authored-by: Gregor Martynus <39992+gr2m@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@ai-sdk/mcp: stdio transport overrides explicit env values (PATH, HOME, TEMP, USERPROFILE) with the parent's

2 participants