AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

ShellToolMiddleware Does Not Inherit Parent Environment When Env Is Omitted

When env is not provided to ShellToolMiddleware, _create_resources coerces None to an empty dict, causing host and Codex shell sessions to lose parent environment variables such as PATH, proxy settings, and credentials.

highConfidence 88%LangchainAffected V1.3.18

Origin Analysis

ShellToolMiddleware._create_resources uses `self.env or {}` (or equivalent) before passing env to the shell session, converting the sentinel None into an empty mapping. This prevents the underlying ShellSession from applying its default behavior of inheriting os.environ for host/codex sandboxes.
Set os.environ["LANGCHAIN_SHELL_PARENT_ENV"] = "visible"; instantiate ShellToolMiddleware() without env; call before_agent and retrieve state["shell_session_resources"]; execute `printf "$LANGCHAIN_SHELL_PARENT_ENV"` in the session; output is empty instead of "visible".

Fixing Code Block

Edge Case Audit

If the Docker-backed ShellSession implementation defaults to os.environ when env is None (i.e., uses `env or os.environ`), this change could leak host environment variables into Docker containers. Verify that the Docker path checks for None separately and passes no environment variables unless an explicit env is supplied. Additionally, sessions snapshot the environment at creation; changes to os.environ after before_agent will not be reflected. Rollback is straightforward: restore `env = self.env or {}` in the previous method body.

Ecosystem Topology