AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

InMemoryRecordManager Ignores Empty Group_ids Due To Truthiness Check, Leading To Validation Bypass And Incorrect Filtering

InMemoryRecordManager treats an explicitly provided empty list for group_ids as if it were None because of truthiness checks. This causes update() to skip length validation and store records with group_id=None, and list_keys() to return all keys instead of an empty result when group_ids=[] is passed. The async methods have the same issue.

highConfidence 95%LangChainAffected V1.6.4

Origin Analysis

The code uses `if group_ids:` (truthiness) to check whether the parameter was provided, which evaluates to False for an empty list. This conflates the distinct semantic states of 'not specified' (None) and 'explicitly empty' ([]), bypassing validation and filtering logic.
1. Instantiate InMemoryRecordManager(namespace='demo'). 2. Call update(['key2'], group_ids=[]) and observe that no ValueError is raised and key2 is stored with group_id=None. 3. Call list_keys(group_ids=[]) and observe that all keys are returned instead of an empty list.

Fixing Code Block

Edge Case Audit

This change alters behavior for callers who previously passed an empty list to intentionally bypass validation or retrieve all keys. Such usage was incorrect per the API contract and should be updated. If rolling back after this fix, records stored with `group_id=None` due to the bug will remain and may need manual cleanup. In concurrent environments, the in-memory store is not thread-safe and may still cause race conditions unrelated to this fix; external synchronization is advised for multi-threaded usage.

Ecosystem Topology