fix: pass agent context config explicitly instead of reading env (#24759)

The CODER_AGENT_EXP_* env vars are agent-internal options. When set
in the workspace environment they leak to MCP subprocesses and user
shells.

ReadEnvConfig() captures the values and ClearEnvVars() strips them
before the reinit loop, so config survives agent restarts. NewAPI
and ReadEnvConfig both use applyDefaults() to fill zero fields.
The chatd test passes config via agenttest.WithContextConfigFromEnv().
This commit is contained in:
Mathias Fredriksson
2026-04-28 17:58:28 +03:00
committed by GitHub
parent 1666bff1f9
commit 3c450899ea
7 changed files with 165 additions and 57 deletions
+7
View File
@@ -28,6 +28,7 @@ import (
"cdr.dev/slog/v3/sloggers/slogstackdriver"
"github.com/coder/coder/v2/agent"
"github.com/coder/coder/v2/agent/agentcontainers"
"github.com/coder/coder/v2/agent/agentcontextconfig"
"github.com/coder/coder/v2/agent/agentexec"
"github.com/coder/coder/v2/agent/agentssh"
"github.com/coder/coder/v2/agent/boundarylogproxy"
@@ -279,6 +280,11 @@ func workspaceAgent() *serpent.Command {
defer reinitCancel()
reinitEvents := agentsdk.WaitForReinitLoop(reinitCtx, logger, client)
// Read and strip env vars before the reinit
// loop so config survives agent restarts.
contextConfig := agentcontextconfig.ReadEnvConfig()
agentcontextconfig.ClearEnvVars()
var (
lastOwnerID uuid.UUID
lastErr error
@@ -335,6 +341,7 @@ func workspaceAgent() *serpent.Command {
SocketPath: socketPath,
SocketServerEnabled: socketServerEnabled,
BoundaryLogProxySocketPath: boundaryLogProxySocketPath,
ContextConfig: contextConfig,
})
if debugAddress != "" {