Skip to content

fix(mcp): keep stdio child no-proxy entries runtime-safe#2081

Open
hydraxman wants to merge 1 commit into
MoonshotAI:mainfrom
hydraxman:fix/stdio-no-proxy-portable-ipv6
Open

fix(mcp): keep stdio child no-proxy entries runtime-safe#2081
hydraxman wants to merge 1 commit into
MoonshotAI:mainfrom
hydraxman:fix/stdio-no-proxy-portable-ipv6

Conversation

@hydraxman

Copy link
Copy Markdown

Related Issue

Fixes #1931

Problem

When an HTTP proxy is configured, stdio MCP children inherit [::1] in both NO_PROXY casings. Python httpx treats that entry as an invalid port and exits before the MCP handshake. Removing it unconditionally would instead regress Node's IPv6 loopback bypass when NODE_USE_ENV_PROXY=1.

What changed

  • pass the stdio command and arguments into child environment construction in both agent engines
  • keep [::1] for direct and commonly wrapped Node launchers and JavaScript entry points
  • emit the portable bare ::1 form for other runtimes, while honoring explicit parent or per-server bracketed overrides
  • add a patch changeset and regression coverage for portable, Node, wrapped-Node, and explicit-override paths

No documentation update is needed because the public proxy configuration and precedence are unchanged.

Testing

  • pnpm exec vitest run test/mcp/client-stdio.test.ts in packages/agent-core — 29 passed
  • pnpm exec vitest run test/agent/mcp/client-stdio.test.ts in packages/agent-core-v2 — 20 passed
  • pnpm --filter @moonshot-ai/agent-core test — 3,990 passed, 3 expected failures, 30 skipped, 1 todo
  • pnpm --filter @moonshot-ai/agent-core-v2 test — 3,958 passed
  • typecheck for both agent-core packages — passed
  • changed-file type-aware lint — 0 warnings, 0 errors
  • root pnpm lint — 0 errors (existing warnings only)
  • Python httpx.Client() reproducer — bracketed child value fails; portable child value succeeds
  • Node 24.15 local IPv6 fetch with an unreachable proxy — bracketed Node value returns 200 ok; bare value attempts the proxy and fails

Checklist

  • I have read the CONTRIBUTING document.
  • I have linked a related issue, or explained the problem above.
  • I have added tests that prove my feature works.
  • Ran gen-changesets skill, or this PR needs no changeset.
  • Ran gen-docs skill, or this PR needs no doc update.

@changeset-bot

changeset-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 6ffe94e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@moonshot-ai/kimi-code Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6ffe94e442

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +288 to +291
function usesNodeEnvProxy(command: string, args: readonly string[]): boolean {
const executable = command.split(/[\\/]/).at(-1) ?? '';
if (NODE_ENV_PROXY_COMMAND_RE.test(executable)) return true;
return NODE_ENV_PROXY_WRAPPER_RE.test(executable) && args.some((arg) => NODE_ENV_PROXY_ARGUMENT_RE.test(arg));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Recognize Node shebang launchers before stripping IPv6

A stdio server started through an extensionless Node bin (for example command: "./node_modules/.bin/my-mcp" or a globally installed MCP executable) inherits NODE_USE_ENV_PROXY=1, but its command does not match either regex and is therefore treated as a non-Node runtime. The new code removes [::1], so that Node child loses the IPv6 loopback proxy bypass that this change is intended to preserve; any such server that connects to http://[::1]:<port> under an HTTP proxy will attempt the proxy instead. This classifier is duplicated in the v2 client as well, so both engines need a way to preserve the entry for Node shebang/bin launchers.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

stdio MCP child env injects bracketed [::1] into NO_PROXY, crashing Python httpx-based MCP servers

2 participants