Skip to content

fix(exec): honor Env override and keep secrets out of debug logs - #15

Merged
zxyao145 merged 1 commit into
mainfrom
fix/env-override-and-exec-overhead
Sep 26, 2026
Merged

zxyao145 merged 1 commit into
mainfrom
fix/env-override-and-exec-overhead

Conversation

@zxyao145

Copy link
Copy Markdown
Owner
  • Clear ProcessStartInfo.Environment before applying CodexOptions.Env, so the override replaces the parent environment as documented instead of extending it
  • Log environment variable names only when starting the CLI; values (including CODEX_API_KEY) are no longer written to the debug log
  • Move CodexExec logging to [LoggerMessage]; the start message is only formatted when Debug is enabled
  • Resolve the executable path once per CodexExec instead of on every run (on Windows it probes every PATH directory), and use Environment.ProcessPath instead of Process.GetCurrentProcess().MainModule
  • Add ApplyEnvironment tests for the override and inherit cases; FakeCodexCli now passes the parent environment explicitly, since the fake CLI is a .NET apphost that needs it to locate the runtime

Behavior change

Callers that set CodexOptions.Env no longer inherit the parent environment (PATH, HOME, DOTNET_ROOT, ...). Anyone relying on the old behavior must now include those variables in Env. The debug log placeholder {Environment} is renamed to {EnvironmentKeys}.

Before the fix, the new test reproduces the leak:

failed CodexSdk.Tests.CodexExecTests.ApplyEnvironment_WhenEnvOverrideProvided_DoesNotInheritProcessEnvironment
  Assert.Equal() Failure: Collections differ at index 0
  Expected: "CODEX_API_KEY"
  Actual:   "AI_AGENT"

Validation

dotnet test --solution codexsdk.slnx: total 52, failed 0, succeeded 52, skipped 0.

Not included

System.Text.Json source generation for event parsing was evaluated and dropped: because the event DTOs use init accessors, it was ~15–20% slower than reflection and allocated more per event.

ProcessStartInfo.Environment is pre-populated from the parent process, so
writing the override on top of it leaked every inherited variable into the
Codex CLI. The override is now applied after clearing that dictionary, and
the parent environment is only inherited when no override is given.

The debug log previously printed every variable's value, which exposed
secrets such as CODEX_API_KEY; it now records variable names only.

Also resolve the executable path once per CodexExec instead of on each run,
since on Windows it probes every PATH directory, move logging to
source-generated LoggerMessage methods, and use Environment.ProcessPath in
place of the Process.GetCurrentProcess() workaround.
@zxyao145
zxyao145 merged commit 5dce1cf into main Sep 26, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant