google-gemini / google-gemini/gemini-cli
expandEnvVars input is overwritten by __GCLI_EXPAND_TARGET__ environment value
- Dominant language
- TypeScript
- Stars
- 107k
- Forks
- 14.6k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 45
Description
### What happened?
`expandEnvVars()` returns the value of the `__GCLI_EXPAND_TARGET__` environment entry instead of expanding its input when the provided environment contains that key.
The helper wraps its input in a parsed object using the fixed key `__GCLI_EXPAND_TARGET__`, then passes the caller-provided environment to `dotenv-expand` as `processEnv`. When both contain the same key, the `processEnv` value takes priority and silently replaces the entire input string.
This focused regression test reproduces the behavior:
```ts
expect(
expandEnvVars('Hello $USER', {
USER: 'morty',
__GCLI_EXPAND_TARGET__: 'unexpected override',
}),
).toBe('Hello morty');
```
The actual returned value is:
```text
unexpected override
```
This can affect MCP configuration because MCP transport headers and explicit server environment values are expanded using environment records passed to this helper:
- `packages/core/src/tools/mcp-client.ts:985-1002`
- `packages/core/src/tools/mcp-client.ts:2361-2374`
### What did you expect to happen?
`expandEnvVars()` should expand the supplied string independently of the environment variable names it receives.
For the example above, it should return:
```text
Hello morty
```
### Client information
Client Information
Tested directly from the current default branch rather than through a released CLI:
- Commit: `ed2ac40df67a319bf348bd7e3d10494696b31b38`
- Core package: `0.61.0-nightly.20260908.gc647533d6`
- Node.js: `v22.18.0`
- OS: macOS 26.5.2, arm64
### Login information
Not applicable. The bug is reproduced by a focused unit test and does not require authentication.
### Anything else we need to know?
The fixed temporary key is defined and used in `packages/core/src/utils/envExpansion.ts:35-53`.
Focused test command:
```console
npm test -w @google/gemini-cli-core -- src/utils/envExpansion.test.ts
```
Result on the tested commit: 16 tests total, 15 passed, and the new collision regression failed because it received `unexpected override` instead of `Hello morty`.
Exact searches for `__GCLI_EXPAND_TARGET__` currently return zero issues and zero pull requests. Related reports about settings load order, missing argument expansion, and documentation describe different problems.
I can prepare a focused fix and tests after maintainers confirm that this is suitable for community contribution.
Contributor guide
Research direction
Start with packages/core/src/utils/envExpansion.ts:35-53 and the focused tests in src/utils/envExpansion.test.ts. Run npm test -w @google/gemini-cli-core -- src/utils/envExpansion.test.ts, then inspect the MCP call sites at packages/core/src/tools/mcp-client.ts:985-1002 and 2361-2374 for context. Done means the collision regression returns the expanded input and the existing tests still pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js, typescript
- Domain
- cli, testing-qa
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Clearly specified
- Newbie friendliness
- 89/100