# How MCP Servers Inherit Environment Variables in 5ire: A Cross-Platform Analysis

> Discover how MCP servers in 5ire inherit environment variables via a whitelist. Understand cross-platform variable management and secure host variable integration.

- Repository: [Ironben/5ire](https://github.com/nanbingxyz/5ire)
- Tags: deep-dive
- Published: 2026-03-07

---

**MCP servers in 5ire inherit environment variables through a whitelist-based system that copies only safe, OS-specific host variables—such as `PATH` and `HOME`—before merging them with server-specific configuration values and proxy settings.**

The 5ire application implements a secure, platform-aware mechanism to control how MCP (Model Context Protocol) servers access environment variables. When launching local servers via `stdio` transport, the framework explicitly filters which host environment variables are passed to the child process, preventing accidental leakage of sensitive data while ensuring cross-platform compatibility.

## Platform-Specific Environment Variable Whitelists

The core of the inheritance logic resides in `DEFAULT_INHERITED_ENV_VARS`, defined in [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts). This constant uses `process.platform` detection to determine which host variables are safe to propagate to child processes.

### Windows Environment Inheritance

On Windows (`process.platform === "win32"`), the framework whitelists system and user path variables required for application execution:

- `APPDATA`
- `HOMEDRIVE`
- `HOMEPATH`
- `LOCALAPPDATA`
- `PATH`
- `PROCESSOR_ARCHITECTURE`
- `SYSTEMDRIVE`
- `SYSTEMROOT`
- `TEMP`
- `USERNAME`
- `USERPROFILE`

These variables allow the MCP server to locate user directories, system tools, and temporary folders without exposing unrelated host environment data.

### Unix and macOS Environment Inheritance

On Unix-like platforms (Linux and macOS), the whitelist follows the conservative pattern used by `sudo` for safe environment inheritance:

- `HOME`
- `LOGNAME`
- `PATH`
- `SHELL`
- `TERM`
- `USER`

This minimal set ensures the child process can resolve executables and identify the user context while maintaining strict isolation from potentially sensitive host variables.

## The Environment Assembly Process

When 5ire instantiates a local MCP server, it constructs the final environment object through a four-step merging process implemented in the client creation logic.

### Safe Host Variables via getDefaultEnvironment()

The `getDefaultEnvironment()` function (lines 34–47 in [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts)) iterates over `DEFAULT_INHERITED_ENV_VARS` and copies values from `process.env` only if they exist and are not functions (excluding values starting with `()`). This creates a sanitized base environment containing only the OS-specific whitelist.

### Configuration Overrides and Mandatory Variables

The framework merges the safe host variables with server-specific configuration entries. According to the implementation at lines 86–94 in [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts), the final environment object is constructed as follows:

```typescript
const mergedEnv = {
  ...getDefaultEnvironment(),          // Safe host vars from whitelist
  ...env,                              // Server-specific overrides from config
  NODE_EXTRA_CA_CERTS: process.env.NODE_EXTRA_CA_CERTS,
  PATH: process.env.PATH,
  ...(proxy
    ? {
        HTTP_PROXY: validateAndGetProxy(proxy),
        HTTPS_PROXY: validateAndGetProxy(proxy),
        ALL_PROXY: validateAndGetProxy(proxy),
      }
    : {}),
};

```

**Mandatory variables** such as `NODE_EXTRA_CA_CERTS` and `PATH` are explicitly assigned to ensure the child process can locate certificates and executables regardless of whitelist restrictions.

### Proxy Configuration Handling

When a `proxy` field is supplied in the server configuration, the framework expands the environment with `HTTP_PROXY`, `HTTPS_PROXY`, and `ALL_PROXY` variables after validation through `validateAndGetProxy()`. This ensures proxy settings are only injected when explicitly configured and validated.

## Implementation in src/main/mcp.ts

The complete inheritance mechanism is orchestrated in [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts). The `DEFAULT_INHERITED_ENV_VARS` constant is defined at lines 14–30:

```typescript
// src/main/mcp.ts – OS-specific whitelist
export const DEFAULT_INHERITED_ENV_VARS =
  process.platform === "win32"
    ? [
        "APPDATA",
        "HOMEDRIVE",
        "HOMEPATH",
        "LOCALAPPDATA",
        "PATH",
        "PROCESSOR_ARCHITECTURE",
        "SYSTEMDRIVE",
        "SYSTEMROOT",
        "TEMP",
        "USERNAME",
        "USERPROFILE",
      ]
    : /* list inspired by the default env inheritance of sudo */
      ["HOME", "LOGNAME", "PATH", "SHELL", "TERM", "USER"];

```

The merged environment is then passed to the `StdioTransport` constructor when establishing the connection:

```typescript
const transport = new this.StdioTransport({
  command: cmd,
  args,
  stderr: process.platform === "win32" ? "pipe" : "inherit",
  env: mergedEnv,
});
await client.connect(transport, { timeout: CONNECT_TIMEOUT });

```

This design ensures that **remote HTTP/SSE endpoints** receive no local environment variables, while **local subprocesses** receive only the carefully curated set defined above.

## Security Benefits of Selective Inheritance

The whitelist approach prevents accidental leakage of secrets such as API keys, database URLs, or private tokens from the host environment into MCP servers. By explicitly enumerating safe variables like `PATH` and `HOME` while requiring explicit configuration for application-specific secrets, 5ire maintains strict security boundaries between the host application and external tool implementations.

## Summary

- **Platform detection** determines whether to use the Windows or Unix whitelist in `DEFAULT_INHERITED_ENV_VARS`.
- **Safe inheritance** is handled by `getDefaultEnvironment()`, which copies only whitelisted variables from `process.env`.
- **Configuration merging** allows server-specific `env` entries to override or extend the base environment at lines 86–94 of [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts).
- **Mandatory variables** including `NODE_EXTRA_CA_CERTS` and `PATH` are always included to ensure basic functionality.
- **Proxy settings** are conditionally injected after validation when the `proxy` configuration field is present.

## Frequently Asked Questions

### Which environment variables does 5ire automatically inherit on Windows?

On Windows, 5ire automatically inherits `APPDATA`, `HOMEDRIVE`, `HOMEPATH`, `LOCALAPPDATA`, `PATH`, `PROCESSOR_ARCHITECTURE`, `SYSTEMDRIVE`, `SYSTEMROOT`, `TEMP`, `USERNAME`, and `USERPROFILE`. These are defined in the `DEFAULT_INHERITED_ENV_VARS` array in [`src/main/mcp.ts`](https://github.com/nanbingxyz/5ire/blob/main/src/main/mcp.ts) when `process.platform === "win32"`.

### How does 5ire handle custom environment variables for MCP servers?

Custom variables defined in the server's `env` configuration field are merged with the whitelisted host variables during client initialization. These configuration values take precedence over inherited host variables, allowing users to override specific settings or inject application secrets explicitly.

### Are proxy settings automatically inherited by MCP servers in 5ire?

Proxy settings are not automatically inherited from the host environment. Instead, they must be explicitly configured via the `proxy` field in the server configuration. When provided, 5ire validates the proxy URL and injects `HTTP_PROXY`, `HTTPS_PROXY`, and `ALL_PROXY` into the environment object before spawning the process.

### Why does 5ire use a whitelist instead of inheriting all environment variables?

The whitelist approach prevents accidental leakage of sensitive host data such as API keys, authentication tokens, or database credentials into untrusted MCP servers. By selectively copying only necessary system variables like `PATH` and `HOME`, 5ire maintains security isolation while providing sufficient context for the child process to function correctly across different operating systems.