Repository navigation
fix(ci): verify managed-settings.json without runner-shell quote stripping - #100
Merged
Merged
Conversation
…pping The verify-command added in #99 embedded literal " around the expected path inside a single-quoted jq filter. After GHA expansion into bash -c "...", the inner " terminated and reopened the outer "..." rather than reaching jq as a string delimiter, so jq received .hooks.SessionStart[0].hooks[0].command == /usr/local/bin/patch-playwright-mcp and failed with "unexpected '/'". Switch to the printenv | grep -qx idiom used since #93: jq -r prints the bare string value, grep -qx asserts an exact match. No literal " inside the matrix value, so the value survives both the YAML decode and the bash -c wrapping unchanged.
4 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Rewrites the
jqassertion that PR #99 added to theverifymatrix inbuild-claude-code.ymlso it survives GitHub Actions' template expansion +bash -cwrapping.Why
PR #99 merged green on PRs but the post-merge
Build claude-coderun failed all four verify legs (run 25765306805) with:Root cause: the matrix value contained a literal
"…"inside a single-quoted jq filter. After GHA expands${{ matrix.verify-command }}intodocker run … bash -c "${{ matrix.verify-command }}"the outer
"…"is the shell's double-quote context, so the inner"characters closed and reopened the outer string rather than reaching jq as string delimiters. By the timebash -cparsed the filter, the comparison value was an unquoted bare token starting with/, and jq rejected it.This is the same class of bug PR #93 fixed for
AGENT_BROWSER_EXECUTABLE_PATH. The fix is the same: emit the value withjq -r(raw string, no surrounding quotes) and assert the match viagrep -qx, so no"ever appears in the matrix value.Changes
.github/workflows/build-claude-code.yml— all four verify-command rows:jq -e '.hooks.SessionStart[0].hooks[0].command == \"/usr/local/bin/patch-playwright-mcp\"' /etc/claude-code/managed-settings.json >/dev/nulljq -r '.hooks.SessionStart[0].hooks[0].command' /etc/claude-code/managed-settings.json | grep -qx /usr/local/bin/patch-playwright-mcpNotes
jq -rerrors if the file is missing), parses as JSON, contains.hooks.SessionStart[0].hooks[0].command, and the value equals the patch binary path exactly.managed-settings.json(e.g. matcher added, hook moved to position 1) — that's the same fragility the previous version had, intentional for now since the file's shape is the contract.Test plan
actionlintclean.bash -c "<value>"locally with the YAML-decoded matrix string against a copy ofmanaged-settings.json— predicate exits 0.Build claude-coderun on merge — all four verify legs (claude-code/claude-code-sandbox × amd64/arm64) should pass.Follow-up to #99; recovers the master build.