Repository navigation
fix(ci): verify AGENT_BROWSER_EXECUTABLE_PATH without runner-shell expansion - #93
Merged
Merged
Conversation
…pansion The verify-command from #92 used `test "$AGENT_BROWSER_EXECUTABLE_PATH" = /usr/bin/chromium`. When GitHub Actions interpolates that string into `bash -c "..."`, the runner's bash expands `$AGENT_BROWSER_EXECUTABLE_PATH` from the **runner's** environment (where it's unset) before docker runs, leaving the container's bash to evaluate `test = /usr/bin/chromium` — malformed, exit 2. Replace with `printenv AGENT_BROWSER_EXECUTABLE_PATH | grep -qx /usr/bin/chromium`. No shell metacharacters in the substituted string, so the runner shell has nothing to expand; the entire command reaches the container's bash intact, and `printenv` reads the env var from inside the container. Verified end-to-end against the published image — exits 0 with the expected env var, exits 1 if unset. The image's ENV instruction itself was correct (confirmed via `docker inspect`); only the CI verify step was broken.
2 of 3 tasks
gatezh
added a commit
that referenced
this pull request
May 13, 2026
…pping (#100) The verify-command added in #99 embedded literal " around the expected path inside a single-quoted jq filter. After GHA expansion into bash -c "...", the inner " terminated and reopened the outer "..." rather than reaching jq as a string delimiter, so jq received .hooks.SessionStart[0].hooks[0].command == /usr/local/bin/patch-playwright-mcp and failed with "unexpected '/'". Switch to the printenv | grep -qx idiom used since #93: jq -r prints the bare string value, grep -qx asserts an exact match. No literal " inside the matrix value, so the value survives both the YAML decode and the bash -c wrapping unchanged.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Hotfix the failing
Verify claude-code (amd64)andVerify claude-code (arm64)stages introduced in #92. Image is fine — only the verify step was broken.Why
#92 added this to the default-target verify command:
When GitHub Actions interpolates
\${{ matrix.verify-command }}into the workflow'sbash -c "..."invocation, the runner's bash sees$AGENT_BROWSER_EXECUTABLE_PATHand expands it before docker runs — but the env var is set in the container, not the runner. So the runner expands it to empty string, and the container's bash receivestest = /usr/bin/chromium(with an empty argument), which fails withbash: line 1: test: =: unary operator expected.Reproduced from the failure log:
Fix
Replace
test "$VAR" = /valuewithprintenv VAR | grep -qx /value. Theprintenv-pipe form has zero shell metacharacters in the substituted string — the runner's shell has nothing to expand, so the entire command reaches the container's bash intact, andprintenvreads the env var from inside the container.Verification
The image itself is correct — the
ENVinstruction took effect:End-to-end test of the new verify command against the live image:
Exit 0 with the env var set; exit 1 if it were unset (
printenvexits non-zero on missing var, breaking the pipeline).Notes
Sandbox-target verify lines unchanged — they don't reference
\$AGENT_BROWSER_EXECUTABLE_PATH(agent-browser isn't installed there).This is the kind of bug that's invisible in static YAML parsing — the rendered
bash -cstring parses fine; the issue is only in which shell processes the$VARreference. Lesson noted for future env-var verifies: preferprintenvovertest "\$VAR"to keep the boundary clean.