Skip to content

fix(ci): verify AGENT_BROWSER_EXECUTABLE_PATH without runner-shell expansion - #93

Merged
gatezh merged 1 commit into
masterfrom
fix-ci-verify-env-expansion
Apr 30, 2026
Merged

gatezh merged 1 commit into
masterfrom
fix-ci-verify-env-expansion

Conversation

@gatezh

@gatezh gatezh commented Apr 30, 2026

Copy link
Copy Markdown
Owner

What

Hotfix the failing Verify claude-code (amd64) and Verify claude-code (arm64) stages introduced in #92. Image is fine — only the verify step was broken.

Why

#92 added this to the default-target verify command:

test "$AGENT_BROWSER_EXECUTABLE_PATH" = /usr/bin/chromium

When GitHub Actions interpolates \${{ matrix.verify-command }} into the workflow's bash -c "..." invocation, the runner's bash sees $AGENT_BROWSER_EXECUTABLE_PATH and expands it before docker runs — but the env var is set in the container, not the runner. So the runner expands it to empty string, and the container's bash receives test = /usr/bin/chromium (with an empty argument), which fails with bash: line 1: test: =: unary operator expected.

Reproduced from the failure log:

bash: line 1: test: =: unary operator expected
##[error]Process completed with exit code 2.

Fix

Replace test "$VAR" = /value with printenv VAR | grep -qx /value. The printenv-pipe form has zero shell metacharacters in the substituted string — the runner's shell has nothing to expand, so the entire command reaches the container's bash intact, and printenv reads the env var from inside the container.

Verification

The image itself is correct — the ENV instruction took effect:

$ docker inspect ghcr.io/gatezh/devcontainers/claude-code:latest --format '{{range .Config.Env}}{{println .}}{{end}}' | grep AGENT_BROWSER
AGENT_BROWSER_EXECUTABLE_PATH=/usr/bin/chromium

End-to-end test of the new verify command against the live image:

$ docker run --rm ghcr.io/gatezh/devcontainers/claude-code:latest bash -c "... && printenv AGENT_BROWSER_EXECUTABLE_PATH | grep -qx /usr/bin/chromium" && echo "EXIT=\$?"
2.1.123 (Claude Code)
2026.4.28 linux-arm64 (2026-04-30)
fish, version 4.0.2
rtk 0.38.0
ralphex v1.0.1-0a54e09-20260421T215012
EXIT=0

Exit 0 with the env var set; exit 1 if it were unset (printenv exits non-zero on missing var, breaking the pipeline).

Notes

Sandbox-target verify lines unchanged — they don't reference \$AGENT_BROWSER_EXECUTABLE_PATH (agent-browser isn't installed there).

This is the kind of bug that's invisible in static YAML parsing — the rendered bash -c string parses fine; the issue is only in which shell processes the $VAR reference. Lesson noted for future env-var verifies: prefer printenv over test "\$VAR" to keep the boundary clean.

…pansion

The verify-command from #92 used `test "$AGENT_BROWSER_EXECUTABLE_PATH" = /usr/bin/chromium`. When GitHub Actions interpolates that string into `bash -c "..."`, the runner's bash expands `$AGENT_BROWSER_EXECUTABLE_PATH` from the **runner's** environment (where it's unset) before docker runs, leaving the container's bash to evaluate `test  = /usr/bin/chromium` — malformed, exit 2.

Replace with `printenv AGENT_BROWSER_EXECUTABLE_PATH | grep -qx /usr/bin/chromium`. No shell metacharacters in the substituted string, so the runner shell has nothing to expand; the entire command reaches the container's bash intact, and `printenv` reads the env var from inside the container.

Verified end-to-end against the published image — exits 0 with the expected env var, exits 1 if unset. The image's ENV instruction itself was correct (confirmed via `docker inspect`); only the CI verify step was broken.
@gatezh
gatezh merged commit 7e52b0b into master Apr 30, 2026
8 checks passed
gatezh added a commit that referenced this pull request May 13, 2026
…pping (#100)

The verify-command added in #99 embedded literal " around the expected path
inside a single-quoted jq filter. After GHA expansion into bash -c "...",
the inner " terminated and reopened the outer "..." rather than reaching
jq as a string delimiter, so jq received

    .hooks.SessionStart[0].hooks[0].command == /usr/local/bin/patch-playwright-mcp

and failed with "unexpected '/'". Switch to the printenv | grep -qx idiom
used since #93: jq -r prints the bare string value, grep -qx asserts an
exact match. No literal " inside the matrix value, so the value survives
both the YAML decode and the bash -c wrapping unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant