anthropics / anthropics/claude-code

[BUG] examples/gateway/gcp/setup.sh: CLAUDE_SHA256 pin compared case-sensitively - uppercase pins (PowerShell Get-FileHash) fail the build

オープン 初心者向け
#89,402 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:installation bug has repro
主要言語
Python
スター
145k
フォーク
23.1k
PR マージ指標
PR 指標を取得中

説明

**Note:** This is a bug in the repo's example deployment assets (`examples/gateway/gcp/setup.sh`), not in the Claude Code CLI itself — so the CLI bug-form fields (version/model/terminal) don't apply. I have a tested 2-line fix ready, but external PR creation appears to be disabled on this repo (no non-maintainer PR since 2026-08-16; `createPullRequest` is rejected via both GraphQL and REST), so I'm filing the report here instead.

## What's wrong?

`examples/gateway/gcp/setup.sh` accepts an optional out-of-band checksum pin, `CLAUDE_SHA256`, and compares it against `openssl dgst` output **case-sensitively**:

```bash
if [[ -n "${CLAUDE_SHA256}" && "$(sha_of "${CLAUDE_BINARY}")" != "${CLAUDE_SHA256}" ]]; then
echo "ERROR: sha256 of ${CLAUDE_BINARY} does not match CLAUDE_SHA256 (${CLAUDE_SHA256}) — refusing to build." >&2
exit 1
fi
```

`openssl` always emits lowercase hex, but some common tools publish checksums in uppercase — e.g. PowerShell's `Get-FileHash`. An operator who pins the **correct** checksum in uppercase gets a spurious "refusing to build" failure on a binary that actually verifies. The error message is misleading, because the hashes are equal apart from case.

The AWS sibling script already guards against exactly this — `examples/gateway/aws/setup.sh` normalizes its equivalent pin:

```bash
DIST_SHA256="${DIST_SHA256,,}" # normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase
```

The GCP script has no such normalization, so the two examples silently disagree on whether an uppercase pin works.

## What should happen?

A correct checksum pin should verify regardless of hex case, matching the AWS example's documented behavior.

## Steps to reproduce

1. `cd examples/gateway/gcp`
2. Compute the correct sha256 of a `./claude` binary in uppercase (as `Get-FileHash` reports it): `CLAUDE_SHA256="$(openssl dgst -sha256 ./claude | awk '{print toupper($NF)}')"`
3. Run `./setup.sh` far enough to reach the image build step.
4. The script exits with `ERROR: sha256 of ./claude does not match CLAUDE_SHA256 (...) — refusing to build.` even though the checksum is correct.

## Fix (2 lines, tested)

Normalize the pin where it is read, mirroring the AWS script's comment — but using `tr` rather than the bash-4-only `${VAR,,}` expansion, which is itself broken on stock macOS bash 3.2 (see #82320, which converts the AWS script to this same portable idiom):

```diff
CLAUDE_SHA256="${CLAUDE_SHA256:-}" # optional: out-of-band sha256 pin for the downloaded binary, checked in addition to the release manifest
+# normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase
+CLAUDE_SHA256="$(printf '%s' "${CLAUDE_SHA256}" | LC_ALL=C tr '[:upper:]' '[:lower:]')"
```

An empty value stays empty, so the "pin is optional" gate (`[[ -n "${CLAUDE_SHA256}" ... ]]`) is unchanged. Verified with `bash -n` and a functional check (uppercase pin normalizes and matches; empty pin still skips the check).

The commit is ready on a fork branch if PRs are re-enabled: https://github.com/Rikinshah787/claude-code/tree/fix-gcp-claude-sha256-case ([compare view](https://github.com/anthropics/claude-code/compare/main...Rikinshah787:claude-code:fix-gcp-claude-sha256-case)).

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

Read examples/gateway/gcp/setup.sh at the CLAUDE_SHA256 assignment and checksum comparison, then compare the normalization already used in examples/gateway/aws/setup.sh. Run bash -n and the functional checks described in the issue; done means uppercase pins verify successfully while an empty optional pin still skips the check.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
bash, gcp, shell
領域
cloud, devops, infrastructure
issue の種類
バグ
難易度
1/5
見積もり時間
1時間未満
活発さ
活発
明瞭さ
明確に書かれている
初心者へのやさしさ
84/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。