Repository navigation
Stop an unused apt source being able to fail CI - #187
Merged
Merged
Conversation
bazauto
enabled auto-merge (squash)
September 9, 2026 17:48
`npx playwright install --with-deps chromium` runs `apt-get update` before installing Chromium's system libraries, and `apt-get update` fails as a whole if any configured source is broken -- including one nothing in this repo uses. The GitHub runner image ships Google's Chrome apt repo preconfigured. On 2026-09-09 that repo served a `Release` file recording SHA256 233e56de... for `main/binary-amd64/Packages.gz` while serving a `Packages.gz` whose actual SHA256 was bc1428ab..., so apt refused the index and exited 100. Confirmed by fetching both files directly, so it was Google's published metadata and not a runner or mirror artefact. Every run failed at that step, on any branch, whatever the diff. Playwright downloads its own Chromium build; only the distro packages behind it come from apt, and none of them come from Google. Removing the source is therefore the fix rather than retrying: a third party we do not depend on should not be able to fail this job, and a retry would not have helped anyway -- their index stayed inconsistent across two reruns twelve minutes apart. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
The first attempt removed /etc/apt/sources.list.d/google-chrome.list and changed nothing: the run log shows the `rm` executing and apt then fetching dl.google.com regardless. The current runner image configures that repo as a deb822 `.sources` file, not the one-line `.list` the older images used, so a fixed path was a no-op that looked like a fix. Match on content instead, which covers both formats and any future rename, and add a guard that fails the step with a clear message if an entry survives -- better than the same `Hash Sum mismatch` forty lines into apt's output, which is what sent the first attempt after the wrong file. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI has been failing on every branch since around 17:30 on 2026-09-09, at the
Install Playwright browserstep, withHash Sum mismatchand exit 100. It is not thediff on any of those branches, and it is not a flake — two reruns twelve minutes apart
failed identically.
npx playwright install --with-deps chromiumrunsapt-get updatebefore installing thesystem libraries Chromium links against.
apt-get updatefails as a whole if anyconfigured source is broken, including one nothing here uses — and the GitHub runner image
ships Google's Chrome apt repo preconfigured.
That repo is currently serving an internally inconsistent index. Fetched directly, outside
GitHub, to rule out the runner and its mirror:
So apt is right to refuse it, and the job dies before a single e2e test runs.
The fix, and why removal rather than a retry
Nothing in this repo installs Google Chrome. Playwright downloads its own Chromium build;
--with-depsonly pulls distro packages, all from Ubuntu's own archives. The Google sourcecontributes nothing to this job and can only ever subtract from it.
Removing it is therefore the fix rather than wrapping the step in a retry:
outage that will recur
sudo rm -fso the step is a no-op if a future runner image stops shipping that source.Deliberately not done here: dropping
--with-depsaltogether and relying on the runnerimage's preinstalled browser libraries. That would also dodge apt, but it trades a stated
dependency for an assumption about the image, and the next image change breaks e2e with a
missing-shared-library error rather than a clear one.
Verification
The honest check on this one is CI itself — this changes only the workflow, and the step it
fixes is the step that was failing, so a green run on this PR is the test. Locally the
workflow still parses and the job's steps are unchanged in name and order:
Nothing outside
.github/workflows/ci.ymlis touched, so no repo docs are falsified.Unblocks #186.
🤖 Generated with Claude Code
https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV