Skip to content

Stop an unused apt source being able to fail CI - #187

Merged
bazauto merged 2 commits into
mainfrom
ci/drop-unused-chrome-apt-source
Sep 9, 2026
Merged

bazauto merged 2 commits into
mainfrom
ci/drop-unused-chrome-apt-source

Conversation

@bazauto

@bazauto bazauto commented Sep 9, 2026

Copy link
Copy Markdown
Owner

CI has been failing on every branch since around 17:30 on 2026-09-09, at the
Install Playwright browser step, with Hash Sum mismatch and exit 100. It is not the
diff on any of those branches, and it is not a flake — two reruns twelve minutes apart
failed identically.

npx playwright install --with-deps chromium runs apt-get update before installing the
system libraries Chromium links against. apt-get update fails as a whole if any
configured source is broken, including one nothing here uses — and the GitHub runner image
ships Google's Chrome apt repo preconfigured.

That repo is currently serving an internally inconsistent index. Fetched directly, outside
GitHub, to rule out the runner and its mirror:

Release claims  SHA256 233e56de019b57db89238fa7bcc3647718dbbea3a40c2dc1c633a8c8952aa9e9
Actually served SHA256 bc1428ab27c6d76ee9bb76de07f1ded0ddb4aaabd958fc72855634ef5894a4b3
                       (main/binary-amd64/Packages.gz, both 1405 bytes)

So apt is right to refuse it, and the job dies before a single e2e test runs.

The fix, and why removal rather than a retry

Nothing in this repo installs Google Chrome. Playwright downloads its own Chromium build;
--with-deps only pulls distro packages, all from Ubuntu's own archives. The Google source
contributes nothing to this job and can only ever subtract from it.

Removing it is therefore the fix rather than wrapping the step in a retry:

  • a retry would not have helped — the index stayed inconsistent across both reruns
  • a third party the build does not depend on should not be able to fail the build
  • it is one line, and it removes the dependency permanently rather than papering over an
    outage that will recur

sudo rm -f so the step is a no-op if a future runner image stops shipping that source.

Deliberately not done here: dropping --with-deps altogether and relying on the runner
image's preinstalled browser libraries. That would also dodge apt, but it trades a stated
dependency for an assumption about the image, and the next image change breaks e2e with a
missing-shared-library error rather than a clear one.

Verification

The honest check on this one is CI itself — this changes only the workflow, and the step it
fixes is the step that was failing, so a green run on this PR is the test. Locally the
workflow still parses and the job's steps are unchanged in name and order:

Use Node.js / Install dependencies / Lint / Run tests / Build backend /
Build frontend / Install Playwright browser / Run e2e tests / Upload Playwright evidence

Nothing outside .github/workflows/ci.yml is touched, so no repo docs are falsified.

Unblocks #186.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV

@bazauto
bazauto enabled auto-merge (squash) September 9, 2026 17:48
bazauto and others added 2 commits September 9, 2026 18:48
`npx playwright install --with-deps chromium` runs `apt-get update`
before installing Chromium's system libraries, and `apt-get update`
fails as a whole if any configured source is broken -- including one
nothing in this repo uses.

The GitHub runner image ships Google's Chrome apt repo preconfigured. On
2026-09-09 that repo served a `Release` file recording SHA256
233e56de... for `main/binary-amd64/Packages.gz` while serving a
`Packages.gz` whose actual SHA256 was bc1428ab..., so apt refused the
index and exited 100. Confirmed by fetching both files directly, so it
was Google's published metadata and not a runner or mirror artefact.
Every run failed at that step, on any branch, whatever the diff.

Playwright downloads its own Chromium build; only the distro packages
behind it come from apt, and none of them come from Google. Removing
the source is therefore the fix rather than retrying: a third party we
do not depend on should not be able to fail this job, and a retry would
not have helped anyway -- their index stayed inconsistent across two
reruns twelve minutes apart.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
The first attempt removed /etc/apt/sources.list.d/google-chrome.list and
changed nothing: the run log shows the `rm` executing and apt then
fetching dl.google.com regardless. The current runner image configures
that repo as a deb822 `.sources` file, not the one-line `.list` the
older images used, so a fixed path was a no-op that looked like a fix.

Match on content instead, which covers both formats and any future
rename, and add a guard that fails the step with a clear message if an
entry survives -- better than the same `Hash Sum mismatch` forty lines
into apt's output, which is what sent the first attempt after the wrong
file.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
@bazauto
bazauto merged commit 24d82b4 into main Sep 9, 2026
1 check passed
@bazauto
bazauto deleted the ci/drop-unused-chrome-apt-source branch September 9, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant