[BUG] examples/gateway/gcp/setup.sh: CLAUDE_SHA256 pin compared case-sensitively - uppercase pins (PowerShell Get-FileHash) fail the build

Status Open
Maintainer reply None cached
Activity 1 comment · opened Aug 25, 2026

Note: This is a bug in the repo's example deployment assets (examples/gateway/gcp/setup.sh), not in the Claude Code CLI itself — so the CLI bug-form fields (version/model/terminal) don't apply. I have a tested 2-line fix ready, but external PR creation appears to be disabled on this repo (no non-maintainer PR since 2026-08-16; createPullRequest is rejected via both GraphQL and REST), so I'm filing the report here instead.

What's wrong?

examples/gateway/gcp/setup.sh accepts an optional out-of-band checksum pin, CLAUDE_SHA256, and compares it against openssl dgst output case-sensitively:

if [[ -n "${CLAUDE_SHA256}" && "$(sha_of "${CLAUDE_BINARY}")" != "${CLAUDE_SHA256}" ]]; then
  echo "ERROR: sha256 of ${CLAUDE_BINARY} does not match CLAUDE_SHA256 (${CLAUDE_SHA256}) — refusing to build." >&2
  exit 1
fi

openssl always emits lowercase hex, but some common tools publish checksums in uppercase — e.g. PowerShell's Get-FileHash. An operator who pins the correct checksum in uppercase gets a spurious "refusing to build" failure on a binary that actually verifies. The error message is misleading, because the hashes are equal apart from case.

The AWS sibling script already guards against exactly this — examples/gateway/aws/setup.sh normalizes its equivalent pin:

DIST_SHA256="${DIST_SHA256,,}"   # normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase

The GCP script has no such normalization, so the two examples silently disagree on whether an uppercase pin works.

What should happen?

A correct checksum pin should verify regardless of hex case, matching the AWS example's documented behavior.

Steps to reproduce

  1. cd examples/gateway/gcp
  2. Compute the correct sha256 of a ./claude binary in uppercase (as Get-FileHash reports it): CLAUDE_SHA256="$(openssl dgst -sha256 ./claude | awk '{print toupper($NF)}')"
  3. Run ./setup.sh far enough to reach the image build step.
  4. The script exits with ERROR: sha256 of ./claude does not match CLAUDE_SHA256 (...) — refusing to build. even though the checksum is correct.

Fix (2 lines, tested)

Normalize the pin where it is read, mirroring the AWS script's comment — but using tr rather than the bash-4-only ${VAR,,} expansion, which is itself broken on stock macOS bash 3.2 (see #82320, which converts the AWS script to this same portable idiom):

 CLAUDE_SHA256="${CLAUDE_SHA256:-}"                         # optional: out-of-band sha256 pin for the downloaded binary, checked in addition to the release manifest
+# normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase
+CLAUDE_SHA256="$(printf '%s' "${CLAUDE_SHA256}" | LC_ALL=C tr '[:upper:]' '[:lower:]')"

An empty value stays empty, so the "pin is optional" gate ([[ -n "${CLAUDE_SHA256}" ... ]]) is unchanged. Verified with bash -n and a functional check (uppercase pin normalizes and matches; empty pin still skips the check).

The commit is ready on a fork branch if PRs are re-enabled: https://github.com/Rikinshah787/claude-code/tree/fix-gcp-claude-sha256-case (compare view).

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗