[BUG] examples/gateway/gcp/setup.sh: CLAUDE_SHA256 pin compared case-sensitively - uppercase pins (PowerShell Get-FileHash) fail the build
Note: This is a bug in the repo's example deployment assets (examples/gateway/gcp/setup.sh), not in the Claude Code CLI itself — so the CLI bug-form fields (version/model/terminal) don't apply. I have a tested 2-line fix ready, but external PR creation appears to be disabled on this repo (no non-maintainer PR since 2026-08-16; createPullRequest is rejected via both GraphQL and REST), so I'm filing the report here instead.
What's wrong?
examples/gateway/gcp/setup.sh accepts an optional out-of-band checksum pin, CLAUDE_SHA256, and compares it against openssl dgst output case-sensitively:
if [[ -n "${CLAUDE_SHA256}" && "$(sha_of "${CLAUDE_BINARY}")" != "${CLAUDE_SHA256}" ]]; then
echo "ERROR: sha256 of ${CLAUDE_BINARY} does not match CLAUDE_SHA256 (${CLAUDE_SHA256}) — refusing to build." >&2
exit 1
fi
openssl always emits lowercase hex, but some common tools publish checksums in uppercase — e.g. PowerShell's Get-FileHash. An operator who pins the correct checksum in uppercase gets a spurious "refusing to build" failure on a binary that actually verifies. The error message is misleading, because the hashes are equal apart from case.
The AWS sibling script already guards against exactly this — examples/gateway/aws/setup.sh normalizes its equivalent pin:
DIST_SHA256="${DIST_SHA256,,}" # normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase
The GCP script has no such normalization, so the two examples silently disagree on whether an uppercase pin works.
What should happen?
A correct checksum pin should verify regardless of hex case, matching the AWS example's documented behavior.
Steps to reproduce
cd examples/gateway/gcp- Compute the correct sha256 of a
./claudebinary in uppercase (asGet-FileHashreports it):CLAUDE_SHA256="$(openssl dgst -sha256 ./claude | awk '{print toupper($NF)}')" - Run
./setup.shfar enough to reach the image build step. - The script exits with
ERROR: sha256 of ./claude does not match CLAUDE_SHA256 (...) — refusing to build.even though the checksum is correct.
Fix (2 lines, tested)
Normalize the pin where it is read, mirroring the AWS script's comment — but using tr rather than the bash-4-only ${VAR,,} expansion, which is itself broken on stock macOS bash 3.2 (see #82320, which converts the AWS script to this same portable idiom):
CLAUDE_SHA256="${CLAUDE_SHA256:-}" # optional: out-of-band sha256 pin for the downloaded binary, checked in addition to the release manifest
+# normalize to lowercase — openssl emits lowercase hex; some tools (PowerShell Get-FileHash) publish uppercase
+CLAUDE_SHA256="$(printf '%s' "${CLAUDE_SHA256}" | LC_ALL=C tr '[:upper:]' '[:lower:]')"
An empty value stays empty, so the "pin is optional" gate ([[ -n "${CLAUDE_SHA256}" ... ]]) is unchanged. Verified with bash -n and a functional check (uppercase pin normalizes and matches; empty pin still skips the check).
The commit is ready on a fork branch if PRs are re-enabled: https://github.com/Rikinshah787/claude-code/tree/fix-gcp-claude-sha256-case (compare view).
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗