ci: let the Swagger validator's browser launch - #162
Merged
sk-portkey merged 2 commits intoSep 30, 2026
Merged
Conversation
Ubuntu 24.04 runners restrict unprivileged user namespaces via AppArmor, so the headless Chromium that char0n/swagger-editor-validate drives cannot start its sandbox and the check fails before validating anything. Lift the restriction on the ephemeral runner, and move checkout to v4. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused workflow changes correctly address the documented browser-launch failure.
Review effort: Balanced
Findings: None
What changed in this PR
Updates CI so Chromium can launch during OpenAPI validation on Ubuntu 24.04 runners.
Changes:
- Upgrades
actions/checkoutfrom v2 to v4. - Enables unprivileged user namespaces before validation.
| File | Description |
|---|---|
.github/workflows/validate-openapi.yml |
Updates checkout and configures AppArmor for Chromium. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
swaggerapi/swagger-editor:latest moved to SwaggerEditor 5. Its nginx listens on 80, not 8080, so the validator got ERR_CONNECTION_RESET, and its UI lacks the .errors-wrapper panel char0n/swagger-editor-validate parses. v4.14.8 is the last v4 release. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
akhilmmenon
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Swagger Editor Validator Service check fails on every PR, including #160, before it validates anything. The cause is the CI setup, not the spec. There were two separate problems:
char0n/swagger-editor-validatedrives a headless Chromium through Puppeteer.ubuntu-latestis now Ubuntu 24.04, where AppArmor blocks the unprivileged user namespaces Chromium's sandbox needs. A new step setskernel.apparmor_restrict_unprivileged_userns=0, which only affects the throwaway GitHub-hosted runner.swaggerapi/swagger-editor:latestis now SwaggerEditor 5. It serves on port 80, not 8080, so the check gotERR_CONNECTION_RESET. Its UI also lacks the v4.errors-wrapperpanel the action reads errors from. The service is now pinned tov4.14.8, the last v4 release.It also bumps
actions/checkoutfrom v2 to v4, since v2 runs on a deprecated Node runtime.With both fixes the check runs to completion on this PR. The log shows "Definition successfully validated by Swagger Editor" for the current
openapi.yamlonmaster.Test plan
openapi.yamlmasterinto Add /v1/decisions endpoint spec #160 and confirm its check passes🤖 Generated with Claude Code