fix(ci): pin actions/checkout@v4 on Windows to bypass v6 includeIf auth bug (#162)
* ci(test): pre-seed git auth header on Windows before actions/checkout actions/checkout@v6 uses includeIf.gitdir: to inject the AUTHORIZATION extraheader on Windows. On Windows git 2.54, the gitdir conditional include is unreliable for a freshly-initialised repo: the path comparison (forward-slash key vs backslash-resolved gitdir) can fail to match, leaving the fetch unauthenticated (exit 128, terminal prompts disabled). Add a PowerShell pre-step (Windows-only) that writes the extraheader directly to the global git config before actions/checkout runs. This bypasses includeIf entirely and is idempotent. Fixes #161 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * ci(test): fix duplicate Authorization header on Windows (persist-credentials) The previous fix pre-seeded the global git config with the extraheader, but left persist-credentials: true. That caused checkout to ALSO write an includeIf entry -- both fired, sending duplicate Authorization headers and GitHub returned HTTP 400. Fix: set persist-credentials: false on Windows only (expression `runner.os != 'Windows'`). The global pre-seed covers the initial checkout fetch. Subsequent git operations (Rebase check) use the x-access-token remote URL already set in that step. Linux/macOS keep persist-credentials: true -- includeIf works correctly on those platforms. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * ci(test): use actions/checkout@v4 on Windows to bypass includeIf.gitdir flake actions/checkout@v6 uses includeIf.gitdir: to inject the auth token, but on Windows git 2.54 the gitdir path comparison (forward-slash key vs backslash-resolved gitdir) intermittently fails to match, leaving the fetch unauthenticated. Previous attempts to pre-seed the global config caused duplicate Authorization headers (HTTP 400). Fix: use actions/checkout@v4.2.2 on Windows only (if/if-not guard). v4 writes http.https://github.com/.extraheader directly to .git/config instead of using includeIf, which is reliable across all git versions. Linux/macOS continue using v6 -- includeIf works correctly there. This replaces the pre-seed approach introduced in the two previous commits on this branch. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
20
.github/workflows/test.yml
vendored
20
.github/workflows/test.yml
vendored
@@ -74,7 +74,25 @@ jobs:
|
||||
# A dedicated windows-compat workflow runs on a weekly schedule.
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
||||
# actions/checkout@v6 uses includeIf.gitdir: to inject auth on Windows.
|
||||
# On Windows git 2.54, the gitdir path comparison (forward-slash key vs
|
||||
# backslash-resolved gitdir) is unreliable, so the conditional include
|
||||
# intermittently fails to fire and the fetch proceeds unauthenticated.
|
||||
#
|
||||
# Fix: use actions/checkout@v4 on Windows only. v4 writes the auth token
|
||||
# directly to .git/config (http.extraheader) instead of using includeIf,
|
||||
# which is reliable across all git versions and platforms.
|
||||
# Linux/macOS continue using v6 (includeIf works correctly there).
|
||||
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 (Windows)
|
||||
if: runner.os == 'Windows'
|
||||
with:
|
||||
# Fetch full history so we can merge origin/main for stale-base detection.
|
||||
fetch-depth: 0
|
||||
persist-credentials: true
|
||||
token: ${{ github.token }}
|
||||
|
||||
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 (Linux/macOS)
|
||||
if: runner.os != 'Windows'
|
||||
with:
|
||||
# Fetch full history so we can merge origin/main for stale-base detection.
|
||||
fetch-depth: 0
|
||||
|
||||
Reference in New Issue
Block a user