fix(ci): pin actions/checkout@v4 on Windows to bypass v6 includeIf auth bug (#162)

* ci(test): pre-seed git auth header on Windows before actions/checkout

actions/checkout@v6 uses includeIf.gitdir: to inject the AUTHORIZATION
extraheader on Windows. On Windows git 2.54, the gitdir conditional
include is unreliable for a freshly-initialised repo: the path comparison
(forward-slash key vs backslash-resolved gitdir) can fail to match,
leaving the fetch unauthenticated (exit 128, terminal prompts disabled).

Add a PowerShell pre-step (Windows-only) that writes the extraheader
directly to the global git config before actions/checkout runs. This
bypasses includeIf entirely and is idempotent.

Fixes #161

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci(test): fix duplicate Authorization header on Windows (persist-credentials)

The previous fix pre-seeded the global git config with the extraheader,
but left persist-credentials: true. That caused checkout to ALSO write
an includeIf entry -- both fired, sending duplicate Authorization
headers and GitHub returned HTTP 400.

Fix: set persist-credentials: false on Windows only (expression
`runner.os != 'Windows'`). The global pre-seed covers the initial
checkout fetch. Subsequent git operations (Rebase check) use the
x-access-token remote URL already set in that step.

Linux/macOS keep persist-credentials: true -- includeIf works correctly
on those platforms.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci(test): use actions/checkout@v4 on Windows to bypass includeIf.gitdir flake

actions/checkout@v6 uses includeIf.gitdir: to inject the auth token,
but on Windows git 2.54 the gitdir path comparison (forward-slash key
vs backslash-resolved gitdir) intermittently fails to match, leaving
the fetch unauthenticated. Previous attempts to pre-seed the global
config caused duplicate Authorization headers (HTTP 400).

Fix: use actions/checkout@v4.2.2 on Windows only (if/if-not guard).
v4 writes http.https://github.com/.extraheader directly to .git/config
instead of using includeIf, which is reliable across all git versions.
Linux/macOS continue using v6 -- includeIf works correctly there.

This replaces the pre-seed approach introduced in the two previous
commits on this branch.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-05-23 15:33:30 -04:00
committed by GitHub
parent 3f9eb43054
commit 925e8d9537

View File

@@ -74,7 +74,25 @@ jobs:
# A dedicated windows-compat workflow runs on a weekly schedule.
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# actions/checkout@v6 uses includeIf.gitdir: to inject auth on Windows.
# On Windows git 2.54, the gitdir path comparison (forward-slash key vs
# backslash-resolved gitdir) is unreliable, so the conditional include
# intermittently fails to fire and the fetch proceeds unauthenticated.
#
# Fix: use actions/checkout@v4 on Windows only. v4 writes the auth token
# directly to .git/config (http.extraheader) instead of using includeIf,
# which is reliable across all git versions and platforms.
# Linux/macOS continue using v6 (includeIf works correctly there).
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 (Windows)
if: runner.os == 'Windows'
with:
# Fetch full history so we can merge origin/main for stale-base detection.
fetch-depth: 0
persist-credentials: true
token: ${{ github.token }}
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 (Linux/macOS)
if: runner.os != 'Windows'
with:
# Fetch full history so we can merge origin/main for stale-base detection.
fetch-depth: 0