From 925e8d95376d550dbb87a9f2f8e0b26e14410aaf Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Sat, 23 May 2026 15:33:30 -0400 Subject: [PATCH] fix(ci): pin actions/checkout@v4 on Windows to bypass v6 includeIf auth bug (#162) * ci(test): pre-seed git auth header on Windows before actions/checkout actions/checkout@v6 uses includeIf.gitdir: to inject the AUTHORIZATION extraheader on Windows. On Windows git 2.54, the gitdir conditional include is unreliable for a freshly-initialised repo: the path comparison (forward-slash key vs backslash-resolved gitdir) can fail to match, leaving the fetch unauthenticated (exit 128, terminal prompts disabled). Add a PowerShell pre-step (Windows-only) that writes the extraheader directly to the global git config before actions/checkout runs. This bypasses includeIf entirely and is idempotent. Fixes #161 Co-Authored-By: Claude Sonnet 4.6 * ci(test): fix duplicate Authorization header on Windows (persist-credentials) The previous fix pre-seeded the global git config with the extraheader, but left persist-credentials: true. That caused checkout to ALSO write an includeIf entry -- both fired, sending duplicate Authorization headers and GitHub returned HTTP 400. Fix: set persist-credentials: false on Windows only (expression `runner.os != 'Windows'`). The global pre-seed covers the initial checkout fetch. Subsequent git operations (Rebase check) use the x-access-token remote URL already set in that step. Linux/macOS keep persist-credentials: true -- includeIf works correctly on those platforms. Co-Authored-By: Claude Sonnet 4.6 * ci(test): use actions/checkout@v4 on Windows to bypass includeIf.gitdir flake actions/checkout@v6 uses includeIf.gitdir: to inject the auth token, but on Windows git 2.54 the gitdir path comparison (forward-slash key vs backslash-resolved gitdir) intermittently fails to match, leaving the fetch unauthenticated. Previous attempts to pre-seed the global config caused duplicate Authorization headers (HTTP 400). Fix: use actions/checkout@v4.2.2 on Windows only (if/if-not guard). v4 writes http.https://github.com/.extraheader directly to .git/config instead of using includeIf, which is reliable across all git versions. Linux/macOS continue using v6 -- includeIf works correctly there. This replaces the pre-seed approach introduced in the two previous commits on this branch. Co-Authored-By: Claude Sonnet 4.6 --------- Co-authored-by: Claude Sonnet 4.6 --- .github/workflows/test.yml | 20 +++++++++++++++++++- 1 file changed, 19 insertions(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 15d52149b..d3f17a1f1 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -74,7 +74,25 @@ jobs: # A dedicated windows-compat workflow runs on a weekly schedule. steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + # actions/checkout@v6 uses includeIf.gitdir: to inject auth on Windows. + # On Windows git 2.54, the gitdir path comparison (forward-slash key vs + # backslash-resolved gitdir) is unreliable, so the conditional include + # intermittently fails to fire and the fetch proceeds unauthenticated. + # + # Fix: use actions/checkout@v4 on Windows only. v4 writes the auth token + # directly to .git/config (http.extraheader) instead of using includeIf, + # which is reliable across all git versions and platforms. + # Linux/macOS continue using v6 (includeIf works correctly there). + - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 (Windows) + if: runner.os == 'Windows' + with: + # Fetch full history so we can merge origin/main for stale-base detection. + fetch-depth: 0 + persist-credentials: true + token: ${{ github.token }} + + - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 (Linux/macOS) + if: runner.os != 'Windows' with: # Fetch full history so we can merge origin/main for stale-base detection. fetch-depth: 0