Repository navigation
fix(setup-stack): authenticate the sparse-workspace heal with the job token - #97
Merged
Merged
Conversation
… token A sparse workspace left on a self-hosted runner is also a blob-less partial clone, so `git sparse-checkout disable` lazily fetches the missing blobs. Checkouts no longer persist credentials, so on a private repo that fetch failed with "could not read Username" and exit 128, failing the job before any phase ran. The job token now reaches that one git command through GIT_CONFIG_* env, never .git/config or argv, and a heal that still fails says what to do. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
🎉 This PR is included in version 1.16.2 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The sparse-workspace heal added in #94 fails on private repos. A self-hosted workspace left sparse by an earlier job is also a blob-less partial clone. So
git sparse-checkout disablelazily fetches every blob outside the old sparse set from the promisor remote. Checkouts no longer persist credentials, so that fetch has none:The job fails in
setup-stack, before install or any phase runs, on whichever runner has such a workspace.Fix
github.token, which already hascontents: readon the checked-out repo) reaches only thesparse-checkout disablecall, as anhttp.<server>/.extraheaderpassed throughGIT_CONFIG_COUNT/KEY/VALUEenv. It is never written to.git/config, so the "no persisted credentials" rule still holds, and it never appears in argv, where another job on the same machine could see it withps.base64 | tr -d '\n'because BSDbase64on a macOS runner has no-w0.Verification
Reproduced locally against a private repo over HTTPS: a
--filter=blob:noneclone with a non-cone sparse checkout andcore.sparseCheckout=truein.git/config(the layout git 2.43 leaves), no stored credentials, andGIT_TERMINAL_PROMPT=0. The step's script was taken straight fromaction.ymlwithyq..git/config/ logzizmor (
--min-severity informational), shellcheck on the step script, typos, andactions/setup-stack/test.sh(24/24) all pass.Not changed
Newer git (2.55 in my test) can write
core.sparseCheckouttoconfig.worktree, where the--localprobe does not look. That only matters once a self-hosted runner upgrades its git, and it deserves its own change.🤖 Generated with Claude Code