You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GitHub Actions Checkout v4 Windows环境间歇性LFS授权失败求助

Windows Runner上actions/checkout@v4拉取LFS仓库间歇性授权错误修复

问题概述

在Windows Runner(标签myWINA3,归属Shared2组)上使用GitHub PowerShell工作流拉取含Git LFS对象的仓库时,actions/checkout@v4动作间歇性抛出LFS授权错误。关闭lfs: true可规避问题,但业务需要启用LFS拉取对象。

复现工作流

name: Testcheckout - AD
on:
  workflow_dispatch:

jobs:
  setvars:
    runs-on:
      group: Shared2
      labels: myWINA3
    outputs:
      runner_name: ${{ runner.name }} 
    steps:
      - name: Checkout User Repo
        uses: actions/checkout@v4
        with:
          ref: "${{ github.ref }}"
          lfs: true
          fetch-depth: 1
          ssh-strict: false
          token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"

错误日志

Run actions/checkout@v4
  with:
    repository: userbank/userrepo
    ref: refs/heads/release/RELEASE_2024_OCT_24
    path: D:\A\3\_work\userrepo\userrepo\userrepo
    lfs: true
    fetch-depth: 1
    ssh-strict: false
    token: ***
    ssh-user: git
    persist-credentials: true
    clean: true
    sparse-checkout-cone-mode: true
    fetch-tags: false
    show-progress: true
    submodules: false
    set-safe-directory: true
  env:
    repodirexists: false
    devtoken: ***
Syncing repository: userbank/userrepo
Getting Git version info
Copying 'C:\Users\autobuild\.gitconfig' to 'D:\A\3\_work\_temp\7d866ea3-512c-44a6-92e5-d3bf9149ee80\.gitconfig'
Temporarily overriding HOME='D:\A\3\_work\_temp\7d866ea3-512c-44a6-92e5-d3bf9149ee80' before making global git config changes
Adding repository directory to the temporary git global config as a safe directory
"C:\Program Files\Git\cmd\git.exe" config --global --add safe.directory D:\A\3\_work\userrepo\userrepo\userrepo
"C:\Program Files\Git\cmd\git.exe" config --local --get remote.origin.url
https://github.com/userbank/userbank/userrepo.git
Deleting the contents of 'D:\A\3\_work\userrepo\userrepo\userrepo'
Initializing the repository
Disabling automatic garbage collection
Setting up auth
"C:\Program Files\Git\cmd\git.exe" lfs install --local
Updated Git hooks.
Git LFS initialized.
Fetching the repository
  "C:\Program Files\Git\cmd\git.exe" -c protocol.version=2 fetch --no-tags --prune --no-recurse-submodules --depth=1 origin +refs/heads/release/RELEASE_2024_OCT_24:refs/remotes/origin/release/RELEASE_2024_OCT_24
  From https://github.com//userbank/userrepo
   * [new branch]      release/RELEASE_2024_OCT_24 -> origin/release/RELEASE_2024_OCT_24
Determining the checkout info
Fetching LFS objects
  "C:\Program Files\Git\cmd\git.exe" lfs fetch origin refs/remotes/origin/release/RELEASE_2024_OCT_24
  fetch: Fetching reference refs/remotes/origin/release/RELEASE_2024_OCT_24
  batch response: Authorization error: ***github.com//userbank/userrepo.git/info/lfs/objects/batch
  Check that you have proper access to the repository
  Error: error: failed to fetch some objects from '***github.com//userbank/userrepo.git/info/lfs'
  The process 'C:\Program Files\Git\cmd\git.exe' failed with exit code 2

已尝试的无效操作

- name: Github Clean Up Old Connections
  run: |
    Write-Host "Clean Up Old Connections"
    git config --global --unset-all http.https://github.com/.extraheader
    git config --global --unset-all core.sshCommand
    git lfs install
  shell: Powershell

环境信息

Git版本:git version 2.46.0.windows.1

永久修复方案

方案1:显式配置Git LFS认证信息

在actions/checkout步骤前添加LFS认证配置,确保拉取时使用指定token,同时禁用认证信息持久化避免残留干扰:

- name: Configure Git LFS Authentication
  run: |
    git config --global lfs.url "https://github.com/userbank/userrepo.git/info/lfs"
    git config --global lfs.token "${{ secrets.ARE_AUTOMATED_TOKEN }}"
  shell: PowerShell

- name: Checkout User Repo
  uses: actions/checkout@v4
  with:
    ref: "${{ github.ref }}"
    lfs: true
    fetch-depth: 1
    ssh-strict: false
    token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"
    persist-credentials: false

方案2:手动触发LFS拉取(规避checkout自动拉取的认证问题)

关闭checkout的自动LFS拉取,手动完成LFS对象的获取和检出,全程控制认证逻辑:

- name: Checkout User Repo
  uses: actions/checkout@v4
  with:
    ref: "${{ github.ref }}"
    lfs: false
    fetch-depth: 1
    ssh-strict: false
    token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"
    persist-credentials: false

- name: Fetch and Checkout LFS Objects
  run: |
    # 配置Git凭证存储,让LFS拉取时自动使用token
    git config --local credential.helper store
    echo "https://x-access-token:${{ secrets.ARE_AUTOMATED_TOKEN }}@github.com" | Out-File -FilePath "$env:USERPROFILE\.git-credentials" -Encoding utf8
    # 初始化LFS并拉取对象
    git lfs install --local
    git lfs fetch origin "${{ github.ref }}"
    git lfs checkout
  shell: PowerShell

方案3:彻底清理Runner上的Git全局配置残留

在工作流开头添加更彻底的Git配置清理步骤,消除之前执行残留的认证信息:

- name: Full Cleanup of Git Global Config
  run: |
    git config --global --unset-all lfs.token
    git config --global --unset-all lfs.url
    git config --global --unset-all http.https://github.com/.extraheader
    git config --global --unset-all credential.helper
    git config --global --unset-all core.sshCommand
    # 重置Git LFS配置
    git lfs uninstall --global
    git lfs install --global
  shell: PowerShell

- name: Checkout User Repo
  uses: actions/checkout@v4
  with:
    ref: "${{ github.ref }}"
    lfs: true
    fetch-depth: 1
    ssh-strict: false
    token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"

额外验证点

  • 确认ARE_AUTOMATED_TOKEN具备目标仓库的读取权限(包括LFS对象的访问权限),建议使用仓库级别的Personal Access Token(PAT)而非组织级token,避免权限范围过大导致的认证冲突。
  • 检查Windows Runner上是否存在残留的凭证文件,可在工作流开头添加清理:
- name: Cleanup Runner Credential Files
  run: |
    if (Test-Path "$env:USERPROFILE\.git-credentials") {
        Remove-Item "$env:USERPROFILE\.git-credentials" -Force
    }
    if (Test-Path "$env:USERPROFILE\.gitconfig") {
        Remove-Item "$env:USERPROFILE\.gitconfig" -Force
    }
  shell: PowerShell

内容的提问来源于stack exchange,提问作者Ashar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 00:12:07