GitHub Actions Checkout v4 Windows环境间歇性LFS授权失败求助
Windows Runner上actions/checkout@v4拉取LFS仓库间歇性授权错误修复
问题概述
在Windows Runner(标签myWINA3,归属Shared2组)上使用GitHub PowerShell工作流拉取含Git LFS对象的仓库时,actions/checkout@v4动作间歇性抛出LFS授权错误。关闭lfs: true可规避问题,但业务需要启用LFS拉取对象。
复现工作流
name: Testcheckout - AD on: workflow_dispatch: jobs: setvars: runs-on: group: Shared2 labels: myWINA3 outputs: runner_name: ${{ runner.name }} steps: - name: Checkout User Repo uses: actions/checkout@v4 with: ref: "${{ github.ref }}" lfs: true fetch-depth: 1 ssh-strict: false token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"
错误日志
Run actions/checkout@v4 with: repository: userbank/userrepo ref: refs/heads/release/RELEASE_2024_OCT_24 path: D:\A\3\_work\userrepo\userrepo\userrepo lfs: true fetch-depth: 1 ssh-strict: false token: *** ssh-user: git persist-credentials: true clean: true sparse-checkout-cone-mode: true fetch-tags: false show-progress: true submodules: false set-safe-directory: true env: repodirexists: false devtoken: *** Syncing repository: userbank/userrepo Getting Git version info Copying 'C:\Users\autobuild\.gitconfig' to 'D:\A\3\_work\_temp\7d866ea3-512c-44a6-92e5-d3bf9149ee80\.gitconfig' Temporarily overriding HOME='D:\A\3\_work\_temp\7d866ea3-512c-44a6-92e5-d3bf9149ee80' before making global git config changes Adding repository directory to the temporary git global config as a safe directory "C:\Program Files\Git\cmd\git.exe" config --global --add safe.directory D:\A\3\_work\userrepo\userrepo\userrepo "C:\Program Files\Git\cmd\git.exe" config --local --get remote.origin.url https://github.com/userbank/userbank/userrepo.git Deleting the contents of 'D:\A\3\_work\userrepo\userrepo\userrepo' Initializing the repository Disabling automatic garbage collection Setting up auth "C:\Program Files\Git\cmd\git.exe" lfs install --local Updated Git hooks. Git LFS initialized. Fetching the repository "C:\Program Files\Git\cmd\git.exe" -c protocol.version=2 fetch --no-tags --prune --no-recurse-submodules --depth=1 origin +refs/heads/release/RELEASE_2024_OCT_24:refs/remotes/origin/release/RELEASE_2024_OCT_24 From https://github.com//userbank/userrepo * [new branch] release/RELEASE_2024_OCT_24 -> origin/release/RELEASE_2024_OCT_24 Determining the checkout info Fetching LFS objects "C:\Program Files\Git\cmd\git.exe" lfs fetch origin refs/remotes/origin/release/RELEASE_2024_OCT_24 fetch: Fetching reference refs/remotes/origin/release/RELEASE_2024_OCT_24 batch response: Authorization error: ***github.com//userbank/userrepo.git/info/lfs/objects/batch Check that you have proper access to the repository Error: error: failed to fetch some objects from '***github.com//userbank/userrepo.git/info/lfs' The process 'C:\Program Files\Git\cmd\git.exe' failed with exit code 2
已尝试的无效操作
- name: Github Clean Up Old Connections run: | Write-Host "Clean Up Old Connections" git config --global --unset-all http.https://github.com/.extraheader git config --global --unset-all core.sshCommand git lfs install shell: Powershell
环境信息
Git版本:git version 2.46.0.windows.1
永久修复方案
方案1:显式配置Git LFS认证信息
在actions/checkout步骤前添加LFS认证配置,确保拉取时使用指定token,同时禁用认证信息持久化避免残留干扰:
- name: Configure Git LFS Authentication run: | git config --global lfs.url "https://github.com/userbank/userrepo.git/info/lfs" git config --global lfs.token "${{ secrets.ARE_AUTOMATED_TOKEN }}" shell: PowerShell - name: Checkout User Repo uses: actions/checkout@v4 with: ref: "${{ github.ref }}" lfs: true fetch-depth: 1 ssh-strict: false token: "${{ secrets.ARE_AUTOMATED_TOKEN }}" persist-credentials: false
方案2:手动触发LFS拉取(规避checkout自动拉取的认证问题)
关闭checkout的自动LFS拉取,手动完成LFS对象的获取和检出,全程控制认证逻辑:
- name: Checkout User Repo uses: actions/checkout@v4 with: ref: "${{ github.ref }}" lfs: false fetch-depth: 1 ssh-strict: false token: "${{ secrets.ARE_AUTOMATED_TOKEN }}" persist-credentials: false - name: Fetch and Checkout LFS Objects run: | # 配置Git凭证存储,让LFS拉取时自动使用token git config --local credential.helper store echo "https://x-access-token:${{ secrets.ARE_AUTOMATED_TOKEN }}@github.com" | Out-File -FilePath "$env:USERPROFILE\.git-credentials" -Encoding utf8 # 初始化LFS并拉取对象 git lfs install --local git lfs fetch origin "${{ github.ref }}" git lfs checkout shell: PowerShell
方案3:彻底清理Runner上的Git全局配置残留
在工作流开头添加更彻底的Git配置清理步骤,消除之前执行残留的认证信息:
- name: Full Cleanup of Git Global Config run: | git config --global --unset-all lfs.token git config --global --unset-all lfs.url git config --global --unset-all http.https://github.com/.extraheader git config --global --unset-all credential.helper git config --global --unset-all core.sshCommand # 重置Git LFS配置 git lfs uninstall --global git lfs install --global shell: PowerShell - name: Checkout User Repo uses: actions/checkout@v4 with: ref: "${{ github.ref }}" lfs: true fetch-depth: 1 ssh-strict: false token: "${{ secrets.ARE_AUTOMATED_TOKEN }}"
额外验证点
- 确认
ARE_AUTOMATED_TOKEN具备目标仓库的读取权限(包括LFS对象的访问权限),建议使用仓库级别的Personal Access Token(PAT)而非组织级token,避免权限范围过大导致的认证冲突。 - 检查Windows Runner上是否存在残留的凭证文件,可在工作流开头添加清理:
- name: Cleanup Runner Credential Files run: | if (Test-Path "$env:USERPROFILE\.git-credentials") { Remove-Item "$env:USERPROFILE\.git-credentials" -Force } if (Test-Path "$env:USERPROFILE\.gitconfig") { Remove-Item "$env:USERPROFILE\.gitconfig" -Force } shell: PowerShell
内容的提问来源于stack exchange,提问作者Ashar
相关产品推荐
相关产品推荐

