You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在GitHub Action中执行git notes时遭遇权限拒绝错误求助

GitHub Action执行git notes时遭遇权限拒绝错误

问题详情

配置了GitHub Action用于给提交添加git notes(执行git notes add -m "foo bar"),但运行时抛出权限错误:

fatal: update_ref failed for ref 'refs/notes/commits': cannot lock ref 'refs/notes/commits': Unable to create '/home/runner/work/repo_name/repo_name/.git/refs/notes/commits.lock': Permission denied

已尝试以下方法但均无效:

  • 使用${{ github.token }}
  • 在仓库Settings/Actions/General/Workflow permissions中设置「Read and Write permissions」
  • 排除chmod +x问题(直接运行命令)
  • 将工作流权限设置为write-all

怀疑是否是并发问题?

工作流YAML文件

name: Notes

on:
  workflow_dispatch:

permissions: write-all

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout
        uses: actions/checkout@v3
        with:
          fetch-depth: 0
          token: ${{ github.token }}
      - name: Add git notes
        id: git-notes
        run: |
          git config user.name "Github Actions"
          git config user.email "bot@github.actions"
          git notes add -m "foo bar"
        env:
          GITHUB_TOKEN: ${{ github.token }}

运行日志

Run git config user.name "Github Actions"
  git config user.name "Github Actions"
  git config user.email "bot@github.actions"
  git notes add --allow-empty -m "foo bar"
  shell: /usr/bin/bash -e {0}
  env:
    GITHUB_TOKEN: ***
Removing note for object HEAD
fatal: update_ref failed for ref 'refs/notes/commits': cannot lock ref 'refs/notes/commits': Unable to create '/home/runner/work/marion_test_notes/marion_test_notes/.git/refs/notes/commits.lock': Permission denied
Error: Process completed with exit code 128.

解决方案

1. 修复.git目录权限

Runner环境中检出的仓库.git目录可能存在权限异常,手动修正后再执行命令:

- name: Add git notes
  id: git-notes
  run: |
    sudo chown -R runner:runner .git
    git config user.name "Github Actions"
    git config user.email "bot@github.actions"
    git notes add -m "foo bar"
  env:
    GITHUB_TOKEN: ${{ github.token }}

2. 显式拉取notes引用

默认actions/checkout不会拉取notes相关引用,提前拉取避免本地无引用导致锁文件创建失败:

- name: Checkout
  uses: actions/checkout@v3
  with:
    fetch-depth: 0
    token: ${{ github.token }}
- name: Fetch git notes
  run: git fetch origin refs/notes/commits:refs/notes/commits

3. 控制工作流并发(针对并发怀疑)

如果存在多工作流同时操作git notes的场景,添加并发控制确保同一时间仅一个工作流执行:

on:
  workflow_dispatch:

concurrency:
  group: git-notes-group
  cancel-in-progress: false # 若需要可设为true取消正在运行的任务

permissions: write-all

4. 使用个人访问令牌(PAT)替代默认token

默认github.token对部分特殊操作(如操作notes)可能存在限制,生成带repo权限的PAT并存储为仓库Secret(如PAT_TOKEN),替换checkout中的token:

- name: Checkout
  uses: actions/checkout@v3
  with:
    fetch-depth: 0
    token: ${{ secrets.PAT_TOKEN }}

验证方法

修改后重新触发工作流,可在步骤中添加git notes show命令验证notes是否添加成功:

git notes add -m "foo bar"
git notes show

内容的提问来源于stack exchange,提问作者ebosi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 02:05:18