在GitHub Action中执行git notes时遭遇权限拒绝错误求助
GitHub Action执行git notes时遭遇权限拒绝错误
问题详情
配置了GitHub Action用于给提交添加git notes(执行git notes add -m "foo bar"),但运行时抛出权限错误:
fatal: update_ref failed for ref 'refs/notes/commits': cannot lock ref 'refs/notes/commits': Unable to create '/home/runner/work/repo_name/repo_name/.git/refs/notes/commits.lock': Permission denied
已尝试以下方法但均无效:
- 使用
${{ github.token }} - 在仓库Settings/Actions/General/Workflow permissions中设置「Read and Write permissions」
- 排除
chmod +x问题(直接运行命令) - 将工作流权限设置为
write-all
怀疑是否是并发问题?
工作流YAML文件
name: Notes on: workflow_dispatch: permissions: write-all jobs: build: runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@v3 with: fetch-depth: 0 token: ${{ github.token }} - name: Add git notes id: git-notes run: | git config user.name "Github Actions" git config user.email "bot@github.actions" git notes add -m "foo bar" env: GITHUB_TOKEN: ${{ github.token }}
运行日志
Run git config user.name "Github Actions" git config user.name "Github Actions" git config user.email "bot@github.actions" git notes add --allow-empty -m "foo bar" shell: /usr/bin/bash -e {0} env: GITHUB_TOKEN: *** Removing note for object HEAD fatal: update_ref failed for ref 'refs/notes/commits': cannot lock ref 'refs/notes/commits': Unable to create '/home/runner/work/marion_test_notes/marion_test_notes/.git/refs/notes/commits.lock': Permission denied Error: Process completed with exit code 128.
解决方案
1. 修复.git目录权限
Runner环境中检出的仓库.git目录可能存在权限异常,手动修正后再执行命令:
- name: Add git notes id: git-notes run: | sudo chown -R runner:runner .git git config user.name "Github Actions" git config user.email "bot@github.actions" git notes add -m "foo bar" env: GITHUB_TOKEN: ${{ github.token }}
2. 显式拉取notes引用
默认actions/checkout不会拉取notes相关引用,提前拉取避免本地无引用导致锁文件创建失败:
- name: Checkout uses: actions/checkout@v3 with: fetch-depth: 0 token: ${{ github.token }} - name: Fetch git notes run: git fetch origin refs/notes/commits:refs/notes/commits
3. 控制工作流并发(针对并发怀疑)
如果存在多工作流同时操作git notes的场景,添加并发控制确保同一时间仅一个工作流执行:
on: workflow_dispatch: concurrency: group: git-notes-group cancel-in-progress: false # 若需要可设为true取消正在运行的任务 permissions: write-all
4. 使用个人访问令牌(PAT)替代默认token
默认github.token对部分特殊操作(如操作notes)可能存在限制,生成带repo权限的PAT并存储为仓库Secret(如PAT_TOKEN),替换checkout中的token:
- name: Checkout uses: actions/checkout@v3 with: fetch-depth: 0 token: ${{ secrets.PAT_TOKEN }}
验证方法
修改后重新触发工作流,可在步骤中添加git notes show命令验证notes是否添加成功:
git notes add -m "foo bar" git notes show
内容的提问来源于stack exchange,提问作者ebosi
相关产品推荐
相关产品推荐

