diff --git a/.github/workflows/simple-release.yml b/.github/workflows/simple-release.yml index ecd8c35..913ad71 100644 --- a/.github/workflows/simple-release.yml +++ b/.github/workflows/simple-release.yml @@ -262,11 +262,8 @@ jobs: fi gitx() { - if [ -n "${EXTRA_HEADER}" ]; then - git -c http.extraHeader="${EXTRA_HEADER}" "$@" - else - git "$@" - fi + # http.extraHeader is configured globally when CI_CD_PAT exists; just run git + git "$@" } # Masked diagnostic: confirm whether CI_CD_PAT/EXTRA_HEADER is present (do NOT print secrets) @@ -282,8 +279,15 @@ jobs: retry gitx -C "$PYENV_ROOT" reset --hard "origin/${PYENV_PYENV_REF}" || true elif [ -d "$PYENV_ROOT" ] && [ -z "$(ls -A "$PYENV_ROOT")" ]; then # directory exists but empty -> safe to clone into - retry gitx clone --depth 1 --branch "${PYENV_PYENV_REF}" "$REPO_PYENV" "$PYENV_ROOT" || \ - { echo "Branch/ref ${PYENV_PYENV_REF} not available for shallow clone; falling back to default branch"; retry gitx clone --depth 1 "$REPO_PYENV" "$PYENV_ROOT"; } + if ! retry gitx clone --depth 1 --branch "${PYENV_PYENV_REF}" "$REPO_PYENV" "$PYENV_ROOT"; then + echo "git clone failed; attempting GitHub API tarball fallback using PAT" + if [ -n "${CI_CD_PAT:-}" ]; then + retry curl -fSL -H "Authorization: token ${CI_CD_PAT}" "https://api.github.com/repos/pyenv/pyenv/tarball/${PYENV_PYENV_REF}" | tar -xz --strip-components=1 -C "$PYENV_ROOT" + else + echo "No CI_CD_PAT provided; cannot use tarball fallback" + exit 1 + fi + fi else # directory exists and is not a git repo (or contains leftover files) -> move aside then clone if [ -d "$PYENV_ROOT" ]; then @@ -301,8 +305,15 @@ jobs: retry gitx -C "$PYENV_ROOT/plugins/python-build" fetch --all --prune --depth=1 || true retry gitx -C "$PYENV_ROOT/plugins/python-build" reset --hard "origin/${PYENV_BUILD_REF}" || true elif [ -d "$PYENV_ROOT/plugins/python-build" ] && [ -z "$(ls -A "$PYENV_ROOT/plugins/python-build")" ]; then - retry gitx clone --depth 1 --branch "${PYENV_BUILD_REF}" "$REPO_BUILD" "$PYENV_ROOT/plugins/python-build" || \ - { echo "Branch/ref ${PYENV_BUILD_REF} not available for shallow clone; falling back to default branch"; retry gitx clone --depth 1 "$REPO_BUILD" "$PYENV_ROOT/plugins/python-build"; } + if ! retry gitx clone --depth 1 --branch "${PYENV_BUILD_REF}" "$REPO_BUILD" "$PYENV_ROOT/plugins/python-build"; then + echo "git clone for python-build failed; attempting GitHub API tarball fallback using PAT" + if [ -n "${CI_CD_PAT:-}" ]; then + retry curl -fSL -H "Authorization: token ${CI_CD_PAT}" "https://api.github.com/repos/pyenv/pyenv-build/tarball/${PYENV_BUILD_REF}" | tar -xz --strip-components=1 -C "$PYENV_ROOT/plugins/python-build" + else + echo "No CI_CD_PAT provided; cannot use tarball fallback" + exit 1 + fi + fi else if [ -d "$PYENV_ROOT/plugins/python-build" ]; then pb_backup="${PYENV_ROOT}/plugins/python-build.bak.$(date +%s)"