[
https://issues.apache.org/jira/browse/SPARK-59106?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Hyukjin Kwon resolved SPARK-59106.
----------------------------------
Fix Version/s: connect-rust-4.2.0
connect-rust-4.3.0
Resolution: Fixed
> Release-tag push to apache uses the built-in token instead of
> RELEASE_GITHUB_TOKEN (403)
> ----------------------------------------------------------------------------------------
>
> Key: SPARK-59106
> URL: https://issues.apache.org/jira/browse/SPARK-59106
> Project: Spark
> Issue Type: Bug
> Components: Connect
> Affects Versions: connect-rust-4.3.0
> Reporter: Hyukjin Kwon
> Priority: Major
> Labels: pull-request-available
> Fix For: connect-rust-4.2.0, connect-rust-4.3.0
>
>
> Cutting an RC failed at the "Create and push the RC tag to the canonical
> apache repo" step of the release workflow:
> remote: Permission to apache/spark-connect-rust.git denied to
> github-actions[bot].
> fatal: unable to access
> '''https://github.com/apache/spark-connect-rust.git/''': The requested URL
> returned error: 403
> RELEASE_GITHUB_TOKEN is set on the fork, so the secret is not the problem.
> The push went out as github-actions[bot] instead of the PAT identity.
> Root cause: the publish-rc and finalize jobs check out
> apache/spark-connect-rust with actions/checkout@v4 at its default
> persist-credentials: true, which stores the built-in GITHUB_TOKEN as a git
> http.https://github.com/.extraheader. That header overrides the
> RELEASE_GITHUB_TOKEN embedded in the subsequent URL, so the push
> authenticates as github-actions[bot] (no write to apache) -> 403. The gh-CLI
> release steps use the PAT via GH_TOKEN and are unaffected; only the two
> git-push steps are hijacked.
> Fix: set persist-credentials: false on the publish-rc and finalize checkouts
> so the PAT-in-URL pushes authenticate as the token owner. No new secret
> required (RELEASE_GITHUB_TOKEN already exists).
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]