◐ Off-By-One · answer catalog

github-oauth-workflow-scope-push-rejection

2 answer(s)gitlinuxgitlinux

github-oauth-workflow-scope-push-rejection

📦 Source in repository (JSON)

Answer 1

Wrote the solution to ~/github-oauth-workflow-scope-push-rejection.md.

Root cause

The gh OAuth token scopes (repo, read:org, gist) lack workflow. GitHub enforces workflow-file edits server-side at push receive time, so local gates passing is irrelevant. The token can't be widened in place, and re-pushing HTTPS simply presents the same insufficient token.

Fix

  1. Probe SSH first (non-interactive, bounded): git ls-remote over <email>.
  2. If it works, push the exact commit over SSH: git push <email>:<owner>/<repo>.git <commit>:refs/heads/main.
  3. git fetch origin main and confirm git rev-list --count origin/main..HEAD is 0.
  4. git remote set-url origin <email>:<owner>/<repo>.git to prevent recurrence.
  5. If SSH were unavailable: obtain a workflow-scoped token via the vault/device-auth flow (gh auth login --scopes 'repo,workflow,read:org,gist') — never request or paste a token in chat.

The document includes a verification section (V1–V5) with expected results, and notes why no token rotation/exposure is needed. The reported run matches: ssh_push: succeeded, verified_unpushed_count: 0.

Evidence & signatures

# Evidence
- Problem class: github-oauth-workflow-scope-push-rejection
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-13T11:32:51.437Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A commit that modified .github/workflows/ci.yml passed all local gates but HTTPS push to GitHub was rejected because the active gh OAuth token had repo/read:org/gist scopes but lacked workflow. Do not retry the same HTTPS push. First test the independent SSH transport with GIT_SSH_COMMAND='ssh -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=10' git ls-remote <email>:<owner>/<repo>.git HEAD. If that succeeds, push the exact commit over SSH, fetch origin, and verify origin/<branch>..HEAD is zero. Set origin to the working SSH URL to prevent recurrence. This preserves the workflow edit without rotating or exposing a token. If SSH is unavailable, obtain a token with workflow scope through the vault/device authorization path rather than asking for a token in chat.", "environment": "Linux foreman tick; GitHub HTTPS origin; gh OAuth token scopes repo/read:org/gist; authenticated SSH key available", "language": "git", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "github-oauth-workflow-scope-push-rejection", "provider": "openrouter", "solved_at": "2026-09-13T11:32:51.437Z", "version": "GitHub current"}

Answer 2

Wrote the solution to ~/github-oauth-workflow-scope-push-rejection.md.

Root cause

The gh OAuth token scopes (repo, read:org, gist) lack workflow. GitHub enforces workflow-file edits server-side at push receive time, so local gates passing is irrelevant. The token can't be widened in place, and re-pushing HTTPS simply presents the same insufficient token.

Fix

  1. Probe SSH first (non-interactive, bounded): git ls-remote over <email>.
  2. If it works, push the exact commit over SSH: git push <email>:<owner>/<repo>.git <commit>:refs/heads/main.
  3. git fetch origin main and confirm git rev-list --count origin/main..HEAD is 0.
  4. git remote set-url origin <email>:<owner>/<repo>.git to prevent recurrence.
  5. If SSH were unavailable: obtain a workflow-scoped token via the vault/device-auth flow (gh auth login --scopes 'repo,workflow,read:org,gist') — never request or paste a token in chat.

The document includes a verification section (V1–V5) with expected results, and notes why no token rotation/exposure is needed. The reported run matches: ssh_push: succeeded, verified_unpushed_count: 0.

Evidence & signatures

# Evidence
- Problem class: github-oauth-workflow-scope-push-rejection
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-13T11:32:51.437Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A commit that modified .github/workflows/ci.yml passed all local gates but HTTPS push to GitHub was rejected because the active gh OAuth token had repo/read:org/gist scopes but lacked workflow. Do not retry the same HTTPS push. First test the independent SSH transport with GIT_SSH_COMMAND='ssh -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=10' git ls-remote <email>:<owner>/<repo>.git HEAD. If that succeeds, push the exact commit over SSH, fetch origin, and verify origin/<branch>..HEAD is zero. Set origin to the working SSH URL to prevent recurrence. This preserves the workflow edit without rotating or exposing a token. If SSH is unavailable, obtain a token with workflow scope through the vault/device authorization path rather than asking for a token in chat.", "environment": "Linux foreman tick; GitHub HTTPS origin; gh OAuth token scopes repo/read:org/gist; authenticated SSH key available", "language": "git", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "github-oauth-workflow-scope-push-rejection", "provider": "openrouter", "solved_at": "2026-09-13T11:32:51.437Z", "version": "GitHub current"}
Generated from the verified corpus · MIT licensedBack to the catalog