From fc8c870695fd250d6e2b4bbb16894be9d343ea98 Mon Sep 17 00:00:00 2001 From: frostebite Date: Mon, 24 Aug 2026 22:47:46 +0100 Subject: [PATCH] fix: sync-secrets wrote "-" as the value of every secret it synced `gh secret set` reads the value from stdin only when --body is NOT passed. `--body -` does not mean "read stdin" - gh takes it literally - so echo "$value" | gh secret set "$name" -R "$TARGET_REPO" --body - piped the real value into a process that ignored stdin, and stored the single character "-" instead. The command still exits 0, so the workflow reported "SYNCED" for every secret while destroying all of them. Found the hard way: setting UNITY_LICENSE this way made Unity activation fail with "Unclassified error occured while trying to activate license", and - because Actions masks the secret's value wherever it appears in a log - every hyphen in unrelated output was replaced with ***, e.g. Unable to find image 'unityci/editor:ubuntu***2022.3.7f1***linux***il2cpp***3' which is what made the real cause obvious. Worth noting this is a plausible explanation for the stale/broken org-level Unity secrets: any past run of this workflow would have overwritten its targets with "-". Passes the value via --body directly. Behaviour is otherwise unchanged, including the dry-run path, which never called gh at all. --- .github/workflows/sync-secrets.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/sync-secrets.yml b/.github/workflows/sync-secrets.yml index b2af4e83..cae90612 100644 --- a/.github/workflows/sync-secrets.yml +++ b/.github/workflows/sync-secrets.yml @@ -70,7 +70,14 @@ jobs: if [ "$DRY_RUN" = "true" ]; then echo "🔍 DRY RUN: would sync $name → $TARGET_REPO" else - if echo "$value" | gh secret set "$name" -R "$TARGET_REPO" --body - 2>/dev/null; then + # `gh secret set` reads the value from stdin only when --body is + # NOT passed. `--body -` does not mean "read stdin" - gh takes it + # literally, so this wrote the single character "-" as the value + # of every secret it synced, silently destroying them. (A secret + # whose value is "-" also makes Actions mask every hyphen in the + # logs, which mangles unrelated output like image tags: + # "unityci/editor:ubuntu***2022.3.7f1***linux***il2cpp***3".) + if gh secret set "$name" -R "$TARGET_REPO" --body "$value" 2>/dev/null; then echo "✅ SYNCED: $name → $TARGET_REPO" else echo "⚠️ FAILED: $name → $TARGET_REPO (continuing)"