Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Copilot plugin marketplace refresh fails with a Schannel revocation error

未关闭
#3,857 0 条评论 2 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
42/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
git

调研方向

首先定位启动捆绑 Git 子进程的 marketplace 刷新路径,然后使用已记录的命令和环境变量重现 Windows Schannel 故障。将 Copilot 的子进程配置与从普通终端调用进行比较。当 marketplace 刷新能够使用受信任的 TLS 检查证书正常工作,并且 Git 配置行为已记录或修正时,即视为完成。

由索引模型根据 Issue 内容生成。

描述

The problem

Trying to pull for the first time or refresh a plugin marketplace fails in the GitHub Copilot desktop app with:

Refresh failed: Failed to fetch GitHub marketplace microsoft/aspire-skills: Command failed: git clone --depth 1 --progress https://github.com/microsoft/aspire-skills.git C:\Users\alexanderc\AppData\Local\copilot\marketplaces\microsoft-aspire-skills
Cloning into 'C:\Users\alexanderc\AppData\Local\copilot\marketplaces\microsoft-aspire-skills'...
fatal: unable to access 'https://github.com/microsoft/aspire-skills.git/': schannel: the revocation status is unknown

Running the same command in a terminal works without error:

git clone --depth 1 --progress https://github.com/microsoft/aspire-skills.git C:\Users\alexanderc\AppData\Local\copilot\marketplaces\microsoft-aspire-skills

The failure is therefore not caused by the repository, URL, credentials, or marketplace availability. The important difference is the Git configuration and environment used by Copilot when it launches its bundled Git.

Procmon captured Copilot starting Git with:

git.exe -c core.askPass= -c credential.interactive=never -c core.fsmonitor=false clone --depth 1 --progress https://github.com/microsoft/aspire-skills.git C:\Users\alexanderc\AppData\Local\copilot\marketplaces\microsoft-aspire-skills

The child process also has:

GIT_CONFIG_NOSYSTEM=1
GIT_CONFIG_GLOBAL=/dev/null

These variables prevent the child Git process from reading the normal system Git configuration and the user's global ~/.gitconfig.

This creates a confusing situation where the complete command copied from Copilot's error works in the user's terminal, while Copilot continues to fail because the command is executed with a different Git configuration environment.

TLS inspection

The affected network uses HTTPS/TLS inspection. Instead of allowing Git to receive GitHub's original certificate directly, the inspection device terminates the TLS connection and creates a new certificate for github.com or another GitHub hostname. That replacement certificate is signed by the organization's private inspection CA.

The inspection CA is trusted on the machine, so this is not a normal certificate trust failure. The certificate chain validates as trusted, and ordinary Git operations outside Copilot work successfully.

However, the proxy-issued leaf certificate does not contain the normal revocation-location extensions:

  • No CRL Distribution Point URL
  • No Authority Information Access/OCSP URL

When Git uses the Windows Schannel TLS backend, Schannel attempts to determine whether the certificate has been revoked. Because the replacement certificate publishes no CRL or OCSP endpoint, Schannel cannot obtain a revocation status and reports:

schannel: the revocation status is unknown

Git for Windows supports http.schannelCheckRevoke=best-effort, which is intended for situations where revocation checking cannot be completed. With the regular terminal Git invocation, explicitly using best-effort allows the clone to complete. Copilot's child process nevertheless continues to fail, despite attempts to provide the same setting through its environment.[1]

The issue can be forced from a regular terminal by enabling strict Schannel revocation checking:

git -c http.schannelCheckRevoke=true -c http.schannelUseSSLCAInfo=true clone --depth 1 --progress https://github.com/microsoft/aspire-skills.git "$env:TEMP\copilot-schannel-repro"

This produces the same schannel: the revocation status is unknown failure. The temporary directory is only used to avoid affecting the marketplace checkout.

Workaround attempts

I first tried to force Schannel's revocation behavior to best-effort through Git's environment configuration:

$env:GIT_CONFIG_COUNT = '1'
$env:GIT_CONFIG_KEY_0 = 'http.schannelCheckRevoke'
$env:GIT_CONFIG_VALUE_0 = 'best-effort'

This works when running Git directly from a terminal, but it does not fix marketplace refreshes when Git is launched by Copilot.

Changing only the TLS backend to OpenSSL does fix the problem. Before starting Copilot, setting these environment variables causes marketplace refresh to succeed:

$env:GIT_CONFIG_COUNT = '1'
$env:GIT_CONFIG_KEY_0 = 'http.sslBackend'
$env:GIT_CONFIG_VALUE_0 = 'openssl'
$env:GIT_SSL_CAINFO = 'C:\path\to\ca\file.pem'

GIT_SSL_CAINFO should point to the organization's trusted CA bundle. The OpenSSL workaround changes the TLS backend; it does not change the repository, URL, credentials, or marketplace operation.

To fix

  1. Copilot should not completely replace the normal system and global Git configuration for marketplace operations. Having the exact same git command line work outside Copilot but fail inside Copilot is highly confusing and makes the error message misleading.
  2. If Copilot needs to configure http.schannelCheckRevoke, it should use best-effort rather than true.
  3. Copilot should avoid combining its configuration overrides with GIT_CONFIG_NOSYSTEM=1 and GIT_CONFIG_GLOBAL=/dev/null unless that behavior is required and documented.
  4. The bundled Git/Schannel path should handle trusted TLS-inspection certificates without CRL/OCSP endpoints without making marketplace refresh fail.
  5. Alternatively, Copilot could use OpenSSL for marketplace Git operations on Windows, or provide a supported way to select the TLS backend.

Environment details

  • Windows
  • GitHub Copilot desktop app
  • Copilot-bundled Git for Windows 2.53.0.windows.4
  • Corporate HTTPS/TLS inspection
  • Corporate CA bundle configured for Git/cURL

References

  1. https://github.com/libgit2/libgit2/issues/6724
主要语言
没有语言数据
星标
2.1k
派生
157
PR 合并指标
30 天内没有已合并 PR

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/app 的其他 Issue

查看 github/app 的全部 Issue

相似的 Issue

更多 Desktop Dev Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。