chore: git_push_dlp 改 robocopy 增量镜像(固定 stage 复用,只复制变动文件)

This commit is contained in:
p40000043244@byd.com
2026-07-31 18:13:44 +08:00
parent e0f1db75c2
commit a458270fa7
2 changed files with 26 additions and 23 deletions
@@ -5,8 +5,11 @@ rem Push from a DLP-protected (transparent-encrypted) directory where
rem "git push" fails with: fatal: not a git repository
rem
rem How it works:
rem 1. xcopy .git to a stage dir under %TEMP% (outside the protected zone,
rem an authorized process reads plaintext, no re-encryption outside).
rem 1. Mirror .git to a fixed per-repo stage dir under %TEMP% with
rem robocopy /MIR (outside the protected zone, an authorized process
rem reads plaintext, no re-encryption outside). The stage dir is kept
rem between runs, so after the first full mirror only changed files
rem are copied on subsequent pushes.
rem 2. Run "git push" from the stage dir.
rem 3. Run "git fetch" in the original repo to sync remote-tracking refs.
rem
@@ -16,8 +19,9 @@ rem git_push_dlp origin main = git push origin main
rem git_push_dlp upstream main:main = any normal push args
rem
rem Env vars:
rem GIT_PUSH_DLP_WITH_LFS=1 = also copy .git\lfs (needed only when
rem the push contains new LFS objects)
rem GIT_PUSH_DLP_WITH_LFS=1 = also mirror .git\lfs (needed only
rem when the push contains new LFS
rem objects)
rem ==========================================================================
setlocal EnableExtensions EnableDelayedExpansion
chcp 65001 >nul
@@ -28,24 +32,24 @@ if not exist ".git\" (
)
for %%I in ("%CD%") do set "REPO_NAME=%%~nxI"
set "STAGE=%TEMP%\git_push_dlp\%REPO_NAME%-%RANDOM%%RANDOM%"
set "STAGE=%TEMP%\git_push_dlp\%REPO_NAME%"
echo [DLP] Stage dir: %STAGE%
rem .git\lfs is the LFS object cache (often several GB); normal commits do
rem not need it for push. Excluding it avoids xcopy disk-space failures.
rem not need it for push. Excluding it avoids filling up the TEMP drive.
rem If this push contains new/changed LFS files, set GIT_PUSH_DLP_WITH_LFS=1 first.
set "EXCLUDE_OPT="
if not defined GIT_PUSH_DLP_WITH_LFS (
set "EXCLUDE_FILE=%TEMP%\git_push_dlp_exclude.txt"
> "!EXCLUDE_FILE!" echo \lfs\
set "EXCLUDE_OPT=/EXCLUDE:!EXCLUDE_FILE!"
set "EXCLUDE_OPT=/XD lfs"
if defined GIT_PUSH_DLP_WITH_LFS set "EXCLUDE_OPT="
if defined GIT_PUSH_DLP_WITH_LFS (
echo [DLP] Including .git\lfs
) else (
echo [DLP] Excluding .git\lfs ^(set GIT_PUSH_DLP_WITH_LFS=1 to include^)
)
xcopy /E /I /Q /H /Y %EXCLUDE_OPT% ".git" "%STAGE%\.git" >nul
if errorlevel 1 (
echo [ERROR] xcopy .git failed.
robocopy ".git" "%STAGE%\.git" /MIR %EXCLUDE_OPT% /NFL /NDL /NJH /NP >nul
if errorlevel 8 (
echo [ERROR] robocopy .git failed ^(exit %ERRORLEVEL%^).
exit /b 1
)
@@ -64,7 +68,6 @@ popd
if not "%EXIT_CODE%"=="0" (
echo [ERROR] push failed with exit code %EXIT_CODE%
rmdir /s /q "%STAGE%" 2>nul
exit /b %EXIT_CODE%
)
@@ -72,7 +75,6 @@ echo [DLP] Sync back: git fetch %REMOTE%
git fetch %REMOTE%
set "FETCH_CODE=%ERRORLEVEL%"
rmdir /s /q "%STAGE%" 2>nul
if not "%FETCH_CODE%"=="0" (
echo [WARN] push succeeded but fetch back failed with exit code %FETCH_CODE%
exit /b %FETCH_CODE%