@@ -72,6 +72,7 @@ HostedGit.addHost('localhostssh', {
7272} )
7373
7474const remote = `git://localhost:${ gitPort } /repo`
75+ const remoteBroken = `git://localhost:${ gitPort } /broken`
7576const remoteHosted = `git://127.0.0.1:${ gitPort } /repo`
7677const submodsRemote = `git://localhost:${ gitPort } /submodule-repo`
7778const workspacesRemote = `git://localhost:${ gitPort } /workspaces-repo`
@@ -86,6 +87,7 @@ const me = t.testdir({
8687 cache : { } ,
8788} )
8889const repo = resolve ( me , 'repo' )
90+ const broken = resolve ( me , 'broken' )
8991const cache = resolve ( me , 'cache' )
9092const cycleA = resolve ( me , 'cycle-a' )
9193const cycleB = resolve ( me , 'cycle-b' )
@@ -455,6 +457,37 @@ t.test('ignores integrity for git deps', { skip: isWindows && 'posix only' }, as
455457 t . end ( )
456458} )
457459
460+ t . test ( 'detects changes in the resolved sha' , { } , async ( t ) => {
461+ const git = ( ...cmd ) => spawnGit ( cmd , { cwd : broken } )
462+ const write = ( f , c ) => fs . writeFileSync ( f , c )
463+
464+ await mkdir ( broken , { recursive : true } )
465+ . then ( ( ) => git ( 'config' , 'user.name' , 'pacotedev' ) )
466+ . then ( ( ) => git ( 'config' , 'user.email' , 'i+pacotedev@izs.me' ) )
467+ . then ( ( ) => git ( 'config' , 'tag.gpgSign' , 'false' ) )
468+ . then ( ( ) => git ( 'config' , 'commit.gpgSign' , 'false' ) )
469+ . then ( ( ) => git ( 'config' , 'tag.forceSignAnnotated' , 'false' ) )
470+ . then ( ( ) => git ( 'init' ) )
471+ . then ( ( ) => write ( `${ broken } /package.json` , JSON . stringify ( {
472+ name : 'repo' ,
473+ version : '0.0.0' ,
474+ } ) ) )
475+ . then ( ( ) => git ( 'add' , 'package.json' ) )
476+ . then ( ( ) => git ( 'commit' , '-m' , 'package json file' ) )
477+ . then ( ( ) => git ( 'checkout' , '-b' , REPO_HEAD ) )
478+
479+ const { stdout : actual } = await git ( 'rev-parse' , 'HEAD' )
480+
481+ const fetcher = new GitFetcher ( remoteBroken + '#' + REPO_HEAD , opts )
482+ await t . rejects ( ( ) => fetcher . manifest ( ) , {
483+ message : `Commit mismatch: expected SHA ${ REPO_HEAD } and cloned HEAD ${ actual } ` ,
484+ code : 'EGITCHECKOUT' ,
485+ sha : REPO_HEAD ,
486+ head : actual ,
487+ } )
488+ t . end ( )
489+ } )
490+
458491t . test ( 'weird hosted that doesnt provide any fetch targets' , { skip : isWindows && 'posix only' } ,
459492 t => {
460493 const hosted = {
0 commit comments