@@ -48,15 +48,30 @@ jobs:
4848 if [ -n "$INPUT_REF" ]; then
4949 # A ref given by hand is the maintainer's call, so the release
5050 # checks below do not apply: the reason to pass one is a docs fix
51- # that is not in a release yet. `rev-parse` both sides, because a
52- # short sha, a branch and a tag all have to compare as refs.
53- TAG=$(git -C /tmp/certified-assets rev-parse --short "$INPUT_REF^{commit}") || {
51+ # that is not in a release yet.
52+ #
53+ # Tried as given and then under `origin/`, because a clone creates a
54+ # local branch only for the default branch and leaves every other
55+ # one reachable as `origin/<branch>` alone. A sha and a tag resolve
56+ # on the first attempt.
57+ REF_COMMIT=$(git -C /tmp/certified-assets rev-parse --verify --quiet "${INPUT_REF}^{commit}" \
58+ || git -C /tmp/certified-assets rev-parse --verify --quiet "origin/${INPUT_REF}^{commit}") || {
5459 echo "::error::Cannot resolve ref '$INPUT_REF' in dfinity/certified-assets."
5560 exit 1
5661 }
62+ TAG=$(git -C /tmp/certified-assets rev-parse --short "$REF_COMMIT")
5763 echo "Manual ref: $INPUT_REF resolved to $TAG. Pinned: $PIN."
58- if [ "$(git -C /tmp/certified-assets rev-parse "$TAG")" = \
59- "$(git -C /tmp/certified-assets rev-parse "$PIN")" ]; then
64+
65+ # Peel the pin to a commit before comparing. The tags here are
66+ # annotated, so an unpeeled tag name resolves to the tag object and
67+ # would never equal a commit: dispatching the pinned tag would then
68+ # read as a change and rewrite the pin from that tag to its own
69+ # commit sha, moving a tag pin onto a commit for no reason.
70+ PIN_COMMIT=$(git -C /tmp/certified-assets rev-parse --verify --quiet "${PIN}^{commit}") || {
71+ echo "::error::Pin '$PIN' does not resolve in dfinity/certified-assets."
72+ exit 1
73+ }
74+ if [ "$REF_COMMIT" = "$PIN_COMMIT" ]; then
6075 echo "That is the pin already. Nothing to sync."
6176 echo "needed=false" >> $GITHUB_OUTPUT
6277 exit 0
0 commit comments