deb/apk: make local repodata deterministic
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful

Part of #117. The two no-affinity replicas (and every regeneration) must
serve byte-identical local repodata so apt/apk never hit a checksum
mismatch between an index's advertised hash and the bytes actually served.

- Derive the deb Release Date: from the newest persisted created_at
  (RFC1123Z, UTC) instead of time.Now(); carry created_at through the deb
  metadata SELECT and DebMetadata struct.
- Pin the apk APKINDEX tar header ModTime to the Unix epoch instead of the
  zero-value time.Time, so it is never wall-clock derived.
- Give both list queries a genuine total order by adding a file_path
  tiebreak (name/version/arch is not unique).
- Add guard tests: deb generators byte-identical across generations, the
  Release checksum/size invariant matches the served Packages(.gz) bytes,
  the Date: is pinned to created_at; apk index byte-identical and tar
  ModTime pinned to epoch.
This commit is contained in:
2026-08-12 23:21:20 +10:00
parent a8aa0c231b
commit cea107d4b5
7 changed files with 273 additions and 6 deletions
+1 -1
View File
@@ -41,7 +41,7 @@ func (db *DB) ListAlpineMetadataEntries(ctx context.Context, repoName string) ([
depends, provides, install_if
FROM alpine_metadata
WHERE repo_name = $1
ORDER BY name, version, arch
ORDER BY name, version, arch, file_path
`, repoName)
if err != nil {
return nil, err
+3 -3
View File
@@ -31,10 +31,10 @@ func (db *DB) ListDebMetadataEntries(ctx context.Context, repoName string) ([]pr
rows, err := db.Pool.Query(ctx, `
SELECT repo_name, file_path, content_hash,
name, version, architecture, control,
size, md5, sha256
size, md5, sha256, created_at
FROM deb_metadata
WHERE repo_name = $1
ORDER BY name, version, architecture
ORDER BY name, version, architecture, file_path
`, repoName)
if err != nil {
return nil, err
@@ -47,7 +47,7 @@ func (db *DB) ListDebMetadataEntries(ctx context.Context, repoName string) ([]pr
if err := rows.Scan(
&m.RepoName, &m.FilePath, &m.ContentHash,
&m.Name, &m.Version, &m.Architecture, &m.Control,
&m.Size, &m.MD5, &m.SHA256,
&m.Size, &m.MD5, &m.SHA256, &m.CreatedAt,
); err != nil {
return nil, err
}