Adds a deb provider with feature parity to rpm for local and remote repos,
so .deb packages can be hosted (flat apt repo generated on upload) and a
Debian/Ubuntu mirror can be cached through the proxy.
- add PackageDeb to the package-type enum
- new internal/provider/deb: Classify (.deb immutable, Packages/Release/dists
mutable), ValidateUpload to pool/<file>, pure-Go .deb parse (ar -> control.tar
gz/xz/zst -> ./control), and a flat-repo LocalIndexer serving Packages,
Packages.gz and an unsigned Release ([trusted=yes], mirroring rpm gpgcheck=0)
- remote proxy path: UpstreamURL/ContentType/AuthHeaders via BasicHeaders
- DebMetadata struct + store interfaces on provider; deb_metadata table in
migrate() and Insert/Delete/List DB methods
- blank-import the deb provider in the server
- testsupport.MinimalDeb pure-Go fixture builder
- unit tests (classify, control parse across gz/xz/zst, Packages/Release
generation, validate) and a dockere2e TestLocalDebRepo
Raises statement coverage of the core packages (all of `internal/` except the interactive `tui/`, plus `pkg/`) from **8.7% to 90.1%**.
## Approach
- **Pure-go unit tests** for all providers, virtual mergers, classifier, config, auth, models, and the API client (httptest).
- **Testcontainers-backed** tests (new `internal/testsupport` helper: Postgres/Redis/MinIO, Ryuk disabled) for database, storage, cache, the proxy engine, the GC, and a full-stack `server` test that drives the whole HTTP API. These `t.Skip` when Docker is absent so `go test` still runs locally without it.
## Measuring
```
go test -coverpkg=./internal/...,./pkg/... -coverprofile=cover.out ./internal/... ./pkg/...
grep -v /internal/tui/ cover.out | go tool cover -func=/dev/stdin | tail -1 # 90.1%
```
Run with `-p 1` (containers are heavy).
## Notes
- The interactive `tui/` package and `cmd/main` are excluded from the target per the agreed scope.
- Some defensive error branches are covered via fault injection (closed DB pool, killing MinIO mid-upload).
Reviewed-on: #98
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>