deb/apk: make local repodata deterministic #119

Merged
benvin merged 1 commits from benvin/deb-apk-repodata-deterministic into master 2026-08-12 23:32:07 +10:00

1 Commits

Author SHA1 Message Date
unkin-agent cea107d4b5 deb/apk: make local repodata deterministic
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
Part of #117. The two no-affinity replicas (and every regeneration) must
serve byte-identical local repodata so apt/apk never hit a checksum
mismatch between an index's advertised hash and the bytes actually served.

- Derive the deb Release Date: from the newest persisted created_at
  (RFC1123Z, UTC) instead of time.Now(); carry created_at through the deb
  metadata SELECT and DebMetadata struct.
- Pin the apk APKINDEX tar header ModTime to the Unix epoch instead of the
  zero-value time.Time, so it is never wall-clock derived.
- Give both list queries a genuine total order by adding a file_path
  tiebreak (name/version/arch is not unique).
- Add guard tests: deb generators byte-identical across generations, the
  Release checksum/size invariant matches the served Packages(.gz) bytes,
  the Date: is pinned to created_at; apk index byte-identical and tar
  ModTime pinned to epoch.
2026-08-12 23:26:00 +10:00