-
released this
2026-08-12 23:32:07 +10:00 Part of #117. Local generated repodata must be byte-identical across the two no-affinity replicas and across every regeneration, so apt/apk never hit a checksum mismatch between an index's advertised hash and the bytes actually served. This does the deb+apk half (the rpm half landed in #118).
How:
- Derive the deb
ReleaseDate:from the newest persistedcreated_at(RFC1123Z, UTC) instead oftime.Now(); carrycreated_atthrough the deb metadata SELECT andDebMetadata. An empty repo falls back to the Unix epoch. This also stopsDate:running ahead of wall clock. - Pin the apk
APKINDEXtar headerModTimeto the Unix epoch instead of the zero-valuetime.Time, so it is never wall-clock derived. - Give both list queries a genuine total order by adding a
file_pathtiebreak (name/version/arch is not unique). - Add guard tests: deb generators byte-identical across generations; the
Releasechecksum/size matches the servedPackages/Packages.gzbytes (the exact apt invariant);Date:pinned tocreated_at; apk index byte-identical and tarModTimepinned to epoch.
Reviewed-on: #119
Co-authored-by: unkin-agent unkin-agent@unkin.net
Co-committed-by: unkin-agent unkin-agent@unkin.netDownloads
- Derive the deb