• deb/apk: make local repodata deterministic (#119)
    ci/woodpecker/tag/docker Pipeline was successful

    unkin-agent released this 2026-08-12 23:32:07 +10:00

    Part of #117. Local generated repodata must be byte-identical across the two no-affinity replicas and across every regeneration, so apt/apk never hit a checksum mismatch between an index's advertised hash and the bytes actually served. This does the deb+apk half (the rpm half landed in #118).

    How:

    • Derive the deb Release Date: from the newest persisted created_at (RFC1123Z, UTC) instead of time.Now(); carry created_at through the deb metadata SELECT and DebMetadata. An empty repo falls back to the Unix epoch. This also stops Date: running ahead of wall clock.
    • Pin the apk APKINDEX tar header ModTime to the Unix epoch instead of the zero-value time.Time, so it is never wall-clock derived.
    • Give both list queries a genuine total order by adding a file_path tiebreak (name/version/arch is not unique).
    • Add guard tests: deb generators byte-identical across generations; the Release checksum/size matches the served Packages/Packages.gz bytes (the exact apt invariant); Date: pinned to created_at; apk index byte-identical and tar ModTime pinned to epoch.

    Reviewed-on: #119
    Co-authored-by: unkin-agent unkin-agent@unkin.net
    Co-committed-by: unkin-agent unkin-agent@unkin.net

    Downloads