-
released this
2026-08-11 23:28:11 +10:00 Why
This stacks the Debian/apt analog of
github_rpmon top of the deb local+remote work (#111). It lets a GitHub repo's.debrelease assets be consumed as a real apt repository without artifactapi ever precaching whole packages: it derives per-asset control metadata from a ranged prefix fetch, synthesizes a flat apt repo from the cache, and redirects the actual.debdownloads to a backendreleases_remote(the generic github.com remote).Base is
benvin/deb-local-remote(stacked) to keep the diff atomic.How
- Adds
github_debto the package-type enum and validity map. - Adds the
github_debprovider mirroringgithub_rpm:ServeRemoteservesPackages/Packages.gz/Release, returns 404 forInRelease/Release.gpg(unsigned, consumed via[trusted=yes]), and 302-redirects*.debto{proxyBaseURL}/api/v1/remote/{releases_remote}/{path}; cold-start prime with a retryable 503. deriveAssetranged-GETs the front of the.deb(anararchive), locates and fully readscontrol.tar.*, and parses the control paragraph — doubling the range if the control member is truncated. The PackagesSHA256comes from the GitHub assetdigestwhen present, else a one-time full stream;MD5sumis left unset (apt verifies against SHA256 under[trusted=yes]).- Adds a
github_debbackground Syncer (own worker pool, shared rate limiter, deduped queue) with per-remote DB-lease-gated scans so only one replica scans per window. - Adds the
github_deb_sync_statetable plusListGitHubDebRemotes/ClaimGitHubDebSyncLease/ReleaseGitHubDebSyncLeaseDB helpers, kept separate from the rpm ones. - Primes
github_debremotes on create and runs the deb syncer alongside the rpm one; prime-on-create is routed by package type. - Reuses the deb apt-index generators and control parser; the Packages generator now skips empty hash lines so a SHA256-only entry is valid.
Notes / deviations
- Filename convention: the
Filenamestored in the Packages index is the github-relative asset path (same as rpm'sassetPath), notpool/<asset>. This is required for the.deb302 to{releases_remote=github}/{path}to resolve against github.com; it still matches the*.debredirect rule. - GitHub client helpers (releases pagination, ranged GET, auth headers) are duplicated into the deb package rather than shared, because the rpm equivalents are unexported in
package rpmand the task requires not modifying the rpm provider. go build,go vet,go mod tidy, andmake test(-race, incl. the Postgres lease integration tests) all pass; pre-commit clean.
Do not merge — for review.
Co-authored-by: unkin-agent unkin-agent@git.unkin.net
Reviewed-on: #112
Co-authored-by: unkin-agent unkin-agent@unkin.net
Co-committed-by: unkin-agent unkin-agent@unkin.netDownloads
- Adds