• v3.9.0 5fde0ee58e

    Add github_deb metadata-only package type (#112)
    ci/woodpecker/tag/docker Pipeline was successful

    unkin-agent released this 2026-08-11 23:28:11 +10:00

    Why

    This stacks the Debian/apt analog of github_rpm on top of the deb local+remote work (#111). It lets a GitHub repo's .deb release assets be consumed as a real apt repository without artifactapi ever precaching whole packages: it derives per-asset control metadata from a ranged prefix fetch, synthesizes a flat apt repo from the cache, and redirects the actual .deb downloads to a backend releases_remote (the generic github.com remote).

    Base is benvin/deb-local-remote (stacked) to keep the diff atomic.

    How

    • Adds github_deb to the package-type enum and validity map.
    • Adds the github_deb provider mirroring github_rpm: ServeRemote serves Packages/Packages.gz/Release, returns 404 for InRelease/Release.gpg (unsigned, consumed via [trusted=yes]), and 302-redirects *.deb to {proxyBaseURL}/api/v1/remote/{releases_remote}/{path}; cold-start prime with a retryable 503.
    • deriveAsset ranged-GETs the front of the .deb (an ar archive), locates and fully reads control.tar.*, and parses the control paragraph — doubling the range if the control member is truncated. The Packages SHA256 comes from the GitHub asset digest when present, else a one-time full stream; MD5sum is left unset (apt verifies against SHA256 under [trusted=yes]).
    • Adds a github_deb background Syncer (own worker pool, shared rate limiter, deduped queue) with per-remote DB-lease-gated scans so only one replica scans per window.
    • Adds the github_deb_sync_state table plus ListGitHubDebRemotes / ClaimGitHubDebSyncLease / ReleaseGitHubDebSyncLease DB helpers, kept separate from the rpm ones.
    • Primes github_deb remotes on create and runs the deb syncer alongside the rpm one; prime-on-create is routed by package type.
    • Reuses the deb apt-index generators and control parser; the Packages generator now skips empty hash lines so a SHA256-only entry is valid.

    Notes / deviations

    • Filename convention: the Filename stored in the Packages index is the github-relative asset path (same as rpm's assetPath), not pool/<asset>. This is required for the .deb 302 to {releases_remote=github}/{path} to resolve against github.com; it still matches the *.deb redirect rule.
    • GitHub client helpers (releases pagination, ranged GET, auth headers) are duplicated into the deb package rather than shared, because the rpm equivalents are unexported in package rpm and the task requires not modifying the rpm provider.
    • go build, go vet, go mod tidy, and make test (-race, incl. the Postgres lease integration tests) all pass; pre-commit clean.

    Do not merge — for review.


    Co-authored-by: unkin-agent unkin-agent@git.unkin.net
    Reviewed-on: #112
    Co-authored-by: unkin-agent unkin-agent@unkin.net
    Co-committed-by: unkin-agent unkin-agent@unkin.net

    Downloads