Add catatonit/nftables/docker-compose packages, fix CSRF/streaming/storage bugs found by live testing
- Package #9-11: catatonit (pod infra init), nftables (netavark firewall backend), docker-compose (external compose provider for `podman compose`) — all vendored prebuilt binaries, versions.env pinned, propagated through build-packages.sh/release.sh/podman.plg/verify+update-packages.sh. - Fix WebUI: every POST action was silently failing (empty response body) because Unraid's own CSRF protection was never satisfied — app.js now sends the page's csrf_token as X-CSRF-Token. - Fix WebUI: PodmanClient::pullImage() assumed a single JSON response, but /images/pull actually streams newline-delimited JSON — every successful pull was throwing "Expected a JSON object/array response". - Fix WebUI: compose.php's up/down status detection had the same single-JSON-vs-NDJSON bug for `podman compose ps`, plus stderr was corrupting the parse. - Add cache-busting (?v=<mtime>) to Podman.page's script/style tags so a redeployed JS/CSS fix isn't served stale from browser cache. - Add a reusable modal dialog (app.js openFormModal) replacing prompt()/alert() for New Volume/Network/Pull Image. - Add host-path (bind-mount) support when creating a named volume. - Add Create Container (image, name, network mode incl. custom networks, ports, volumes, env, restart policy, privileged, start-after-create), auto-pulling the image on first use since /containers/create doesn't. All fixes verified live against a real podman system service and, where reachable, via the actual WebUI over the real socket — not just unit-level. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
# packages/nftables/
|
||||
|
||||
Pinned version: see `NFTABLES_VERSION` in [versions.env](../../versions.env).
|
||||
|
||||
Not built from source, and no `slack-desc` here (unlike this project's
|
||||
other packages) — `nftables.SlackBuild` fetches Slackware's own official
|
||||
`nftables` package and re-hosts it as-is under this project's naming and
|
||||
checksum convention. It's already a correctly-built Slackware package
|
||||
(built by the Slackware team for exactly this OS/glibc/arch); the
|
||||
slack-desc bundled inside it travels along unchanged.
|
||||
|
||||
netavark >= 2.0 dropped its iptables firewall driver entirely — nftables
|
||||
(via the `nft` binary this package provides) is the only firewall backend
|
||||
that works on Unraid (firewalld needs systemd/dbus, which Unraid has
|
||||
neither of). Unraid OS itself ships no `nft` binary.
|
||||
|
||||
Found by live-testing this plugin end-to-end against a real Unraid
|
||||
install, not from reading netavark's docs — see
|
||||
[docs/ARCHITECTURE.md, section 8](../../docs/ARCHITECTURE.md#8-netzwerke).
|
||||
Executable
+45
@@ -0,0 +1,45 @@
|
||||
#!/bin/bash
|
||||
# =============================================================================
|
||||
# packages/nftables/nftables.SlackBuild
|
||||
#
|
||||
# Vendors Slackware's own official nftables package as-is — not rebuilt
|
||||
# from source, see versions.env's NFTABLES_* block for why. Unlike every
|
||||
# other package here, there is no compile step: the fetched .txz is
|
||||
# already a correctly-built Slackware package (built by the Slackware
|
||||
# team for exactly this OS/glibc/arch), so it is re-hosted under this
|
||||
# project's naming/checksum convention rather than unpacked and restaged
|
||||
# through makepkg, which would add risk (differing compression/metadata)
|
||||
# for no benefit.
|
||||
#
|
||||
# netavark >= 2.0 requires the nftables firewall driver (its iptables
|
||||
# driver was removed entirely) but Unraid OS ships no `nft` binary — see
|
||||
# config/containers.conf and docs/ARCHITECTURE.md section 8. Without this
|
||||
# package, every `podman run`/`podman pod create` that touches networking
|
||||
# fails with "netavark: Must provide a valid firewall backend" (found by
|
||||
# live-testing against a real Unraid install).
|
||||
# =============================================================================
|
||||
|
||||
set -eu
|
||||
|
||||
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||
# shellcheck source=/dev/null
|
||||
. "$REPO_ROOT/scripts/lib/slackbuild-common.sh"
|
||||
# shellcheck source=/dev/null
|
||||
. "$REPO_ROOT/versions.env"
|
||||
|
||||
VERSION="$NFTABLES_VERSION"
|
||||
ARCH="$PKG_ARCH"
|
||||
BUILD="$PKG_BUILD"
|
||||
TAG="$PKG_TAG"
|
||||
|
||||
sb_init "nftables"
|
||||
|
||||
official_pkg=$(sb_fetch_and_verify "$NFTABLES_SRC_URL" "$NFTABLES_SRC_SHA256" "nftables-$VERSION-official.txz")
|
||||
|
||||
pkg_file="nftables-$VERSION-$ARCH-$BUILD$TAG.txz"
|
||||
cp "$official_pkg" "$OUTPUT/$pkg_file"
|
||||
|
||||
( cd "$OUTPUT" && sha256sum "$pkg_file" > "$pkg_file.sha256" )
|
||||
( cd "$OUTPUT" && md5sum "$pkg_file" > "$pkg_file.md5" )
|
||||
|
||||
echo "==> [nftables] vendored official Slackware package as $OUTPUT/$pkg_file"
|
||||
Reference in New Issue
Block a user