Add catatonit/nftables/docker-compose packages, fix CSRF/streaming/storage bugs found by live testing
- Package #9-11: catatonit (pod infra init), nftables (netavark firewall backend), docker-compose (external compose provider for `podman compose`) — all vendored prebuilt binaries, versions.env pinned, propagated through build-packages.sh/release.sh/podman.plg/verify+update-packages.sh. - Fix WebUI: every POST action was silently failing (empty response body) because Unraid's own CSRF protection was never satisfied — app.js now sends the page's csrf_token as X-CSRF-Token. - Fix WebUI: PodmanClient::pullImage() assumed a single JSON response, but /images/pull actually streams newline-delimited JSON — every successful pull was throwing "Expected a JSON object/array response". - Fix WebUI: compose.php's up/down status detection had the same single-JSON-vs-NDJSON bug for `podman compose ps`, plus stderr was corrupting the parse. - Add cache-busting (?v=<mtime>) to Podman.page's script/style tags so a redeployed JS/CSS fix isn't served stale from browser cache. - Add a reusable modal dialog (app.js openFormModal) replacing prompt()/alert() for New Volume/Network/Pull Image. - Add host-path (bind-mount) support when creating a named volume. - Add Create Container (image, name, network mode incl. custom networks, ports, volumes, env, restart policy, privileged, start-after-create), auto-pulling the image on first use since /containers/create doesn't. All fixes verified live against a real podman system service and, where reachable, via the actual WebUI over the real socket — not just unit-level. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -93,6 +93,50 @@ PASST_VERSION="git${PASST_COMMIT:0:7}"
|
||||
PASST_SRC_URL="https://passt.top/passt/snapshot/passt-${PASST_COMMIT}.tar.gz"
|
||||
PASST_SRC_SHA256="4c58a77504a77d613464dddf22ae69d749a5ba64cb87e44c3b8c252333e209fc"
|
||||
|
||||
# --- catatonit -----------------------------------------------------------
|
||||
# https://github.com/openSUSE/catatonit — the init process podman runs
|
||||
# inside every pod's infra container to reap zombies; not built by
|
||||
# podman's own Makefile, not packaged by Slackware, needed at runtime on
|
||||
# every target Unraid install (found by live-testing `podman pod create`
|
||||
# against a real install: "finding catatonit binary: exec: catatonit: no
|
||||
# such file or directory"). Upstream publishes a prebuilt static
|
||||
# (non-dynamic-linked) x86_64 binary release asset — no from-source build
|
||||
# needed, no runtime library surprises like the crun/yajl chain had.
|
||||
CATATONIT_VERSION="0.2.1"
|
||||
CATATONIT_SRC_URL="https://github.com/openSUSE/catatonit/releases/download/v${CATATONIT_VERSION}/catatonit.x86_64"
|
||||
CATATONIT_SRC_SHA256="8293951eaa7767fa411e3b89777bd01bc5e56db9ba6d145ad10cc4d05b01e961"
|
||||
|
||||
# --- nftables --------------------------------------------------------------
|
||||
# netavark >= 2.0 dropped its iptables firewall driver entirely (see
|
||||
# config/containers.conf and docs/ARCHITECTURE.md section 8) — nftables is
|
||||
# now the only viable firewall backend on Unraid (no systemd/dbus for
|
||||
# firewalld), but Unraid OS ships no `nft` binary. Slackware — Unraid's own
|
||||
# base distro — already builds and ships this as an official package, so
|
||||
# it is vendored through as-is (verified working live) rather than
|
||||
# rebuilt from source: nftables pulls in its own dependency chain
|
||||
# (libmnl, libnftnl, gmp, ...) for no benefit over the distro's own build,
|
||||
# which is already correctly built for this exact environment.
|
||||
NFTABLES_VERSION="1.0.1"
|
||||
NFTABLES_SRC_URL="http://slackware.osuosl.org/slackware64-15.0/slackware64/n/nftables-${NFTABLES_VERSION}-x86_64-1.txz"
|
||||
NFTABLES_SRC_SHA256="239e70d48edd6667ce875ff0d339b6f63c1fc94c472524d58772310b1006d31c"
|
||||
|
||||
# --- docker-compose ----------------------------------------------------------
|
||||
# https://github.com/docker/compose — the Compose v2 CLI-plugin binary
|
||||
# (Go, not the older Python podman-compose). `podman compose` (backing
|
||||
# webui/plugins/podman/ajax/compose.php, the WebUI's Compose panel) has no
|
||||
# compose implementation of its own — it searches a fixed set of
|
||||
# CLI-plugin directories for a binary named exactly "docker-compose" and
|
||||
# shells out to it. Without one present, every Compose panel action fails
|
||||
# outright (found by live-testing: it only worked on the test host because
|
||||
# that host happened to already have Docker's own compose plugin
|
||||
# installed from an unrelated, pre-existing Docker setup — a clean Unraid
|
||||
# install has none). Upstream publishes a prebuilt static x86_64 binary
|
||||
# release asset (verified via `ldd`: "not a dynamic executable") plus a
|
||||
# matching .sha256 sidecar — no from-source build needed.
|
||||
DOCKER_COMPOSE_VERSION="5.3.1"
|
||||
DOCKER_COMPOSE_SRC_URL="https://github.com/docker/compose/releases/download/v${DOCKER_COMPOSE_VERSION}/docker-compose-linux-x86_64"
|
||||
DOCKER_COMPOSE_SRC_SHA256="f9ebc6ebdb19d769b793c245a736caaeb198c62587f13b25c660c13b4987f959"
|
||||
|
||||
# =============================================================================
|
||||
# Slackware package BUILD number (not upstream version). Bump this if a
|
||||
# package must be rebuilt without an upstream version change (e.g. a
|
||||
|
||||
Reference in New Issue
Block a user