#!/bin/bash # ============================================================================= # packages/nftables/nftables.SlackBuild # # Vendors Slackware's own official nftables package as-is — not rebuilt # from source, see versions.env's NFTABLES_* block for why. Unlike every # other package here, there is no compile step: the fetched .txz is # already a correctly-built Slackware package (built by the Slackware # team for exactly this OS/glibc/arch), so it is re-hosted under this # project's naming/checksum convention rather than unpacked and restaged # through makepkg, which would add risk (differing compression/metadata) # for no benefit. # # netavark >= 2.0 requires the nftables firewall driver (its iptables # driver was removed entirely) but Unraid OS ships no `nft` binary — see # config/containers.conf and docs/ARCHITECTURE.md section 8. Without this # package, every `podman run`/`podman pod create` that touches networking # fails with "netavark: Must provide a valid firewall backend" (found by # live-testing against a real Unraid install). # ============================================================================= set -eu REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" # shellcheck source=/dev/null . "$REPO_ROOT/scripts/lib/slackbuild-common.sh" # shellcheck source=/dev/null . "$REPO_ROOT/versions.env" VERSION="$NFTABLES_VERSION" ARCH="$PKG_ARCH" BUILD="$PKG_BUILD" TAG="$PKG_TAG" sb_init "nftables" official_pkg=$(sb_fetch_and_verify "$NFTABLES_SRC_URL" "$NFTABLES_SRC_SHA256" "nftables-$VERSION-official.txz") pkg_file="nftables-$VERSION-$ARCH-$BUILD$TAG.txz" cp "$official_pkg" "$OUTPUT/$pkg_file" ( cd "$OUTPUT" && sha256sum "$pkg_file" > "$pkg_file.sha256" ) ( cd "$OUTPUT" && md5sum "$pkg_file" > "$pkg_file.md5" ) echo "==> [nftables] vendored official Slackware package as $OUTPUT/$pkg_file"