Files
unraid-podman/versions.env
maggesandClaude Sonnet 5 2b79411b68 Replace vendored docker-compose with podman-compose
podman-compose and docker-compose aren't discovered the same way by
`podman compose` - verified live (a fake-binary test reading podman's own
provider-search error output) that docker-compose is searched for by
exact path across a fixed list of CLI-plugin directories, while
podman-compose is instead looked up as a plain command on $PATH. This
package installs to /usr/local/bin/podman-compose accordingly, not under
any cli-plugins/ directory.

Unlike docker-compose (a single static Go binary), podman-compose is a
Python script with two runtime dependencies neither of which ship with
Unraid's own Python3 - PyYAML and python-dotenv, vendored here as plain
pure-Python source (no C extension build; PyYAML's own fallback handles
its optional C accelerator being absent).

Verified end-to-end on a real host: with the previous docker-compose
binary temporarily moved aside to confirm podman-compose was actually the
one invoked, `podman compose up/ps/down` ran a real compose project
correctly, including a live HTTP check against the started service.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 18:35:38 +00:00

170 lines
10 KiB
Bash

# =============================================================================
# versions.env — single source of truth for upstream component versions.
#
# Every SlackBuild under packages/*/ and the orchestrator
# (scripts/build-packages.sh) source this file instead of hardcoding a
# version or URL. This is what makes the build reproducible: given the same
# versions.env, the same source tarballs (verified by SHA256) are fetched and
# built, every time.
#
# To bump a component's version, run scripts/update-versions.sh <component>
# (fetches the new upstream release, recomputes the checksum, rewrites the
# corresponding block below) rather than editing hashes by hand.
#
# SHA256 sums below were computed directly against the upstream source
# tarball/snapshot at the time of pinning (see the fetch command in each
# comment). GitHub's auto-generated "archive/refs/tags" tarballs are stable
# in practice but are NOT cryptographically signed by upstream — treat this
# checksum as tamper-evidence against a compromised mirror/CDN, not as a
# replacement for verifying upstream's own release signing where available.
# =============================================================================
# --- podman ------------------------------------------------------------------
# https://github.com/containers/podman
PODMAN_VERSION="6.0.1"
PODMAN_SRC_URL="https://github.com/containers/podman/archive/refs/tags/v${PODMAN_VERSION}.tar.gz"
PODMAN_SRC_SHA256="4829d7c1423523a6a4d5537dea7968ae7f6c22ed7f1d5f416638fd81c83caa47"
# --- conmon --------------------------------------------------------------
# https://github.com/containers/conmon
CONMON_VERSION="2.2.1"
CONMON_SRC_URL="https://github.com/containers/conmon/archive/refs/tags/v${CONMON_VERSION}.tar.gz"
CONMON_SRC_SHA256="814fb5979a3a4b8576b1f901e606b482bebb41cb7e57926e6d5765ee786b96d3"
# --- crun ----------------------------------------------------------------
# https://github.com/containers/crun
CRUN_VERSION="1.28"
CRUN_SRC_URL="https://github.com/containers/crun/archive/refs/tags/${CRUN_VERSION}.tar.gz"
CRUN_SRC_SHA256="90284c7f097f8ee72a6447978c263e1b1355727c2f2ca0ac667e6d57788f46f5"
# crun's build depends on the libocispec git submodule, which GitHub's
# source archive (fetched above) never includes — a plain tarball has no
# .git directory for `git submodule update` to work against, so that has
# to be fetched as its own separate pinned source instead. Commit pinned
# to exactly what crun 1.28 references (verified via
# `curl https://api.github.com/repos/containers/crun/contents/libocispec?ref=1.28`);
# re-derive it the same way whenever CRUN_VERSION changes.
LIBOCISPEC_COMMIT="8034d0ecd27f646ba3ffae5ff24db234ce062825"
LIBOCISPEC_SRC_URL="https://github.com/containers/libocispec/archive/${LIBOCISPEC_COMMIT}.tar.gz"
LIBOCISPEC_SRC_SHA256="3e9170e54ddf487dc087ff1b88d0722e134a206cf36bba87cc946819ccf036ab"
# libocispec itself has two more git submodules (same problem, one level
# deeper) — its own generate.py needs both schema trees present at build
# time. Commits pinned to exactly what the LIBOCISPEC_COMMIT above
# references (verified the same way, via
# `curl https://api.github.com/repos/containers/libocispec/contents/image-spec?ref=$LIBOCISPEC_COMMIT`
# and .../runtime-spec?ref=...).
IMAGE_SPEC_COMMIT="26647a49f642c7d22a1cd3aa0a48e4650a542269"
IMAGE_SPEC_SRC_URL="https://github.com/opencontainers/image-spec/archive/${IMAGE_SPEC_COMMIT}.tar.gz"
IMAGE_SPEC_SRC_SHA256="8668357de6a1162220b2d1fb654a4182a55844b90ad2774c3b99640eec7e2f54"
RUNTIME_SPEC_COMMIT="d64c1d945da7cf6970061c7c9ff4391fafdf2a15"
RUNTIME_SPEC_SRC_URL="https://github.com/opencontainers/runtime-spec/archive/${RUNTIME_SPEC_COMMIT}.tar.gz"
RUNTIME_SPEC_SRC_SHA256="1698ebaa7ff07f8409c084fe9539d0391820e71b7a6e6d877aa1ce8b383a4b50"
# --- netavark --------------------------------------------------------------
# https://github.com/containers/netavark
NETAVARK_VERSION="2.0.0"
NETAVARK_SRC_URL="https://github.com/containers/netavark/archive/refs/tags/v${NETAVARK_VERSION}.tar.gz"
NETAVARK_SRC_SHA256="031aeeacc930382e8635d40a885798eff1da164dfcf9024b698f822e5995d9c8"
# --- aardvark-dns ----------------------------------------------------------
# https://github.com/containers/aardvark-dns
AARDVARK_DNS_VERSION="2.0.0"
AARDVARK_DNS_SRC_URL="https://github.com/containers/aardvark-dns/archive/refs/tags/v${AARDVARK_DNS_VERSION}.tar.gz"
AARDVARK_DNS_SRC_SHA256="d3f5d6b3be3c2d80e8257fb9467e34ff104f299474427979454034dca6dc88cc"
# --- fuse-overlayfs --------------------------------------------------------
# https://github.com/containers/fuse-overlayfs
FUSE_OVERLAYFS_VERSION="1.17"
FUSE_OVERLAYFS_SRC_URL="https://github.com/containers/fuse-overlayfs/archive/refs/tags/v${FUSE_OVERLAYFS_VERSION}.tar.gz"
FUSE_OVERLAYFS_SRC_SHA256="cefffecfbb001b2784f19af344f27eae07b31a4faa38d345b738af96b2bec59e"
# --- passt -------------------------------------------------------------------
# https://passt.top/passt/about/ — "Plug A Simple Socket Transport". Podman's
# modern (post-slirp4netns) rootless network transport. Upstream has NO
# GitHub mirror and no semver tags; it is released continuously from the
# cgit-hosted git repository at https://passt.top/passt/, identified by full
# git commit hash. We pin to a specific commit snapshot for reproducibility,
# fetched via cgit's snapshot endpoint:
# https://passt.top/passt/snapshot/passt-<commit>.tar.gz
PASST_COMMIT="6ef3d1c86ffc690a17a9a4445df4a741446bcd44"
PASST_VERSION="git${PASST_COMMIT:0:7}"
PASST_SRC_URL="https://passt.top/passt/snapshot/passt-${PASST_COMMIT}.tar.gz"
PASST_SRC_SHA256="4c58a77504a77d613464dddf22ae69d749a5ba64cb87e44c3b8c252333e209fc"
# --- catatonit -----------------------------------------------------------
# https://github.com/openSUSE/catatonit — the init process podman runs
# inside every pod's infra container to reap zombies; not built by
# podman's own Makefile, not packaged by Slackware, needed at runtime on
# every target Unraid install (found by live-testing `podman pod create`
# against a real install: "finding catatonit binary: exec: catatonit: no
# such file or directory"). Upstream publishes a prebuilt static
# (non-dynamic-linked) x86_64 binary release asset — no from-source build
# needed, no runtime library surprises like the crun/yajl chain had.
CATATONIT_VERSION="0.2.1"
CATATONIT_SRC_URL="https://github.com/openSUSE/catatonit/releases/download/v${CATATONIT_VERSION}/catatonit.x86_64"
CATATONIT_SRC_SHA256="8293951eaa7767fa411e3b89777bd01bc5e56db9ba6d145ad10cc4d05b01e961"
# --- nftables --------------------------------------------------------------
# netavark >= 2.0 dropped its iptables firewall driver entirely (see
# config/containers.conf and docs/ARCHITECTURE.md section 8) — nftables is
# now the only viable firewall backend on Unraid (no systemd/dbus for
# firewalld), but Unraid OS ships no `nft` binary. Slackware — Unraid's own
# base distro — already builds and ships this as an official package, so
# it is vendored through as-is (verified working live) rather than
# rebuilt from source: nftables pulls in its own dependency chain
# (libmnl, libnftnl, gmp, ...) for no benefit over the distro's own build,
# which is already correctly built for this exact environment.
NFTABLES_VERSION="1.0.1"
NFTABLES_SRC_URL="http://slackware.osuosl.org/slackware64-15.0/slackware64/n/nftables-${NFTABLES_VERSION}-x86_64-1.txz"
NFTABLES_SRC_SHA256="239e70d48edd6667ce875ff0d339b6f63c1fc94c472524d58772310b1006d31c"
# --- podman-compose -----------------------------------------------------------
# https://github.com/containers/podman-compose — `podman compose` (backing
# webui/plugins/podman/ajax/compose.php, the WebUI's Compose panel) has no
# compose implementation of its own; it needs an external "compose
# provider" command. This project previously vendored docker/compose (the
# Go CLI-plugin binary) for that role, found by podman searching a fixed
# set of CLI-plugin directories for a binary named exactly
# "docker-compose". podman-compose is looked up differently — verified
# live (placing a fake executable and watching podman's own error output
# list its search order) that it's found as a plain command on $PATH,
# not from those same CLI-plugin directories — so it's installed as
# /usr/local/bin/podman-compose, not under any cli-plugins/ path.
#
# Unlike docker-compose, podman-compose is a single Python script, not a
# compiled binary — Unraid ships Python3 itself, but not either of its two
# runtime dependencies (PyYAML, python-dotenv), so those are vendored
# alongside it as plain pure-Python source (no C extension build; PyYAML's
# own __init__.py falls back gracefully when its optional C accelerator
# isn't importable — verified by reading it, not assumed).
PODMAN_COMPOSE_VERSION="1.6.0"
PODMAN_COMPOSE_SRC_URL="https://raw.githubusercontent.com/containers/podman-compose/v${PODMAN_COMPOSE_VERSION}/podman_compose.py"
PODMAN_COMPOSE_SRC_SHA256="10df1662477a673dc803c03e89c1bc1fba6c8c091e716fb6c7dd09c0081e1255"
PYYAML_VERSION="6.0.3"
PYYAML_SRC_URL="https://files.pythonhosted.org/packages/05/8e/961c0007c59b8dd7729d542c61a4d537767a59645b82a0b521206e1e25c2/pyyaml-${PYYAML_VERSION}.tar.gz"
PYYAML_SRC_SHA256="d76623373421df22fb4cf8817020cbb7ef15c725b9d5e45f17e189bfc384190f"
PYTHON_DOTENV_VERSION="1.2.2"
PYTHON_DOTENV_SRC_URL="https://files.pythonhosted.org/packages/82/ed/0301aeeac3e5353ef3d94b6ec08bbcabd04a72018415dcb29e588514bba8/python_dotenv-${PYTHON_DOTENV_VERSION}.tar.gz"
PYTHON_DOTENV_SRC_SHA256="2c371a91fbd7ba082c2c1dc1f8bf89ca22564a087c2c287cd9b662adde799cf3"
# =============================================================================
# Slackware package BUILD number (not upstream version). Bump this if a
# package must be rebuilt without an upstream version change (e.g. a
# packaging-only fix). Reset to 1 whenever *_VERSION above changes.
# =============================================================================
PKG_BUILD="1"
# Slackware package architecture. Unraid is x86_64-only today; kept as a
# variable rather than hardcoded so the build scripts don't need a second
# source of truth if that ever changes.
PKG_ARCH="x86_64"
# Suffix appended to every package's tag field (Slackware convention:
# <name>-<version>-<arch>-<build><tag>.txz), identifies packages built by
# this project as opposed to a stock Slackware/SBo package of the same name.
PKG_TAG="_unraidpodman"