- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt, and fuse-overlayfs to verified upstream source checksums; SlackBuild recipes, scripts/build-packages.sh, checksums.sh, release.sh, and update-versions.sh implement the reproducible pipeline; GitHub Actions workflows build in a Slackware container and publish releases without committing any binaries. - plugin/podman.plg installs/updates/removes all eight packages (the seven components plus the plugin's own unraid-podman scaffolding package) via upgradepkg, using the official Unraid array-event hook mechanism (event/disks_mounted, event/stopping) instead of editing /boot/config/go. rc.podman and the sbin/ helper scripts implement storage creation, config seeding/sync, preflight checks, autostart with per-container Safe-Mode, and package verify/update/rollback. - webui/plugins/podman implements the Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, and Settings panels against the approved mockup (webui/mockups/prototype.html), talking to podman system service exclusively via PodmanClient.php (libpod REST API over the Unix socket), with two documented exceptions: Terminal's one-shot exec model and Compose's use of the podman compose CLI, since libpod has no REST equivalent for either. - docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions and honest current status (syntax-checked, unit- and integration-tested against fake sockets/servers; not yet run against a real Unraid/Podman/Slackware system). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
87 lines
4.8 KiB
Bash
87 lines
4.8 KiB
Bash
# =============================================================================
|
|
# versions.env — single source of truth for upstream component versions.
|
|
#
|
|
# Every SlackBuild under packages/*/ and the orchestrator
|
|
# (scripts/build-packages.sh) source this file instead of hardcoding a
|
|
# version or URL. This is what makes the build reproducible: given the same
|
|
# versions.env, the same source tarballs (verified by SHA256) are fetched and
|
|
# built, every time.
|
|
#
|
|
# To bump a component's version, run scripts/update-versions.sh <component>
|
|
# (fetches the new upstream release, recomputes the checksum, rewrites the
|
|
# corresponding block below) rather than editing hashes by hand.
|
|
#
|
|
# SHA256 sums below were computed directly against the upstream source
|
|
# tarball/snapshot at the time of pinning (see the fetch command in each
|
|
# comment). GitHub's auto-generated "archive/refs/tags" tarballs are stable
|
|
# in practice but are NOT cryptographically signed by upstream — treat this
|
|
# checksum as tamper-evidence against a compromised mirror/CDN, not as a
|
|
# replacement for verifying upstream's own release signing where available.
|
|
# =============================================================================
|
|
|
|
# --- podman ------------------------------------------------------------------
|
|
# https://github.com/containers/podman
|
|
PODMAN_VERSION="6.0.1"
|
|
PODMAN_SRC_URL="https://github.com/containers/podman/archive/refs/tags/v${PODMAN_VERSION}.tar.gz"
|
|
PODMAN_SRC_SHA256="4829d7c1423523a6a4d5537dea7968ae7f6c22ed7f1d5f416638fd81c83caa47"
|
|
|
|
# --- conmon --------------------------------------------------------------
|
|
# https://github.com/containers/conmon
|
|
CONMON_VERSION="2.2.1"
|
|
CONMON_SRC_URL="https://github.com/containers/conmon/archive/refs/tags/v${CONMON_VERSION}.tar.gz"
|
|
CONMON_SRC_SHA256="814fb5979a3a4b8576b1f901e606b482bebb41cb7e57926e6d5765ee786b96d3"
|
|
|
|
# --- crun ----------------------------------------------------------------
|
|
# https://github.com/containers/crun
|
|
CRUN_VERSION="1.28"
|
|
CRUN_SRC_URL="https://github.com/containers/crun/archive/refs/tags/${CRUN_VERSION}.tar.gz"
|
|
CRUN_SRC_SHA256="90284c7f097f8ee72a6447978c263e1b1355727c2f2ca0ac667e6d57788f46f5"
|
|
|
|
# --- netavark --------------------------------------------------------------
|
|
# https://github.com/containers/netavark
|
|
NETAVARK_VERSION="2.0.0"
|
|
NETAVARK_SRC_URL="https://github.com/containers/netavark/archive/refs/tags/v${NETAVARK_VERSION}.tar.gz"
|
|
NETAVARK_SRC_SHA256="031aeeacc930382e8635d40a885798eff1da164dfcf9024b698f822e5995d9c8"
|
|
|
|
# --- aardvark-dns ----------------------------------------------------------
|
|
# https://github.com/containers/aardvark-dns
|
|
AARDVARK_DNS_VERSION="2.0.0"
|
|
AARDVARK_DNS_SRC_URL="https://github.com/containers/aardvark-dns/archive/refs/tags/v${AARDVARK_DNS_VERSION}.tar.gz"
|
|
AARDVARK_DNS_SRC_SHA256="d3f5d6b3be3c2d80e8257fb9467e34ff104f299474427979454034dca6dc88cc"
|
|
|
|
# --- fuse-overlayfs --------------------------------------------------------
|
|
# https://github.com/containers/fuse-overlayfs
|
|
FUSE_OVERLAYFS_VERSION="1.17"
|
|
FUSE_OVERLAYFS_SRC_URL="https://github.com/containers/fuse-overlayfs/archive/refs/tags/v${FUSE_OVERLAYFS_VERSION}.tar.gz"
|
|
FUSE_OVERLAYFS_SRC_SHA256="cefffecfbb001b2784f19af344f27eae07b31a4faa38d345b738af96b2bec59e"
|
|
|
|
# --- passt -------------------------------------------------------------------
|
|
# https://passt.top/passt/about/ — "Plug A Simple Socket Transport". Podman's
|
|
# modern (post-slirp4netns) rootless network transport. Upstream has NO
|
|
# GitHub mirror and no semver tags; it is released continuously from the
|
|
# cgit-hosted git repository at https://passt.top/passt/, identified by full
|
|
# git commit hash. We pin to a specific commit snapshot for reproducibility,
|
|
# fetched via cgit's snapshot endpoint:
|
|
# https://passt.top/passt/snapshot/passt-<commit>.tar.gz
|
|
PASST_COMMIT="6ef3d1c86ffc690a17a9a4445df4a741446bcd44"
|
|
PASST_VERSION="git${PASST_COMMIT:0:7}"
|
|
PASST_SRC_URL="https://passt.top/passt/snapshot/passt-${PASST_COMMIT}.tar.gz"
|
|
PASST_SRC_SHA256="4c58a77504a77d613464dddf22ae69d749a5ba64cb87e44c3b8c252333e209fc"
|
|
|
|
# =============================================================================
|
|
# Slackware package BUILD number (not upstream version). Bump this if a
|
|
# package must be rebuilt without an upstream version change (e.g. a
|
|
# packaging-only fix). Reset to 1 whenever *_VERSION above changes.
|
|
# =============================================================================
|
|
PKG_BUILD="1"
|
|
|
|
# Slackware package architecture. Unraid is x86_64-only today; kept as a
|
|
# variable rather than hardcoded so the build scripts don't need a second
|
|
# source of truth if that ever changes.
|
|
PKG_ARCH="x86_64"
|
|
|
|
# Suffix appended to every package's tag field (Slackware convention:
|
|
# <name>-<version>-<arch>-<build><tag>.txz), identifies packages built by
|
|
# this project as opposed to a stock Slackware/SBo package of the same name.
|
|
PKG_TAG="_unraidpodman"
|