- Package #9-11: catatonit (pod infra init), nftables (netavark firewall backend), docker-compose (external compose provider for `podman compose`) — all vendored prebuilt binaries, versions.env pinned, propagated through build-packages.sh/release.sh/podman.plg/verify+update-packages.sh. - Fix WebUI: every POST action was silently failing (empty response body) because Unraid's own CSRF protection was never satisfied — app.js now sends the page's csrf_token as X-CSRF-Token. - Fix WebUI: PodmanClient::pullImage() assumed a single JSON response, but /images/pull actually streams newline-delimited JSON — every successful pull was throwing "Expected a JSON object/array response". - Fix WebUI: compose.php's up/down status detection had the same single-JSON-vs-NDJSON bug for `podman compose ps`, plus stderr was corrupting the parse. - Add cache-busting (?v=<mtime>) to Podman.page's script/style tags so a redeployed JS/CSS fix isn't served stale from browser cache. - Add a reusable modal dialog (app.js openFormModal) replacing prompt()/alert() for New Volume/Network/Pull Image. - Add host-path (bind-mount) support when creating a named volume. - Add Create Container (image, name, network mode incl. custom networks, ports, volumes, env, restart policy, privileged, start-after-create), auto-pulling the image on first use since /containers/create doesn't. All fixes verified live against a real podman system service and, where reachable, via the actual WebUI over the real socket — not just unit-level. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
packages/
One subdirectory per Slackware .txz package required by the plugin, built
against Unraid's Slackware base. See
docs/ARCHITECTURE.md, section 5
for the full rationale (why these components, static linking preference,
version pinning, build strategy).
Packages
| Directory | Upstream project | Purpose |
|---|---|---|
podman/ |
containers/podman | Core container engine binary |
conmon/ |
containers/conmon | Container monitor process |
crun/ |
containers/crun | OCI runtime (preferred over runc) |
netavark/ |
containers/netavark | Network backend |
aardvark-dns/ |
containers/aardvark-dns | DNS for container-to-container name resolution |
containers-common/ |
containers/common | Default config/seccomp/registries templates |
fuse-overlayfs/ |
containers/fuse-overlayfs | Fallback storage driver (rootless, Phase 2) |
passt/ |
passt.top (no GitHub mirror) | Rootless networking (Phase 2), successor to slirp4netns |
unraid-podman/ |
this repository (not an upstream project) | Plugin's own scaffolding — rc.podman, sbin/ scripts, event/ hooks, config templates (see its README) |
podman, conmon, crun, netavark, aardvark-dns, passt,
fuse-overlayfs, and unraid-podman are built and released automatically by
.github/workflows/build-packages.yml. containers-common currently only
supplies reference config (see config/) and is not yet wired
into the automated build.
Standard layout per package
Each package directory follows the same skeleton:
packages/<name>/
├── <name>.SlackBuild # Slackware build script (source download, build, packaging)
├── slack-desc # Slackware package description (max 70 cols / 11 lines)
├── patches/ # Optional patches applied during the build
└── README.md # Upstream version pinned, build notes, patch rationale
Build pipeline
Packages are built via scripts/build-packages.sh, which runs each
package's <name>.SlackBuild in turn (see scripts/lib/slackbuild-common.sh
for the shared fetch/verify/package helpers they all use). This must run
inside a Slackware-compatible build environment — never on an arbitrary host
distro, to avoid glibc/ABI drift against Unraid's base.
.github/workflows/build-packages.yml is the CI entry point: it runs the
same script inside a pinned Slackware container
(scripts/ci/setup-slackware-buildenv.sh bootstraps any build-time
dependency the base image doesn't already ship) and uploads the results as a
workflow artifact — nothing built is ever committed to this repository.
Exact upstream versions and source checksums are pinned centrally in
versions.env (update via scripts/update-versions.sh,
never by hand) and, at release time, mirrored into the top-level
plugin/podman.plg manifest together with MD5 checksums by
scripts/release.sh, so installs are reproducible and rollback-able — see
docs/ARCHITECTURE.md, section 14 (Rollback).