- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt, and fuse-overlayfs to verified upstream source checksums; SlackBuild recipes, scripts/build-packages.sh, checksums.sh, release.sh, and update-versions.sh implement the reproducible pipeline; GitHub Actions workflows build in a Slackware container and publish releases without committing any binaries. - plugin/podman.plg installs/updates/removes all eight packages (the seven components plus the plugin's own unraid-podman scaffolding package) via upgradepkg, using the official Unraid array-event hook mechanism (event/disks_mounted, event/stopping) instead of editing /boot/config/go. rc.podman and the sbin/ helper scripts implement storage creation, config seeding/sync, preflight checks, autostart with per-container Safe-Mode, and package verify/update/rollback. - webui/plugins/podman implements the Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, and Settings panels against the approved mockup (webui/mockups/prototype.html), talking to podman system service exclusively via PodmanClient.php (libpod REST API over the Unix socket), with two documented exceptions: Terminal's one-shot exec model and Compose's use of the podman compose CLI, since libpod has no REST equivalent for either. - docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions and honest current status (syntax-checked, unit- and integration-tested against fake sockets/servers; not yet run against a real Unraid/Podman/Slackware system). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
38 lines
1.4 KiB
Markdown
38 lines
1.4 KiB
Markdown
# Security Policy
|
|
|
|
## Threat model context
|
|
|
|
This plugin runs **rootful Podman**. Its API socket (`/var/run/podman/podman.sock`)
|
|
is root-equivalent on the host, in the same way Docker's `docker.sock` is. See
|
|
[docs/ARCHITECTURE.md](../docs/ARCHITECTURE.md#19-sicherheitsbetrachtungen-phase-1-rootful)
|
|
for the full rationale. Treat any bug that affects socket permissions, WebUI
|
|
authentication, or container-to-host isolation as security-sensitive by default.
|
|
|
|
## Reporting a vulnerability
|
|
|
|
Please **do not** open a public GitHub issue for security vulnerabilities.
|
|
|
|
Instead, use one of:
|
|
|
|
- GitHub [private security advisories](https://github.com/OWNER/unraid-podman/security/advisories/new)
|
|
for this repository, or
|
|
- Email the maintainers at `security@OWNER-DOMAIN` (placeholder — update once a
|
|
contact address exists).
|
|
|
|
Please include:
|
|
|
|
- A description of the issue and its potential impact.
|
|
- Steps to reproduce (Unraid version, plugin version, storage backend).
|
|
- Whether the issue requires local access, network access, or a malicious
|
|
container image to trigger.
|
|
|
|
## Supported versions
|
|
|
|
This project has not yet cut a stable release. Until a `1.0.0` release, only the
|
|
latest `main` branch / most recent tag is supported with security fixes.
|
|
|
|
## Disclosure process
|
|
|
|
We aim to acknowledge reports within 5 business days and to agree on a
|
|
coordinated disclosure timeline before any public write-up.
|