Files
unraid-podman/webui/plugins/podman/ajax/settings.php
T
maggesandClaude Sonnet 5 7f6fcb9166
Build Packages / Build .txz packages (push) Successful in 9m17s
Lint / ShellCheck (push) Successful in 12s
Lint / Validate .plg XML (push) Successful in 13s
Lint / EditorConfig (push) Successful in 6s
Fix real STORAGE_PATH bug; add Start Podman + format-disk from the WebUI
Root cause of a fresh-install "cannot reach the Podman API socket" report
(a friend's Unraid box, cache pool present and mounted): unlike
Docker-for-Unraid's docker.img path, this plugin never auto-created
STORAGE_PATH itself — only podman.img inside it. A perfectly normal,
already-mounted cache pool still failed preflight/storage-create with
"does not exist", just because its own .../system/podman subdirectory
had never been created. Fixed by walking up to the nearest existing
ancestor and checking whether it's on a different device than / (real
mount vs. nothing mounted at all) — see podman-common.sh's new
podman_path_has_real_mount_ancestor(), used by both podman-preflight.sh
and podman-storage.sh.

Settings gets a "Podman Service" card (status chip + Start/Restart,
backed by new ajax/settings.php service_status/start/restart actions
that just shell out to rc.podman) so a fresh install that failed to start
can be diagnosed and retried without SSH/terminal access at all — exactly
what was missing when this was first needed live.

Also adds "Format a Disk for Podman Storage" (new ajax/disks.php) for a
single-disk system with no cache pool at all. Only ever lists disks with
literally no existing partition/filesystem/RAID-or-ZFS-membership
signature and that aren't Unraid's boot flash — found live, twice, during
development: the boot USB (FAT, labeled "UNRAID") passed the initial
mounted-only check because this host's /boot is backed by a ZFS dataset
rather than a direct partition mount, and active RAID-member cache disks
passed a data-vs-blank *warning* rather than a hard exclusion. Both are
now excluded outright, not just flagged — see disks.php's
device_or_children_labeled_unraid() and the hasData exclusion in
list_candidate_disks(). A disk formatted this way is remounted by UUID on
every boot via a new plugin/sbin/podman-mount-managed-disk.sh, called
from plugin/event/disks_mounted before rc.podman start.

Unrelated fix bundled in: scripts/lib/slackbuild-common.sh now sets
SOURCE_DATE_EPOCH (derived from the repo's last commit) before calling
makepkg, so two separate builds of the same commit produce byte-identical
.txz files — makepkg already supports this (`--clamp-mtime` when
$SOURCE_DATE_EPOCH is set, confirmed by reading a real host's
/sbin/makepkg) but nothing was setting the variable, so release.yml's
"rebuild in CI and verify it matches the committed checksums" step was
guaranteed to fail on the first package it checked alphabetically
(observed live: aardvark-dns).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 22:55:14 +00:00

215 lines
7.8 KiB
PHP

<?php
/**
* ajax/settings.php
*
* Backs the Settings panel. Unlike every other ajax/*.php file, this one
* is NOT primarily a PodmanClient consumer — plugin settings (podman.cfg,
* the autostart list, installed package versions) are unraid-podman's own
* data on /boot, not a libpod-managed resource, so there is no API to call
* here in the first place. Writes go straight to the same files
* plugin/sbin/podman-config.sh and podman-autostart.sh read, using the
* same paths (see include/Config.php, which mirrors podman-common.sh's
* path constants).
*
* Actions (?action=...):
* get GET -> current settings + autostart list + package versions
* save POST {"storagePath": "...", "storageImageSizeGb": 20,
* "enabled": true, "stopTimeoutSeconds": 10}
* autostart_save POST {"names": ["postgres", "nextcloud", ...]}
* service_status GET -> {"running": bool, "output": "..."}
* service_start POST -> {"running": bool, "output": "..."}
* service_restart POST -> {"running": bool, "output": "..."}
*/
declare(strict_types=1);
require __DIR__ . '/../include/bootstrap.php';
const RC_PODMAN = '/etc/rc.d/rc.podman';
$action = $_GET['action'] ?? '';
switch ($action) {
case 'get':
podman_json_response(settings_get($podmanConfig));
break;
case 'save':
$body = podman_read_json_body();
settings_save($podmanConfig, $body);
podman_json_response(['status' => 'saved']);
break;
case 'autostart_save':
$body = podman_read_json_body();
$names = $body['names'] ?? null;
if (!is_array($names)) {
podman_json_error('Missing names array in request body', 400);
}
autostart_save($podmanConfig, $names);
podman_json_response(['status' => 'saved']);
break;
case 'service_status':
podman_json_response(rc_podman('status', 15));
break;
case 'service_start':
podman_json_response(rc_podman('start', 120));
break;
case 'service_restart':
podman_json_response(rc_podman('restart', 120));
break;
default:
podman_json_error("Unknown action '{$action}'", 400);
}
/**
* Shells out to /etc/rc.d/rc.podman <verb> — the plugin's own real
* start/stop/status script, the SAME one the array-start event hook and
* a terminal `rc.podman status` use (see plugin/rc.d/rc.podman's header
* comment). This exists specifically so a fresh install where podman
* failed to start (e.g. no cache pool configured yet, see
* podman-storage.sh's "does not exist or is not mounted" error) can be
* diagnosed and retried from the WebUI itself — no SSH/terminal access
* needed, which is exactly what was missing when this was first needed
* live (a fresh install on a different Unraid box with nobody able to
* reach a terminal to run `rc.podman start` by hand).
*
* @return array{running: bool, output: string}
*/
function rc_podman(string $verb, int $timeoutSeconds): array
{
$descriptors = [1 => ['pipe', 'w'], 2 => ['pipe', 'w']];
$process = proc_open([RC_PODMAN, $verb], $descriptors, $pipes);
if (!is_resource($process)) {
podman_json_error("Could not run rc.podman {$verb}", 500);
}
stream_set_timeout($pipes[1], $timeoutSeconds);
$stdout = stream_get_contents($pipes[1]) ?: '';
$stderr = stream_get_contents($pipes[2]) ?: '';
fclose($pipes[1]);
fclose($pipes[2]);
proc_close($process);
$combined = trim($stdout . $stderr);
// rc.podman status/start both print "service: running (pid ..., socket ...)"
// on success — cheaper and more honest than re-implementing the same
// socket/pid check PHP-side when the shell script already did it.
$running = (bool) preg_match('/service:\s+running/', $combined);
return ['running' => $running, 'output' => $combined];
}
/** @return array<string,mixed> */
function settings_get(PodmanConfig $config): array
{
return [
'storagePath' => $config->storagePath,
'storageImageSizeGb' => $config->storageImageSizeGb,
'enabled' => $config->enabled,
'stopTimeoutSeconds' => $config->stopTimeoutSeconds,
'autostart' => autostart_read($config),
'packageVersions' => installed_package_versions(),
];
}
/** @param array<string,mixed> $input */
function settings_save(PodmanConfig $config, array $input): void
{
$storagePath = isset($input['storagePath']) ? (string) $input['storagePath'] : $config->storagePath;
if (!storage_path_is_safe($storagePath)) {
podman_json_error(
"storagePath ({$storagePath}) is under /mnt/user (FUSE/shfs). " .
'The overlay storage driver needs a real mounted filesystem — use a cache pool or a specific disk path instead.',
400
);
}
$lines = [
'# Rewritten by the unraid-podman WebUI (ajax/settings.php).',
'# Applies on the next "rc.podman restart" — see plugin/rc.d/rc.podman.',
'STORAGE_PATH="' . $storagePath . '"',
'STORAGE_IMAGE_SIZE_GB="' . (int) ($input['storageImageSizeGb'] ?? $config->storageImageSizeGb) . '"',
'PODMAN_ENABLED="' . ((bool) ($input['enabled'] ?? $config->enabled) ? 'yes' : 'no') . '"',
'STOP_TIMEOUT="' . (int) ($input['stopTimeoutSeconds'] ?? $config->stopTimeoutSeconds) . '"',
'CONFIG_SCHEMA_VERSION="1"',
'',
];
$target = $config->bootDir . '/podman.cfg';
if (file_put_contents($target, implode("\n", $lines), LOCK_EX) === false) {
podman_json_error("Could not write {$target} — check permissions on /boot/config/plugins/podman/", 500);
}
}
/**
* Mirrors plugin/sbin/podman-common.sh's podman_storage_path_is_safe() —
* kept in sync deliberately (both reject the same /mnt/user prefix, for
* the same reason) rather than shelling out to the bash version, since
* this is a one-line string check, not worth a process spawn for.
*/
function storage_path_is_safe(string $path): bool
{
return $path !== '/mnt/user' && !str_starts_with($path, '/mnt/user/');
}
/** @return array<int,string> */
function autostart_read(PodmanConfig $config): array
{
if (!is_readable($config->autostartFile)) {
return [];
}
$lines = file($config->autostartFile, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES) ?: [];
$names = [];
foreach ($lines as $line) {
$line = trim(preg_replace('/#.*$/', '', $line) ?? '');
if ($line !== '') {
$names[] = $line;
}
}
return $names;
}
/** @param array<int,mixed> $names */
function autostart_save(PodmanConfig $config, array $names): void
{
$lines = array_map(static fn($n) => (string) $n, $names);
$content = implode("\n", $lines) . (count($lines) > 0 ? "\n" : '');
if (file_put_contents($config->autostartFile, $content, LOCK_EX) === false) {
podman_json_error("Could not write {$config->autostartFile}", 500);
}
}
/**
* Reads /usr/local/share/unraid-podman/installed-versions.env — the same
* manifest plugin/sbin/podman-verify-packages.sh and
* podman-update-packages.sh use (see plugin/podman.plg's postinstall step,
* which generates it) — so Settings shows exactly what those tools would
* report, not a second, possibly-diverging source of truth.
*
* @return array<string,string>
*/
function installed_package_versions(): array
{
$path = '/usr/local/share/unraid-podman/installed-versions.env';
if (!is_readable($path)) {
return [];
}
$lines = file($path, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES) ?: [];
$out = [];
foreach ($lines as $line) {
$line = trim($line);
if ($line === '' || str_starts_with($line, '#')) {
continue;
}
if (preg_match('/^([A-Z_][A-Z0-9_]*)="?([^"]*)"?$/', $line, $m)) {
$out[$m[1]] = $m[2];
}
}
return $out;
}