Files
unraid-podman/packages
maggesandClaude Sonnet 5 5b47b4cc0a Add catatonit/nftables/docker-compose packages, fix CSRF/streaming/storage bugs found by live testing
- Package #9-11: catatonit (pod infra init), nftables (netavark firewall
  backend), docker-compose (external compose provider for `podman compose`)
  — all vendored prebuilt binaries, versions.env pinned, propagated through
  build-packages.sh/release.sh/podman.plg/verify+update-packages.sh.
- Fix WebUI: every POST action was silently failing (empty response body)
  because Unraid's own CSRF protection was never satisfied — app.js now
  sends the page's csrf_token as X-CSRF-Token.
- Fix WebUI: PodmanClient::pullImage() assumed a single JSON response, but
  /images/pull actually streams newline-delimited JSON — every successful
  pull was throwing "Expected a JSON object/array response".
- Fix WebUI: compose.php's up/down status detection had the same
  single-JSON-vs-NDJSON bug for `podman compose ps`, plus stderr was
  corrupting the parse.
- Add cache-busting (?v=<mtime>) to Podman.page's script/style tags so a
  redeployed JS/CSS fix isn't served stale from browser cache.
- Add a reusable modal dialog (app.js openFormModal) replacing
  prompt()/alert() for New Volume/Network/Pull Image.
- Add host-path (bind-mount) support when creating a named volume.
- Add Create Container (image, name, network mode incl. custom networks,
  ports, volumes, env, restart policy, privileged, start-after-create),
  auto-pulling the image on first use since /containers/create doesn't.

All fixes verified live against a real podman system service and, where
reachable, via the actual WebUI over the real socket — not just unit-level.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 11:51:17 +00:00
..

packages/

One subdirectory per Slackware .txz package required by the plugin, built against Unraid's Slackware base. See docs/ARCHITECTURE.md, section 5 for the full rationale (why these components, static linking preference, version pinning, build strategy).

Packages

Directory Upstream project Purpose
podman/ containers/podman Core container engine binary
conmon/ containers/conmon Container monitor process
crun/ containers/crun OCI runtime (preferred over runc)
netavark/ containers/netavark Network backend
aardvark-dns/ containers/aardvark-dns DNS for container-to-container name resolution
containers-common/ containers/common Default config/seccomp/registries templates
fuse-overlayfs/ containers/fuse-overlayfs Fallback storage driver (rootless, Phase 2)
passt/ passt.top (no GitHub mirror) Rootless networking (Phase 2), successor to slirp4netns
unraid-podman/ this repository (not an upstream project) Plugin's own scaffolding — rc.podman, sbin/ scripts, event/ hooks, config templates (see its README)

podman, conmon, crun, netavark, aardvark-dns, passt, fuse-overlayfs, and unraid-podman are built and released automatically by .github/workflows/build-packages.yml. containers-common currently only supplies reference config (see config/) and is not yet wired into the automated build.

Standard layout per package

Each package directory follows the same skeleton:

packages/<name>/
├── <name>.SlackBuild   # Slackware build script (source download, build, packaging)
├── slack-desc            # Slackware package description (max 70 cols / 11 lines)
├── patches/               # Optional patches applied during the build
└── README.md              # Upstream version pinned, build notes, patch rationale

Build pipeline

Packages are built via scripts/build-packages.sh, which runs each package's <name>.SlackBuild in turn (see scripts/lib/slackbuild-common.sh for the shared fetch/verify/package helpers they all use). This must run inside a Slackware-compatible build environment — never on an arbitrary host distro, to avoid glibc/ABI drift against Unraid's base. .github/workflows/build-packages.yml is the CI entry point: it runs the same script inside a pinned Slackware container (scripts/ci/setup-slackware-buildenv.sh bootstraps any build-time dependency the base image doesn't already ship) and uploads the results as a workflow artifact — nothing built is ever committed to this repository.

Exact upstream versions and source checksums are pinned centrally in versions.env (update via scripts/update-versions.sh, never by hand) and, at release time, mirrored into the top-level plugin/podman.plg manifest together with MD5 checksums by scripts/release.sh, so installs are reproducible and rollback-able — see docs/ARCHITECTURE.md, section 14 (Rollback).