v0.1.34 Security and reliability fixes The service keeps serving when /var/log is full. A failed write to /var/log/unraidclaw.log used to raise an error inside the request logger, whose shutdown then retried the same write forever. The service stayed listening on its port but never completed a TLS handshake, never answered a request and ignored rc.unraidclaw stop until it was killed. Log lines that cannot be written are now dropped and the service carries on. Thanks to @golgoth85 for the report and the diagnosis in #18. rc.unraidclaw stop always ends the service. If closing open connections stalls, the process exits on its own after five seconds instead of waiting for the SIGKILL the script sends after ten. rc.unraidclaw start warns when /var/log has no free space, since the service log will explain nothing in that state. /var/log/unraidclaw.log is rotated at 5 MB through Unraid's daily logrotate run, so the request log cannot fill /var/log on its own. Upgrade notes Nothing to configure. If your /var/log is full, the service now starts and answers, but its log stays empty until space is freed. On Unraid 7.3.2, a full /var/log is often nginx/error.log growing from the missing question.png container icon; clearing the rotated logs frees it. v0.1.33 MCP support New Streamable HTTP endpoint at /mcp on the service port, off by default and switched on with Enable MCP in Settings. It exposes the same 55 tools with the same API key, permissions, input validation and activity logging as the REST API. REST and the OpenClaw plugin keep working as before. Activity log entries for MCP tool calls name the tool and show the outcome of the API route it ran. Successful MCP handshakes and GET/DELETE responses with status 405 are left out of the log; other failed connection requests are still logged. Setup for Claude Code, Codex and other clients is described in the MCP section of the README. Command-line client The plugin now installs the unraidclaw command at /usr/local/bin/unraidclaw, with the same tools and permissions as OpenClaw and MCP. On the server it finds the local gateway and trusts its certificate on its own; set the API key once with unraidclaw config set-key. For other machines, the same client is published as unraidclaw-cli on npm and as unraidclaw-cli-0.1.33.tar.gz on this release. It needs Node.js 22 or newer. Connection errors name the cause (untrusted certificate, address not in the certificate, nothing listening, protocol mismatch or DNS), and invalid arguments name the failing flag and rule. Tables and help are shorter, logs and nested values are formatted for reading, certificate details are shown once when trusting in table mode, and supported dry runs proceed without confirmation. See the CLI guide for install, credentials, certificate trust, all commands and exit codes. TLS certificate Generated certificates now list the server's host name, its .local name, loopback and stable global addresses in subjectAltName, so clients that trust the certificate can verify the host name. Settings shows the certificate's subject, alternative names, expiry and SHA-256 fingerprint, so remote CLI users can compare the fingerprint before trusting it. A Regenerate certificate button replaces the certificate when the server's address or host name changed. It keeps the old pair as .bak files (older backups get numbered suffixes) and restarts the service. Security and reliability fixes A parity check started with correct sent as the text "false" no longer runs as a correcting check. The field must now be true or false. Share comments containing quotes, backslashes, $, backticks or control characters are rejected, since they could write extra keys into the share's config file. Share settings are now written atomically and read back. Docker, VM, array, parity and notification actions reject malformed input and unknown fields, refuse IDs that start with -, time out instead of hanging, and check the real state afterwards. Responses include a verified field; a VM shutdown or reboot still in progress returns verified: false. A container created through the API keeps its Unraid template even when it exits right after starting, and a failed create reports Docker's error without echoing environment values. Requests to paths that do not exist return 404 instead of 401 when sent without a key, and no longer count toward the failed-login limit. MCP clients that probe for OAuth metadata locked themselves out before connecting. /api/health stays public and unlogged when called with a query string. /api/health no longer reports the previous version after an upgrade until the service restarted again. The package now records its own version instead of the service reading it from the .plg, which Unraid saves only after the install script restarts the service. Other changes Settings Apply reports when the service did not end up running or stopped, and no longer restarts the service when the settings file could not be written. The Disk Info permission description no longer mentions SMART data, which the disk endpoints do not return. The unused vms:create permission is removed from the VM Manager preset. Upgrade notes MCP is off after the upgrade. Turn it on with Enable MCP in Settings if you want the /mcp endpoint. A certificate created by an earlier version has no subjectAltName and is replaced once on the first service start after the upgrade. The previous pair is kept as cert.pem.bak and key.pem.bak in /boot/config/plugins/unraidclaw/tls. Clients that pinned or trusted the old certificate must trust the new one; the OpenClaw plugin with tlsSkipVerify: true is not affected. Regenerating the certificate from Settings has the same effect: clients that trusted the old certificate must trust the new one. Docker, VM, array, parity, share and notification routes now reject unknown fields and wrongly typed values that earlier versions accepted. Check API scripts that send extra or loosely typed fields, and note that responses from these routes now carry a verified field. Unknown paths answer 404 without a key where they previously answered 401. v0.1.32 Fixes Check /etc/rc.d after upgrading Earlier packages carried directory entries for shared paths. Installing one could replace Unraid's /etc/rc.d symlink with a plain directory holding only rc.unraidclaw. That hides rc.0 and rc.6, so a reboot can't shut the array down cleanly. 0.1.32 builds the package without directory entries and installs it with --keep-directory-symlink --no-overwrite-dir. A new archive safety test runs in the release workflow against a host where /etc/rc.d is a symlink. The upgrade doesn't repair a server that was already hit. Run ls -ld /etc/rc.d. If it shows a directory instead of a symlink, stop the array from the WebGUI before you reboot. Unraid rebuilds its root filesystem from the boot image on every start, so the symlink is back after that reboot. Features Community Applications You can search the CA catalog, read an app's template, and install it with overrides. Installed apps can be updated and removed. An update rebuilds the container from the template saved on the flash drive, not from today's catalog, so the ports, paths and variables you set stay as they are. Volumes attached to the running container are carried over. Removal keeps appdata, volumes, images and the saved template. If the replacement container fails, UnraidClaw tries to put the old one back. Anything it can't reproduce exactly is refused with a blocker code instead of being dropped. Extra Parameters, device passthrough, custom networks, privileged containers and resource limits the template doesn't describe all fall in that group. The new operations accept dryRun: true. Masked template values such as passwords and API keys are redacted from update previews and errors. Plugin Management A separate Plugins category lists, inspects, installs, checks, updates and removes Unraid plugins. Permissions New keys: ca:read, ca:create, ca:update, ca:delete, plugins:read, plugins:create, plugins:update, plugins:delete. The Docker Manager preset includes the CA permissions and Read Only includes plugins:read. Plugin write permissions need an explicit checkbox or Full Admin. ca:update and ca:delete are off in a default permission file. Unraid 7.4 Unraid 7.4 adds a memory limit and Additional Networks to Docker templates. Installs and updates pass the template's memory limit to docker as --memory. An update is refused if the running container's limit doesn't match the template. On Unraid before 7.4, which ignores the field, an install with a memory limit is refused. Templates with Additional Networks are refused rather than installed on a single network. VM listings no longer query the deprecated uuid GraphQL field. The uuid in responses now comes from the VM id and keeps the same value. OpenClaw plugin 0.1.14 Published to npm as
[email protected]. It adds 11 tools, 55 in total: unraid_ca_search, unraid_ca_app, unraid_ca_install, unraid_ca_update, unraid_ca_remove, unraid_plugins_list, unraid_plugin_info, unraid_plugin_install, unraid_plugin_check_updates, unraid_plugin_update, unraid_plugin_remove The new tools call endpoints that exist only in gateway 0.1.32, so upgrade the Unraid plugin first. The plugin README and SKILL.md had stale tool counts, a 6.12+ requirement where 7.0.0+ is correct, and outdated config examples. Those are fixed. The repo also has a CONTRIBUTING.md and an AGENTS.md now. v0.1.31 Fixes Parity-check status now reflects reality (#14, thanks @rodaballo) /api/array/parity/status previously read Unraid's GraphQL array.parityCheckStatus, which doesn't reflect parity checks started outside Connect (via mdcmd, cron, or the webGUI) — so it reported no activity during a running check. It now reads live md-driver state from mdcmd status (the same source the webGUI uses, consistent with how start/pause/resume/cancel already shell out to mdcmd). API Backward compatible — the existing keys keep their names and now carry real data, with new fields added: Field Source running mdResyncPos>0 ‖ mdResync>0 progress mdResyncPos / mdResyncSize (0–100) speed / speedHuman mdResyncDb / mdResyncDt (KiB/s) / MB/s string errors sbSyncErrs paused (new) in progress but not advancing correcting (new) mdResyncCorr action (new) mdResyncAction (e.g. "check P Q") position / size (new) KiB done / total lastCheck (new) start/finish/duration/exit of the previous check No changes required for existing API consumers (OpenClaw included) v0.1.30 Important Critical fix. v0.1.27–v0.1.29 silently chowned host root paths (/, /usr, /usr/local, /usr/local/emhttp, ...) to UID 1001 on install, breaking SSH key authentication on systems with default StrictModes yes. All users on those versions should upgrade. Fixes Stop chowning host paths (#13) The build's tar invocation lacked --owner=root --group=root, so the GitHub Actions runner's UID 1001 was baked into every directory entry of the .txz. upgradepkg then preserved that ownership on the host's matching paths. Build now uses tar --owner=root --group=root --numeric-owner. All archive metadata is root:root. Heal existing installs Postinstall step issues a corrective chown root:root on the affected host paths. Upgrading to v0.1.30 fixes already-broken systems automatically. No-op on healthy systems. After upgrade, you can safely revert any StrictModes no workaround in /etc/ssh/sshd_config. Huge thanks to @justinmeader for the exceptional bug report, root cause and fix included. v0.1.29 Fixes Fix POST /api/docker/containers rejecting valid registry-prefixed image references (#12) Now accepts host[:port]/path/name:tag (e.g. 192.168.178.158:5000/homelab/myapp:latest) Now accepts digest references (e.g. nginx@sha256:...) The previous validator only allowed a single : and didn't permit @, which blocked everyone running a local/private Docker registry. v0.1.28 Fix min/max version to align with XML v7 minimum by @mstrhakr in #11 v0.1.27 Add memory stats (total, used, free, percent) to /api/system/info and /api/system/metrics Add CPU load averages (1m, 5m, 15m) to /api/system/info and /api/system/metrics Add disk usage (used, free, percent) to /api/disks endpoints via df Make /api/system/metrics a lightweight endpoint for polling (memory + CPU load only) v0.1.26 Security Hardening Release Fix command injection in syslog and notification endpoints (execSync to execFileAsync) Fix path traversal in notification archive/delete and docker template filename Restrict CORS to local network origins only Stop exposing Unraid API key in settings page HTML Remove internal error details from API error responses Add rate limiting on API authentication (10 attempts/min per IP) Add input validation on docker:create parameters (image, ports, volumes, env, network) Validate share update fields (floor, splitLevel, comment) Set restrictive file permissions on config, permissions, and log files Enforce strict boolean types in permission saves Require WebGUI authentication on activity log PHP endpoints Move CSRF token from global JS variable to data attribute v0.1.25 Add Unraid WebUI Port setting for non-standard port configurations GraphQL URL is now constructed automatically from the port (no more manual URL editing) v0.1.24 Remove GraphQL URL from settings (hardcode to http://localhost/graphql) Prevents misconfiguration that caused 500 errors on all GraphQL-based endpoints v0.1.23 Fix /api/health reporting hardcoded version "0.1.0" instead of actual installed version Version is now read from the .plg file automatically, so it always matches the installed release v0.1.22 Fix Docker inspect, logs, and all actions (start/stop/restart/pause/unpause) failing with 400 Bad Request Switch all Docker and VM operations from GraphQL to CLI for compatibility with Unraid 7.2.3 Add docker:create endpoint for deploying containers via AI agents (thanks @bitcryptic-gw) Fix OpenAI function calling compatibility Fix global TLS bypass in OpenClaw plugin (now scoped per-connection) Fix XML injection in docker:create template generation Add ADMIN API key requirement to documentation Correct API route paths in README OpenClaw plugin also updated to v0.1.3 on npm: rm -rf ~/.openclaw/extensions/unraidclaw && npm pack unraidclaw && openclaw plugins install unraidclaw-*.tgz && rm unraidclaw-*.tgz
openclaw gateway restart On the OpenClaw side, multi server support has been added, config is backwards compatible, but you can have multiple servers configured this way: {
"plugins": {
"allow": ["unraidclaw"],
"entries": {
"unraidclaw": {
"config": {
"servers": [
{
"name": "home",
"serverUrl": "https://192.168.1.100:9876",
"apiKey": "...",
"tlsSkipVerify": true,
"default": true
},
{
"name": "work",
"serverUrl": "https://10.0.0.50:9876",
"apiKey": "..."
}
]
}
}
}
}
}With multi-server, every tool accepts an optional server parameter (e.g. unraid_docker_list(server: "work")). If omitted, the default server is used.