Remote denial of service via malicious repo mirror
Description: A malicious arch repo mirror can remotely crash pacman by serving a crafted repository database which omits the %PACKAGER% entry completely, resulting in a SIGSEGV. Arch's default SigLevel...
View ArticleMissing license information in .src.tar.gz files
Thanks to https://rfc.archlinux.page/0040-license-package-sources/ and https://rfc.archlinux.page/0052-reuse/, now, in each package repositories, there should be LICENSE files and a REUSE.toml file to...
View Articlelibalpm exposes partially extracted shared libraries, causing SIGBUS
Environment pacman 7.1.0.r9.g54d9411-2 libarchive 3.8.9-1 openssl upgrade: 3.6.3-1→ 3.6.4-1 Problem During pacman -Syu, /usr/lib/systemd/systemd-executor crashed with SIGBUS. The stack shows...
View Article`verify()` does not have access to sources when `SRCDEST` is set
verify() expects sources to be in $startdir. This makes sense in the absence of SRCDEST, because that is where sources are downloaded to. But that is not the case with SRCDEST set. Sources are wherever...
View Article`makepkg --printsrcinfo` doesn't find depends in nested functions
The current lua-lub 1.1.0-7 (PKGBUILD) is a split package for each Lua version. At runtime, each package depends on their respective version of lua-filesystem. For easier maintenance, the version...
View ArticleConsider limiting the set of allowed characters in `pkgver` further
Currently, the PKGBUILD man page makes the following assumption about the pkgver value: The version of the software as released from the author (e.g., 2.7.1). The variable is not allowed to contain...
View Article--dbpath with a symlinked local/ is silently destroyed mid-transaction,...
Summary If the --dbpath directory's local/ is a symlink (e.g. to /var/lib/pacman/local), any transaction that installs or upgrades a package silently unlinks that symlink partway through the first...
View Articlerepo-add fails to sign Repository with forwarded gpg-agent
Dear maintainers, the repo-add script currently fails to sign the repository if it is executed in a SSH session with forwarded gpg-agent using the extra socket. In our use case, we host a private...
View ArticleWhen ParallelDownloads has more than two, dedicate one download for small...
To my understanding, the initiation of a download takes time. To make the whole upgrade take less time, dedicate one download to downloading the smalles package instead of the biggest. If my...
View Articlemakepkg includes query string in downloaded file names
If in a PKGBUILD you specify a source url such as: https://invent.kde.org/multimedia/amarok/-/archive/v$pkgver/amarok-v$pkgver.tar.gz?ref_type=tags, the file gets saved as...
View Articlemakepkg: Add a builddir variable in PKGBUILD
makepkg defines "$srcdir" as the default build directory while, in most cases, the build happens in the unpacked sources path (usually something like "$srcdir/$pkgname-$pkgver"). This therefore...
View ArticleAdd local-only package annotations to pacman/libalpm
Summary pacman currently tracks whether an installed package was installed explicitly or as a dependency, but it does not provide a first-class way to record why an explicitly installed package exists...
View ArticleDLAGENTS parsing is too simple
The code in get_downloadclient and download_file just splits a DLAGENTS line on spaces. This makes it impossible to pass arguments that contain spaces. The default http and https agents use -b "" for...
View Article`crates.io` started to block `curl` requests, intervention is needed
To fix this, it is necessary to set the user-agent in /etc/makepkg.conf, so curl request passes. If I attempt to add the user agent manually like this in makepkg.conf: https::/usr/bin/curl -A...
View Articlerepo-add script not handling package version upgrades correctly
Package teams-for-linux version 2.9.0 overrides teams-for-linux version 2.10.0 when creating a local/custom pacman repo. Consider the following packages, added to a local/custom pacman repo: ❯ ll...
View Articledoc pacman.8 --info x 2: extended data is implemented, but not documented.
doc pacman.8 --info x 2: extended data is implemented, but not documented.
View Article--noconfirm in a script: Should more '\n' characters added at selected lines?
When using --noconfirm in a script, the logger has: . . . Total Download Size: 198.05 MiB :: Proceed with download? [Y/n] :: Retrieving packages... checking keyring... checking package integrity......
View ArticleAdd config option to only update if package is older than a certain age
With the increase in supply chain attacks in registries such as npm, uv/pip and others; it may be a good idea to add the option to only update if the package is older that a set time-frame such as 1...
View ArticlePreserve file capabilities set by the underlying build system
KDE's ksystsmstats software sets a file capability in CMake: https://invent.kde.org/plasma/ksystemstats/-/blob/master/plugins/gpu/CMakeLists.txt?ref_type=heads#L22 Arch's packaging runs cmake to build...
View Articlecashing with recent curl (and threaded resolver)
Description: pacman uses libcurl to sync databases and download package files. This used to work just fine. However things broke with curl7.20.0-1: pacman started to crash and dump core. Turned out the...
View Article