efr-code

LOW
maintainer eggfriedrice 0 votes scanned 2026-10-07 20:08:44.287246
View on AUR
Why flagged

All sources are from plausible official hosts (GitHub project tarball, ghostty-org/ghostty on GitHub, ziglang.org official Zig release) with pinned b2sums; the package builds its own Rust source with no obfuscated payloads, no exfiltration, and no redirection of official endpoints — the only mild concern is that this is a new, low-vote package from an unknown maintainer, but the build process itself is transparent and well-documented.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): All sources are from plausible official hosts (GitHub project tarball, ghostty-org/ghostty on GitHub, ziglang.org official Zig release) with pinned b2sums; the package builds its own Rust source with no obfuscated payloads, no exfiltration, and no redirection of official endpoints — the only mild concern is that this is a new, low-vote package from an unknown maintainer, but the build process itself is transparent and well-documented.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:39 "https://ziglang.org/download/$_zig/$_zigdir.tar.xz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: eggfriedrice <eggfriedricew.g.o@gmail.com>
2
3# Builds efr from the GitHub tag tarball, with the ghostty screen backend. The
4# efr-code-bin package installs the prebuilt release of the same version.
5#
6# The ghostty screen needs a build of libghostty-vt by Zig 0.16.0 exactly
7# (docs/ghostty-pin.md). The Zig of the Arch repositories moves on to 0.17 and
8# later, so this package does not use it: it downloads the official Zig 0.16.0
9# build from ziglang.org, pinned by its checksum, and uses it only for the
10# build. The ghostty source is the commit that the libghostty-vt pin names.
11# All downloads happen in the sources and in prepare(); build() needs no network.
12pkgname=efr-code
13pkgver=0.0.1
14pkgrel=1
15pkgdesc='Terminal-first AI agent harness that lives in zsh, with a daemon that owns the state'
16arch=('x86_64')
17url='https://github.com/eggfriedrice24/eggfriedrice.code'
18license=('MIT')
19depends=('glibc' 'libgcc' 'zsh')
20makedepends=('cargo')
21# The scope tests of check() run git.
22checkdepends=('git')
23optdepends=('bubblewrap: the kernel sandbox of the auto mode (also needs Linux 7.1 or newer)'
24 'git: project roots and the git facts of a turn'
25 'xdg-utils: let efr login openai open the browser with EFR_OPEN_BROWSER=1')
26conflicts=("$pkgname-bin")
27install=efr-code.install
28# The -flto of makepkg.conf makes GCC write LTO bytecode into the C objects of
29# aws-lc-sys, which the lld of rustc cannot link. The Cargo profile has its own LTO.
30options=('!lto')
31# The ghostty commit of the libghostty-vt pin, and the Zig release it needs.
32# Change them together with docs/ghostty-pin.md.
33_ghostty=22d13172cde98a0a4dda05d3d6a3fcb0dd8ed018
34_zig=0.16.0
35_src="eggfriedrice.code-$pkgver"
36_zigdir="zig-$CARCH-linux-$_zig"
37source=("$pkgname-$pkgver.tar.gz::$url/archive/refs/tags/v$pkgver.tar.gz"
38 "ghostty-$_ghostty.tar.gz::https://github.com/ghostty-org/ghostty/archive/$_ghostty.tar.gz"
39 "https://ziglang.org/download/$_zig/$_zigdir.tar.xz")
40# The first sum is filled in for each release by .github/workflows/aur.yml from
41# the tag tarball. The other two are pinned: the ghostty archive of the commit,
42# and the Zig tarball whose SHA-256 ziglang.org publishes in
43# https://ziglang.org/download/index.json
44# (70e49664a74374b48b51e6f3fdfbf437f6395d42509050588bd49abe52ba3d00).
45b2sums=('29ddaf4ae7516fd0d5bbbe6646ac98cd2edbc6cf481194c58f472d67b2098164f3242dc3f02ba256d5d55e82924013e60fc8adbfb6ff97451c7cc68829299911'
46 '04e7fc2104a5e6bccbe5b189f5dcc4e3abf0a80410764f6ae44fcd042ca952250df08f6e60631653b00b7202dd1d906ca6033ad66a2ecb1cfa2935496120daef'
47 '77f476c241e6be49e8e71a98276261bdc8cc0bb90aca277f2d81413fe373d94c442df5277cf4cd0893b986b4c6c2a6f8b2061c9305fe8445883316899ff67958')
48
49# Keep debug info in the binaries so makepkg can split it into the -debug package.
50export CARGO_PROFILE_RELEASE_DEBUG=2 CARGO_PROFILE_RELEASE_STRIP=false
51
52# aws-lc-sys (under rustls) must build its jitter entropy source with -O0 and fails
53# with any other level. cc appends CFLAGS last, so the -O2 of makepkg.conf would win.
54# Without a -O in CFLAGS, cc takes the level of the Cargo profile, so the rest of the
55# C code stays optimized.
56_drop_cflags_optimization() {
57 local flag kept=()
58 for flag in $CFLAGS; do
59 [[ $flag == -O* ]] || kept+=("$flag")
60 done
61 export CFLAGS="${kept[*]}"
62}
63
64prepare() {
65 cd "$_src"
66 export RUSTUP_TOOLCHAIN=stable
67 cargo fetch --locked --target host-tuple
68
69 # The Zig packages of the ghostty build. Zig 0.16 fetches them into zig-pkg/ of
70 # the ghostty source, where build() finds them. A lazy package is fetched only
71 # when the build asks for it, and --help asks for the ones of these options, so
72 # they must stay the options that libghostty-vt-sys's build.rs passes at the
73 # pinned rev; zig build --fetch=all would fetch about 550 MB instead of 20 MB.
74 cd "$srcdir/ghostty-$_ghostty"
75 "$srcdir/$_zigdir/zig" build --global-cache-dir "$srcdir/zig-global-cache" \
76 -Demit-lib-vt=true -Doptimize=ReleaseFast -Dcpu=baseline \
77 -Demit-xcframework=false -Dapp-runtime=none --help > /dev/null
78}
79
80build() {
81 cd "$_src"
82 export RUSTUP_TOOLCHAIN=stable
83 export CARGO_TARGET_DIR=target
84 # libghostty-vt-sys runs zig from PATH and builds this ghostty source with the
85 # packages from prepare(); docs/ghostty-pin.md lists its variables.
86 export PATH="$srcdir/$_zigdir:$PATH"
87 export GHOSTTY_SOURCE_DIR="$srcdir/ghostty-$_ghostty"
88 export ZIG_GLOBAL_CACHE_DIR="$srcdir/zig-global-cache"
89 export LIBGHOSTTY_VT_SYS_CPU=baseline
90 _drop_cflags_optimization
91 # The packages and the feature of `just build-release`.
92 cargo build --frozen --release -p efr-daemon -p efr-cli -p efr-sbx \
93 --features efr-daemon/screen-ghostty
94
95 # A build with the sandbox's test seams lets a test replace the launcher and the
96 # probe; it must never ship.
97 if [[ "$(target/release/efrd --test-seams)" != off ]]; then
98 echo "target/release/efrd has the test-sandbox-fake feature" >&2
99 return 1
100 fi
101}
102
103check() {
104 cd "$_src"
105 export RUSTUP_TOOLCHAIN=stable
106 export CARGO_TARGET_DIR=target
107 # The leaf crates of the justfile, as `just test-leaf` runs them. The other tests
108 # need a real zsh session, bubblewrap and a kernel sandbox, which a build chroot
109 # does not have.
110 local crate crates args=()
111 read -ra crates <<<"$(sed -nE 's/^leaf_crates := "(.*)"$/\1/p' justfile)"
112 if (( ${#crates[@]} == 0 )); then
113 echo "no leaf_crates in the justfile" >&2
114 return 1
115 fi
116 for crate in "${crates[@]}"; do
117 args+=(-p "$crate")
118 done
119 _drop_cflags_optimization
120 INSTA_UPDATE=no cargo test --frozen "${args[@]}" --lib --tests
121}
122
123package() {
124 cd "$_src"
125 install -Dm0755 -t "$pkgdir/usr/bin/" target/release/efr target/release/efrd
126 # efrd finds its sandbox launcher in ../lib/efr/ next to its own directory. It is
127 # never on PATH.
128 install -Dm0755 -t "$pkgdir/usr/lib/efr/" target/release/efr-sbx
129 install -Dm0644 -t "$pkgdir/usr/share/zsh/plugins/efr/" shell/zsh/efr.plugin.zsh
130 # The unit of `just install` with the daemon in /usr/bin.
131 install -dm0755 "$pkgdir/usr/lib/systemd/user"
132 sed 's|^ExecStart=%h/\.local/bin/efrd$|ExecStart=/usr/bin/efrd|' systemd/efrd.service \
133 > "$pkgdir/usr/lib/systemd/user/efrd.service"
134 grep -qx 'ExecStart=/usr/bin/efrd' "$pkgdir/usr/lib/systemd/user/efrd.service"
135 install -Dm0644 -t "$pkgdir/usr/share/licenses/$pkgname/" LICENSE
136 install -Dm0644 -t "$pkgdir/usr/share/doc/efr-code/" README.md \
137 docs/config.md docs/permissions.md docs/sandbox.md
138 install -Dm0644 -t "$pkgdir/usr/share/doc/efr-code/examples/" crates/efr-config/examples/config.toml
139}
140

Scan history

Scanned at (UTC)SeverityRules
2026-10-07 20:08:44 Low 3
2026-10-07 20:06:42 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion