electric-bin

maintainer sapient_cogbag · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads prebuilt JAR files and data assets from a non-whitelisted but plausibly project-associated host (staticfreesoft.com), but these are primarily data files and libraries for a legacy Java application; the main executable JAR is sourced from the official GNU mirror, and there is no evidence of malicious payloads or remote code execution.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt JAR files and data assets from a non-whitelisted but plausibly project-associated host (staticfreesoft.com), but these are primarily data files and libraries for a legacy Java application; the main executable JAR is sourced from the official GNU mirror, and there is no evidence of malicious payloads or remote code execution.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:18 "electric-staticfreesoft-extras-$pkgver.jar::https://www.staticfreesoft.com/electricSFS-$pkgver.jar"
  • PKGBUILD:25 "electric-sclib.jelib::https://personalpages.hs-kempten.de/~vollratj/Microelectronics/jelib/sclib.jelib"

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: sapient_cogbag <sapient_cogbag at protonmail dot com>
2pkgname=electric-bin
3pkgver=9.07
4pkgrel=2
5pkgdesc="Integrated circuit physical layout design & simulation tool"
6arch=('any')
7url="https://www.staticfreesoft.com/index.html"
8license=('GPL' 'custom:IRSIM')
9# For BSDTAR
10makedepends=('libarchive')
11depends=('java-runtime' 'java3d' 'bash')
12provides=('electric')
13conflicts=('electric')
14# While I would prefer to build from source, I don't understand SVN well enough to pull from trunk instead of
15# the 9.07 tag. Furthermore, this is a seriously-legacy application with tons of obscure java stuff.
16source=(
17 "https://ftpmirror.gnu.org/gnu/electric/electric-$pkgver.jar"
18 "electric-staticfreesoft-extras-$pkgver.jar::https://www.staticfreesoft.com/electricSFS-$pkgver.jar"
19
20 "electric-manual-$pkgver.pdf::https://www.staticfreesoft.com/jmanual/ElectricManual-$pkgver.pdf"
21
22 "electric-boise-state-standard-cmos-sclib.jelib::https://www.staticfreesoft.com/contrib/CMOScells.jelib"
23 "electric-harvey-mudd-college-sclib.jelib::https://www.staticfreesoft.com/contrib/muddLib07.jelib.gz"
24 "electric-city-engineering-college-bangalore-mosis-cmos-180nm-sclib.jelib::https://www.staticfreesoft.com/contrib/MOSIS180nmCells.jelib"
25 "electric-sclib.jelib::https://personalpages.hs-kempten.de/~vollratj/Microelectronics/jelib/sclib.jelib"
26
27 "electric-sun-microsystems-laboratories-mosis-cmos-350nm-pads.jelib::https://www.staticfreesoft.com/contrib/pads4u.jelib"
28
29 "electric-harvey-mudd-college-example-mips-chip-32bit::https://www.staticfreesoft.com/contrib/muddChip.tar.gz"
30 "electric-sun-microsystems-test-chip-qThree::https://www.staticfreesoft.com/contrib/qThree.tar.gz"
31
32 "electric"
33 "electric.desktop"
34)
35
36sha512sums=(
37 'b68e86ad16a7e97bd6fee72da90e2bd403c54cecb3055505b6f8eaa85125546b83e268da12cf57bedaa33dab78a387f7b7ba8aa33ce6412588e339759aa1a716'
38 '1e99f1ec7c6dec8f64e10f993261992233cb8c3d246ffebbc9d1521376b9a0ebe987c48a7d5c251ca212d96c477645420af2a70cef00b5da2eb5f60cf61506e1'
39
40 'b68027b300b75f92a531c8bf2a273bb571f0c3d839ef3819bde60bd4ed60bb63e35ec9c93488859d74ba43e68e7aee57cf72330640780f31036a4ff2d999ea5e'
41
42 '2b7787fac634418300da37469731a364d0f92868fc408aff11a79f8597211db2b49a68061e00738e36c9a745aef646acd1b49a462e0c6b8f9dd9386436f1c767'
43 '19ecf7e8a6dbddcf7312b2443cda201b1afa20f7fd5fb3ef70ec1870a9909cb3b82b3536739cab76beb3e5fc0e55c050a3641ea82089d3599f890bfa9ec1afb5'
44 '86bb6e8fc0451cbda3b08e591c99c0859c7e6274c8e76b8c3182fc6845f34d653b37f16b522cad255ccd1f262fd26e8543385430af6e28320ed98841abda59ef'
45 'd1ae31523a271e863315c1ca93325e4527c29769a0f354b165ab2e256d19c0c1d362b272f8e72e53610c03bd4f5ea2c7292865d566ceab1d8ee36106be9c95e0'
46
47 'd155f089815f4ab4210c5e6d97559589c065bf3794f51f3f09e95b7f71612e6e838083a63169916a7ebc4caa75cb5be7eefa954f31e831528c5d7dee1717e363'
48
49 'f0c3d5bcac80beb302a5f9c235352cc877539fb4d93803dc858f97c79ad5201ee53a91393a60df5bd075e13f22af048e582b3ba98912676e21a05ebf7ec33e08'
50 'b55b44bcd8c5a35ab17b35a1dec36b49eb2bd94f6f9c7e1f5db9c39ac44ec4af5081e5e3625b2a5f17a602c083f3895ca6df66a3af3e53c18ae883906c902010'
51
52 'e3498bdd381ffeb369d685592d1215b800ec66d6e6c28a68be389f6592e72091fdac70506caf22df45458a4ff2f3f6eb8918693aae67eda72179fedb510ad649'
53 '47640352c0d3922494104fbb7dec28d0b967dbbf5c0a464f6565eae657cc60049a219d59adc91adeea359b00f001a84ef4788d9eafd84fd2f59a6673ee5be179'
54)
55
56# We shouldn't be extracting jar files!
57noextract=(
58 "electric-$pkgver.jar"
59 "electric-staticfreesoft-extras-$pkgver.jar"
60)
61
62prepare() {
63 # Extract IRSIM license from the staticfreesoft-extras jar file.
64 cd "$srcdir"
65 bsdtar -f "electric-staticfreesoft-extras-$pkgver.jar" -x "LicenseIRSIM.txt"
66
67 # Extract the electric icon
68 bsdtar -f "electric-$pkgver.jar" -x "ElectricIcon64x64.png"
69}
70
71package() {
72 cd "$srcdir"
73
74 local ELECTRIC_MAIN_ROOT="$pkgdir/usr/share/java/electric"
75
76 # the harvey mudd chip goes in it's own "muddChip" folder, but the other chip example gets extracted out into the main folder
77 # All other jelib files are the standard cell libraries, but they are also *all symlinks* in src
78 # since they're provided as files directly rather than being shunted into a gz or zip folder.
79 # As such, we:
80 # * Move the mudd chip into the main examples folder nya~
81 # * Move all non-symlink jelib files into the sun microsystems test chip folder. Note we just do this by hand.
82 # * Copy the symlinked files into their respective folders (either standard cells or pads or any others)
83 # * Move the jar files too :)
84 #
85 # Then we can establish the executor script.
86 # -T => target is file
87 # -t => reverse order and target is directory
88 # -D => create any directory components of the target (if it's file like, this doesn't include the last, if it's directory like, it does nya)
89 install -Dm0755 -T "electric-$pkgver.jar" "$ELECTRIC_MAIN_ROOT/electric.jar"
90 install -Dm0755 -T "electric-staticfreesoft-extras-$pkgver.jar" "$ELECTRIC_MAIN_ROOT/electric-sfs-extras.jar"
91 # IRSIM license
92 install -Dm0644 -t "$pkgdir/usr/share/licenses/electric-bin/irsim/" "LicenseIRSIM.txt"
93 # Manual
94 install -Dm0644 -T "electric-manual-$pkgver.pdf" "$ELECTRIC_MAIN_ROOT/manual.pdf"
95 # Icon
96 install -Dm0644 -T "ElectricIcon64x64.png" "$pkgdir/usr/share/pixmaps/electric.png"
97 # Desktop file
98 install -Dm0755 -T "electric.desktop" "$pkgdir/usr/share/applications/electric.desktop"
99
100 # Standard Cell Libraries
101 install -Dm0644 -T "electric-boise-state-standard-cmos-sclib.jelib" "$ELECTRIC_MAIN_ROOT/sclib/boise-state-standard-cmos.jelib"
102 install -Dm0644 -T "electric-harvey-mudd-college-sclib.jelib" "$ELECTRIC_MAIN_ROOT/sclib/harvey-mudd-college.jelib"
103 install -Dm0644 -T "electric-city-engineering-college-bangalore-mosis-cmos-180nm-sclib.jelib" "$ELECTRIC_MAIN_ROOT/sclib/city-engineering-college-bangalore-mosis-cmos-180nm.jelib"
104 install -Dm0644 -T "electric-sclib.jelib" "$ELECTRIC_MAIN_ROOT/sclib/sclib.jelib"
105
106 # Pad Libraries
107 install -Dm0644 -T "electric-sun-microsystems-laboratories-mosis-cmos-350nm-pads.jelib" "$ELECTRIC_MAIN_ROOT/pads/sun-microsystems-laboratories-mosis-cmos-350nm.jelib"
108
109 # Example chips.
110 # This first one is from that harvey mudd college, but it gets extracted as a single folder.
111 install -Dm0644 -t "$ELECTRIC_MAIN_ROOT/examples/harvey-mudd-college-example-mips-chip-32bit" "muddChip"/*
112 local sun_microsystems_test_chip_files=(
113 "capFC2.jelib"
114 "group.jelib"
115 "jtag.jelib"
116 "padParts.jelib"
117 "purpleThree.jelib"
118 "qThree_pads_180nm.jelib"
119 "qThreeTop.jelib"
120 "rowColScan.jelib"
121 "scanChain.jelib"
122 "scanFans.jelib"
123 "txrx.jelib"
124 )
125
126 for test_chip_file in "${sun_microsystems_test_chip_files[@]}"; do
127 install -Dm0644 -t "$ELECTRIC_MAIN_ROOT/examples/sun-microsystems-test-chip-qThree" "$test_chip_file"
128 done
129
130 install -Dm0755 -t "$pkgdir/usr/bin/" "$srcdir/electric"
131
132}
133

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion