lib32-glibc-eac
MEDIUM
maintainer xiota
13 votes
base
glibc-eac
scanned 2026-10-05 23:40:58.404909
Why flagged
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
Triggered rules
Medium
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:28
glibc::git+https://forge.sourceware.org/glibc/glibc-mirror#commit=${_commit}
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Based on core/glibc, synced on 2026-09-29
2
export LDFLAGS+=" -Wl,--hash-style=both"
3
4
# toolchain build order: linux-api-headers->glibc->binutils->gcc->glibc->binutils->gcc
5
# NOTE: valgrind requires rebuilt with each major glibc version
6
7
pkgbase=glibc-eac
8
pkgname=(glibc-eac lib32-glibc-eac)
9
pkgver=2.44+r50+g1848099f063e
10
_commit=1848099f063e99d4ffecbd7667766d54862398b9
11
pkgrel=1
12
arch=(x86_64 aarch64)
13
url='https://www.gnu.org/software/libc'
14
license=(GPL-2.0-or-later LGPL-2.1-or-later)
15
makedepends=(
16
gd
17
git
18
python
19
)
20
makedepends_x86_64=(
21
lib32-gcc-libs
22
)
23
options=(
24
staticlibs
25
!lto
26
)
27
source=(
28
glibc::git+https://forge.sourceware.org/glibc/glibc-mirror#commit=${_commit}
29
locale.gen.txt
30
locale-gen
31
lib32-glibc.conf
32
sdt.h
33
sdt-config.h
34
tunables.conf
35
shstk.conf
36
10-glibc-locale-gen.hook
37
10-glibc-remove-locale-archive.hook
38
11-glibc-ldconfig.hook
39
11-glibc-remove-ldconfig-cache.hook
40
12-glibc-iconvconfig.hook
41
12-glibc-remove-iconvconfig-cache.hook
42
12-lib32-glibc-iconvconfig.hook
43
12-lib32-glibc-remove-iconvconfig-cache.hook
44
)
45
validpgpkeys=(7273542B39962DF7B299931416792B4EA25340F8 # Carlos O'Donell
46
BC7C7372637EC10C57D7AA6579C43DFBF1CF2187) # Siddhesh Poyarekar
47
b2sums=('91eb837659e2ced59a06cff6050d897cc28dc8467e05514db28b0ad6c4dbbe6d0ec0cd77024da016c4e6b0fc2b013fa8cb4d1eb78aab3e0fd44328050a0e6f46'
48
'c859bf2dfd361754c9e3bbd89f10de31f8e81fd95dc67b77d10cb44e23834b096ba3caa65fbc1bd655a8696c6450dfd5a096c476b3abf5c7e125123f97ae1a72'
49
'bdc313a77d7158768b06864fdee6419b25f9eda5b942a394713bf61e289a37993d003c779761be4a70d9febeee2377ba2912f459e879801e3d80f4d0550a2592'
50
'7c265e6d36a5c0dff127093580827d15519b6c7205c2e1300e82f0fb5b9dd00b6accb40c56581f18179c4fbbc95bd2bf1b900ace867a83accde0969f7b609f8a'
51
'a6a5e2f2a627cc0d13d11a82458cfd0aa75ec1c5a3c7647e5d5a3bb1d4c0770887a3909bfda1236803d5bc9801bfd6251e13483e9adf797e4725332cd0d91a0e'
52
'214e995e84b342fe7b2a7704ce011b7c7fc74c2971f98eeb3b4e677b99c860addc0a7d91b8dc0f0b8be7537782ee331999e02ba48f4ccc1c331b60f27d715678'
53
'315cf92976714d88c60d23a3114e172f26ade1c1461bd2939b6842b03cd76ec63a3c867af5eab56f8c61d3f011158d69194ef1495e28ac47fd60b9f8bd76673c'
54
'9725f12fce07b9f5bc413c6d8a3fa7887d4531e499bb0d56588791be74219ae978b60688ad61a7ffca1d4915ba191cd98ddaaa8931f7c72176086de6d4b50948'
55
'88b36b26d8ee8ac0d2034106d3ba9595296e6d474d5b892f165701865ff790515f979693897b6c23bb421e7e091b3e7367ec1065a7e9dbaab3b0546e1b037009'
56
'9aea685518e63377b745c83ce51c36434f2a3c181440d108ecad915ec6162087302710c1bd95a1097af4ad66468a7fae485881fb030bc2dd886882864b36bdfe'
57
'a5884949727babde41941ba276b696f2f473fb4936ade4da7f7f376cddd1ba189efc1b24fa5b8f4861d3988c3e22404ba5806fa8b67437635eaa73df0c0dc13c'
58
'c18f52b188ecde915a0d3b69fd87391fdf4a8800a3cd5332456f3009d5c1161944d7ab10a7f2a68fb0b035b69ae1576cb80c1a81ce94ae410066ad19f3d5c196'
59
'8537d5d673e73c3656c474ad46d30fce23a317ee6758e304875e3099f1a2250da8a7fb358fb1785dfde704d06c5ab7cdf18e213f7906cdcafa586d3d7b60d085'
60
'55ca66ad10e5e8ecb7f205acd009a3ca945c27894047e1ace20866a14d5dd9f2b97e23e6da678877363c2963a6fc2ef83030b4f5de6d7bf84da88bd7434c5596'
61
'a6fa4b559b4b701b8fcee294d0a30371de233ba5cb3a08f915b9aa9be42e08e70814a71f74b9e87e8936a847b621fac0b282e8260ea3d728a26ce879953ff17f'
62
'8836f747a59cab143679eb751bc67f79b2bd1057f2108a984e63905b8404caeeec5f2e01bfbb42e83e1c7d24e2b10731a9abab4b8b472588e9196c1d519ac3e2')
63
64
pkgver() {
65
cd glibc
66
git describe --abbrev=12 --tags | sed 's/[^-]*-//;s/[^-]*-/&r/;s/-/+/g'
67
}
68
69
prepare() {
70
mkdir -p glibc-build lib32-glibc-build
71
72
[[ -d glibc-$pkgver ]] && ln -s glibc-$pkgver glibc
73
cd glibc
74
}
75
76
build() {
77
local _configure_flags=(
78
--prefix=/usr
79
--with-headers=/usr/include
80
--with-bugurl=https://gitlab.archlinux.org/archlinux/packaging/packages/glibc/-/issues
81
--enable-bind-now
82
--enable-fortify-source
83
--enable-kernel=4.4
84
--enable-multi-arch
85
--enable-stack-protector=strong
86
--enable-systemtap
87
--disable-nscd
88
--disable-profile
89
--disable-werror
90
)
91
92
# _FORTIFY_SOURCE=3 causes testsuite build failure and is unnecessary during
93
# actual builds (support is built-in via --enable-fortify-source).
94
CFLAGS=${CFLAGS/-Wp,-D_FORTIFY_SOURCE=3/}
95
96
# ldconfig segfaults without this on glibc 2.44
97
if [[ ${CARCH} = "aarch64" ]]; then
98
CFLAGS=${CFLAGS/-fno-plt/}
99
fi
100
101
(
102
cd glibc-build
103
104
echo "slibdir=/usr/lib" >> configparms
105
echo "rtlddir=/usr/lib" >> configparms
106
echo "sbindir=/usr/bin" >> configparms
107
echo "rootsbindir=/usr/bin" >> configparms
108
109
"${srcdir}"/glibc/configure \
110
--libdir=/usr/lib \
111
--libexecdir=/usr/lib \
112
--enable-cet \
113
--enable-sframe \
114
"${_configure_flags[@]}"
115
116
make -O
117
118
# build info pages manually for reproducibility
119
make info
120
)
121
122
if [[ ${CARCH} == x86_64* ]]; then (
123
cd lib32-glibc-build
124
export CC="gcc -m32 -mstackrealign"
125
export CXX="g++ -m32 -mstackrealign"
126
127
# remove frame pointer flags due to crashes of nvidia driver on steam starts
128
# See https://gitlab.archlinux.org/archlinux/packaging/packages/glibc/-/issues/10
129
CFLAGS=${CFLAGS/-fno-omit-frame-pointer -mno-omit-leaf-frame-pointer/}
130
131
echo "slibdir=/usr/lib32" >> configparms
132
echo "rtlddir=/usr/lib32" >> configparms
133
echo "sbindir=/usr/bin" >> configparms
134
echo "rootsbindir=/usr/bin" >> configparms
135
136
"${srcdir}"/glibc/configure \
137
--host=i686-pc-linux-gnu \
138
--libdir=/usr/lib32 \
139
--libexecdir=/usr/lib32 \
140
"${_configure_flags[@]}"
141
142
make -O
143
)
144
fi
145
# pregenerate locales here instead of in package
146
# functions because localedef does not like fakeroot
147
make -C "${srcdir}"/glibc/localedata objdir="${srcdir}"/glibc-build \
148
DESTDIR="${srcdir}"/locales install-locale-files
149
}
150
151
# Credits for _skip_test() and check() @allanmcrae
152
# https://github.com/allanmcrae/toolchain/blob/f18604d70c5933c31b51a320978711e4e6791cf1/glibc/PKGBUILD
153
_skip_test() {
154
test=${1}
155
file=${2}
156
sed -i "/\b${test} /d" "${srcdir}/glibc/${file}"
157
}
158
159
_check() (
160
cd glibc-build
161
162
# adjust/remove buildflags that cause false-positive testsuite failures
163
sed -i 's/-Werror=format-security/-Wformat-security/' config.make # failure to build testsuite
164
sed -i '/CFLAGS/s/-fno-plt//' config.make # 27 failures
165
sed -i '/CFLAGS/s/-fexceptions//' config.make # 1 failure
166
167
# The following tests fail due to restrictions in the Arch build system
168
# The correct fix is to add the following to the systemd-nspawn call:
169
# --system-call-filter="@clock @memlock @pkey"
170
_skip_test tst-ldconfig-cache elf/Makefile
171
_skip_test tst-pthread-gdb-attach nptl/Makefile
172
_skip_test tst-pthread-gdb-attach-static nptl/Makefile
173
_skip_test test-errno-linux sysdeps/unix/sysv/linux/Makefile
174
_skip_test tst-mlock2 sysdeps/unix/sysv/linux/Makefile
175
_skip_test tst-ntp_gettime sysdeps/unix/sysv/linux/Makefile
176
_skip_test tst-ntp_gettimex sysdeps/unix/sysv/linux/Makefile
177
_skip_test tst-pkey sysdeps/unix/sysv/linux/Makefile
178
_skip_test tst-mseal-pkey sysdeps/unix/sysv/linux/Makefile
179
_skip_test tst-process_mrelease sysdeps/unix/sysv/linux/Makefile
180
_skip_test tst-shstk-legacy-1g sysdeps/x86_64/Makefile
181
_skip_test tst-adjtime time/Makefile
182
183
make -O check
184
)
185
186
package_glibc-eac() {
187
provides=("glibc=$pkgver")
188
conflicts=(glibc)
189
pkgdesc='GNU C Library with DT_HASH enabled'
190
depends=('linux-api-headers>=4.10' tzdata filesystem)
191
optdepends=(
192
'gd: for memusagestat'
193
'perl: for mtrace'
194
)
195
backup=(
196
etc/gai.conf
197
etc/locale.gen
198
etc/tunables.conf
199
etc/tunables.conf.d/shstk.conf
200
)
201
202
make -C glibc-build DESTDIR="${pkgdir}" install
203
rm -f "${pkgdir}"/etc/ld.so.cache
204
205
# Shipped in tzdata
206
rm -f "${pkgdir}"/usr/bin/{tzselect,zdump,zic}
207
208
cd glibc
209
210
install -dm755 "${pkgdir}"/usr/lib/locale
211
212
install -m644 posix/gai.conf "${pkgdir}"/etc/gai.conf
213
214
install -m755 "${srcdir}"/locale-gen "${pkgdir}"/usr/bin
215
216
# Create /etc/locale.gen
217
install -m644 "${srcdir}"/locale.gen.txt "${pkgdir}"/etc/locale.gen
218
sed -e '1,3d' -e 's|/| |g' -e 's|\\| |g' -e 's|^|#|g' \
219
localedata/SUPPORTED >> "${pkgdir}"/etc/locale.gen
220
221
# Add SUPPORTED file to pkg
222
sed -e '1,3d' -e 's|/| |g' -e 's| \\||g' \
223
localedata/SUPPORTED > "${pkgdir}"/usr/share/i18n/SUPPORTED
224
225
# install C.UTF-8 so that it is always available
226
# should be built into glibc eventually
227
# https://sourceware.org/glibc/wiki/Proposals/C.UTF-8
228
# https://bugs.archlinux.org/task/74864
229
install -dm755 "${pkgdir}"/usr/lib/locale
230
cp -r "${srcdir}"/locales/usr/lib/locale/C.utf8 -t "${pkgdir}"/usr/lib/locale
231
sed -i '/#C\.UTF-8 /d' "${pkgdir}"/etc/locale.gen
232
233
# Provide tracing probes to libstdc++ for exceptions, possibly for other
234
# libraries too. Useful for gdb's catch command.
235
install -Dm644 "${srcdir}"/sdt.h "${pkgdir}"/usr/include/sys/sdt.h
236
install -Dm644 "${srcdir}"/sdt-config.h "${pkgdir}"/usr/include/sys/sdt-config.h
237
238
# Install relevant pre- and post-transaction hooks.
239
install -vDm 644 ../10-glibc-locale-gen.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
240
install -vDm 644 ../10-glibc-remove-locale-archive.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
241
install -vDm 644 ../11-glibc-ldconfig.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
242
install -vDm 644 ../11-glibc-remove-ldconfig-cache.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
243
install -vDm 644 ../12-glibc-iconvconfig.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
244
install -vDm 644 ../12-glibc-remove-iconvconfig-cache.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
245
246
# Install tunables.conf
247
install -vDm 644 ../tunables.conf -t "${pkgdir}"/etc/
248
install -vDm 644 ../shstk.conf -t "${pkgdir}"/etc/tunables.conf.d/
249
}
250
251
package_lib32-glibc-eac() {
252
provides=("lib32-glibc=$pkgver")
253
conflicts=(lib32-glibc)
254
pkgdesc='GNU C Library with DT_HASH enabled (32-bit)'
255
depends=("glibc=$pkgver")
256
options+=('!emptydirs')
257
arch=(x86_64)
258
259
cd lib32-glibc-build
260
261
make DESTDIR="${pkgdir}" install
262
rm -rf "${pkgdir}"/{etc,sbin,usr/{bin,sbin,share},var}
263
264
# We need to keep 32 bit specific header files
265
find "${pkgdir}"/usr/include -type f -not -name '*-32.h' -delete
266
267
# Dynamic linker
268
install -d "${pkgdir}"/usr/lib
269
ln -s ../lib32/ld-linux.so.2 "${pkgdir}"/usr/lib/
270
271
# Add lib32 paths to the default library search path
272
install -Dm644 "${srcdir}"/lib32-glibc.conf "${pkgdir}"/etc/ld.so.conf.d/lib32-glibc.conf
273
274
# Symlink /usr/lib32/locale to /usr/lib/locale
275
ln -s ../lib/locale "${pkgdir}"/usr/lib32/locale
276
277
# Install relevant pre- and post-transaction hooks.
278
install -vDm 644 ../12-lib32-glibc-iconvconfig.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
279
install -vDm 644 ../12-lib32-glibc-remove-iconvconfig-cache.hook -t "${pkgdir}"/usr/share/libalpm/hooks/
280
}
281
282
_package_glibc-locales() {
283
provides=("glibc-locales=$pkgver")
284
conflicts=(glibc-locales)
285
pkgdesc='Pregenerated locales for GNU C Library with DT_HASH enabled'
286
depends=("glibc=$pkgver")
287
288
cp -r locales/* -t "${pkgdir}"
289
rm -r "${pkgdir}"/usr/lib/locale/C.utf8
290
291
# deduplicate locale data
292
hardlink -c "${pkgdir}"/usr/lib/locale
293
}
294
Changes since previous scan
--- PKGBUILD @ 2026-08-13 00:17+++ PKGBUILD @ 2026-10-05 23:40@@ -1,4 +1,4 @@-# Maintainer: Based on core/glibc, synced on 2026-08-12+# Maintainer: Based on core/glibc, synced on 2026-09-29 export LDFLAGS+=" -Wl,--hash-style=both" # toolchain build order: linux-api-headers->glibc->binutils->gcc->glibc->binutils->gcc@@ -6,8 +6,8 @@ pkgbase=glibc-eac pkgname=(glibc-eac lib32-glibc-eac)-pkgver=2.44+r24+g16be1518495f-_commit=16be1518495f1fa05481b0182c4e4c24927c62df+pkgver=2.44+r50+g1848099f063e+_commit=1848099f063e99d4ffecbd7667766d54862398b9 pkgrel=1 arch=(x86_64 aarch64) url='https://www.gnu.org/software/libc'@@ -44,7 +44,7 @@ ) validpgpkeys=(7273542B39962DF7B299931416792B4EA25340F8 # Carlos O'Donell BC7C7372637EC10C57D7AA6579C43DFBF1CF2187) # Siddhesh Poyarekar-b2sums=('df2b52cfca4b4a7ad04db0c3c47ef4d65f0053a5a2d137aa06e660615f70e30a53c9375c2975c9d2c81eaff80e968b468e90fcf7f917b0802af16cf60c417003'+b2sums=('91eb837659e2ced59a06cff6050d897cc28dc8467e05514db28b0ad6c4dbbe6d0ec0cd77024da016c4e6b0fc2b013fa8cb4d1eb78aab3e0fd44328050a0e6f46' 'c859bf2dfd361754c9e3bbd89f10de31f8e81fd95dc67b77d10cb44e23834b096ba3caa65fbc1bd655a8696c6450dfd5a096c476b3abf5c7e125123f97ae1a72' 'bdc313a77d7158768b06864fdee6419b25f9eda5b942a394713bf61e289a37993d003c779761be4a70d9febeee2377ba2912f459e879801e3d80f4d0550a2592' '7c265e6d36a5c0dff127093580827d15519b6c7205c2e1300e82f0fb5b9dd00b6accb40c56581f18179c4fbbc95bd2bf1b900ace867a83accde0969f7b609f8a'Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-05 23:40:58 | Medium | 1 |
| 2026-08-13 00:17:07 | Clean | 2 |
| 2026-08-12 05:22:53 | Medium | 1 |
| 2026-07-30 00:17:23 | Clean | 2 |
| 2026-07-29 03:10:20 | Medium | 1 |
| 2026-07-27 00:24:32 | Clean | 2 |
| 2026-07-26 23:33:54 | Medium | 1 |
| 2026-07-26 21:33:42 | Medium | 1 |
| 2026-07-16 00:05:41 | Clean | 2 |
| 2026-07-15 07:48:03 | Medium | 1 |
| 2026-06-19 19:07:35 | Clean | 2 |
| 2026-06-18 16:11:54 | Medium | 1 |