libreswan

LOW
maintainer cedricroijakkers 43 votes scanned 2026-10-03 00:23:04.761738
View on AUR
Why flagged

The source URL is hosted on the project's official domain (download.libreswan.org), which is a standard and trusted location for the software, despite not being on the analyzer's whitelist; the package builds from official source code and poses no execution or supply-chain risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source URL is hosted on the project's official domain (download.libreswan.org), which is a standard and trusted location for the software, despite not being on the analyzer's whitelist; the package builds from official source code and poses no execution or supply-chain risk.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:27 "https://download.libreswan.org/${pkgname}-${pkgver}.tar.gz"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Cedric Roijakkers <cedric at roijakkers dot be>.
2# Based on previous work from the following people:
3# Contributor: Chris Severance <aur.severach at spamgourmet dot com>
4# Contributor: Gomasy <nyan at gomasy dot jp>
5# Contributor: Alexandre BIQUE <bique.alexandre at gmail dot com>
6# Contributor: Patrick Burroughs (Celti) <celti at celti dot name>
7
8set -u
9pkgname='libreswan'
10pkgver='5.4'
11pkgrel='1'
12pkgdesc='IPsec implementation with IKEv1 and IKEv2 keying protocols'
13arch=('x86_64' 'armv7h' 'aarch64')
14url='https://libreswan.org/'
15license=('GPL-2.0-or-later')
16depends=('systemd' 'nss' 'libcap-ng' 'curl' 'inetutils' 'audit' 'nspr' 'pam' 'libxcrypt' 'libevent')
17optdepends=(
18 'networkmanager-libreswan: NetworkManager support'
19 'networkmanager-l2tp: L2TP support for NetworkManager using libreswan for IPSec'
20)
21makedepends=('docbook-xsl' 'xmlto' 'flex' 'bison')
22conflicts=('freeswan' 'openswan' 'strongswan' 'ipsec-tools')
23backup=('etc/ipsec.conf' 'etc/ipsec.secrets' 'etc/pam.d/pluto')
24install="${pkgname}.install"
25_srcdir="${pkgname}-${pkgver}"
26source=(
27 "https://download.libreswan.org/${pkgname}-${pkgver}.tar.gz"
28 'tmpfiles.conf'
29 'libreswan.install'
30)
31sha256sums=('d26340cf625316cc9127e05b392214a24a10889f4f1d9940c2ea64bab710a855'
32 '78265c690d58228c3bcc1a8793456172c39d493d268e9d9b1816288d0a47f573'
33 '762be0c8e1df04bcd94776d19b669bbc20754e19cae7c73a2d45fdc370fa4b32')
34
35# https://git.centos.org/rpms/libreswan/blob/c8s/f/SPECS/libreswan.spec
36_bargs=(
37 LIBEXECDIR='/usr/lib/ipsec'
38 #INC_MANDIR='/usr/share/man'
39 MANDIR='/usr/share/man'
40 SBINDIR='/usr/bin'
41 #INC_USRLOCAL='/usr' # required by 3.32 for /usr/share/doc
42 PREFIX='/usr'
43 USE_DNSSEC=false
44 USE_LABELED_IPSEC=false
45 USE_LIBCAP_NG=true
46 USE_DH2=false # insecure modp1024; broken in 5.4, see https://github.com/libreswan/libreswan/issues/2980
47
48 USE_LEAK_DETECTIVE=false
49 USE_XAUTH=true
50)
51
52prepare() {
53 set -u
54 bash -n "${srcdir}/${install}"
55 set +u
56}
57
58build() {
59 set -u
60 cd "${_srcdir}"
61
62 # Disable preprocessor warnings, because the build failed with GCC 13.2
63 local _cf=(
64 -Wp,-w
65 )
66
67 CFLAGS="${CFLAGS} ${_cf[*]}" \
68 nice make -s "${_bargs[@]}" programs
69 set +u
70}
71
72package() {
73 set -u
74 cd "${_srcdir}"
75
76 make -j1 DESTDIR="${pkgdir}/" "${_bargs[@]}" install
77
78 #sed -e '1s|python\b|python2|' -i "${pkgdir}/usr/lib/ipsec"/{verify,show}
79 install -Dpm644 "${srcdir}/tmpfiles.conf" "${pkgdir}/usr/lib/tmpfiles.d/libreswan.conf"
80 rm -rf "${pkgdir}/var"
81
82 install -Dpm644 <(cat << EOF
83# Automatically generated by ${pkgname}-${pkgver} PKGBUILD from Arch Linux AUR
84# https://aur.archlinux.org/
85
86# Disable redirects for ipsec tunnels
87
88net.ipv4.conf.default.accept_redirects = 0
89net.ipv4.conf.default.send_redirects = 0
90EOF
91 ) "${pkgdir}/usr/lib/sysctl.d/${pkgname}-icmp-redirects.conf"
92 install -Dm644 <(sed -e 's: = 0: = 1:g' "${pkgdir}/usr/lib/sysctl.d/${pkgname}-icmp-redirects.conf") "${pkgdir}/usr/lib/${pkgname}/icmp-redirects.conf.revert"
93
94 if [ "$(vercmp "${pkgver}" '4.0')" -ge 0 ]; then
95 install -dm700 "${pkgdir}/var/lib/ipsec/nss"
96 fi
97 set +u
98}
99set +u
100# vim:set ts=2 sw=2 et:
101

Scan history

Scanned at (UTC)SeverityRules
2026-10-03 00:23:04 Low 2
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion