libvirt-iso-endeavouros-bin
LOW
maintainer RubenKelevra
1 votes
scanned 2026-09-28 15:21:17.813621
Why flagged
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
PKGBUILD
1
# Maintainer: @RubenKelevra <rubenkelevra@gmail.com>
2
3
_pkgname='endeavouros'
4
_release_name='Titan-Nova'
5
pkgname="libvirt-iso-${_pkgname}-bin"
6
pkgver=2026.08.15
7
pkgrel=2
8
pkgdesc='Official EndeavourOS installation ISO for libvirt'
9
arch=('x86_64')
10
url='https://endeavouros.com/'
11
license=('LicenseRef-Various')
12
checkdepends=(
13
'libarchive'
14
'squashfs-tools'
15
)
16
_iso="EndeavourOS_${_release_name}-${pkgver}.iso"
17
_base_url='https://mirror.moson.org/endeavouros/iso'
18
source=(
19
"${_iso}::${_base_url}/${_iso}"
20
"${_iso}.sig::${_base_url}/${_iso}.sig"
21
'DISTRIBUTION-LICENSE'
22
)
23
noextract=("${_iso}")
24
sha512sums=(
25
'3f83bd745e9d5d518bdf6fc9a24092fb5347da449a6e109c6572bf999097b8b548c4cf1848fdfb3c7c2823f558c3f5b51a127060d9c5b81b9ad89b4041bee7fa'
26
'SKIP'
27
'e9646093ab4151048815230efa2de326f2fc932e7e5704bb1c08aa1ca29aa70107221c5e803ff7bbcf84fca2e0b7be47dc6c144b021cdbf0f898fb3ce64bc152'
28
)
29
validpgpkeys=('8F43FC374CD4CEEA19CEE323E3D8752ACDF595A1')
30
31
_install_payload() {
32
local root="${1:?missing package root}"
33
local image_dir="${root}/var/lib/libvirt/images"
34
35
install -Dm644 -- "${srcdir}/${_iso}" "${image_dir}/${_iso}"
36
ln -s -- "${_iso}" "${image_dir}/${_pkgname}-${CARCH}.iso"
37
install -Dm644 -- "${srcdir}/DISTRIBUTION-LICENSE" \
38
"${root}/usr/share/licenses/${pkgname}/LICENSE"
39
}
40
41
_check_payload() {
42
local root="${1:?missing package root}"
43
local check_owner="${2:-false}"
44
local image_path="${root}/var/lib/libvirt/images/${_iso}"
45
local image_link="${root}/var/lib/libvirt/images/${_pkgname}-${CARCH}.iso"
46
local license_path="${root}/usr/share/licenses/${pkgname}/LICENSE"
47
local manifest
48
49
[[ -f "${image_path}" ]] || return 1
50
[[ -L "${image_link}" ]] || return 1
51
[[ "$(readlink -- "${image_link}")" == "${_iso}" ]] || return 1
52
[[ -f "${license_path}" ]] || return 1
53
[[ "$(stat -c '%a' -- "${image_path}")" == '644' ]] || return 1
54
[[ "$(stat -c '%a' -- "${license_path}")" == '644' ]] || return 1
55
[[ -z "$(find "${root}" -name '*.sig' -print -quit)" ]] || return 1
56
57
manifest="$(find "${root}" \( -type f -o -type l \) -printf '%P\n' | sort)"
58
[[ "${manifest}" == "$(printf '%s\n' \
59
"usr/share/licenses/${pkgname}/LICENSE" \
60
"var/lib/libvirt/images/${_iso}" \
61
"var/lib/libvirt/images/${_pkgname}-${CARCH}.iso")" ]] || return 1
62
63
if [[ "${check_owner}" == 'true' ]]; then
64
[[ "$(stat -c '%u:%g' -- "${image_path}")" == '0:0' ]] || return 1
65
[[ "$(stat -c '%u:%g' -- "${license_path}")" == '0:0' ]] || return 1
66
[[ "$(stat -c '%u:%g' -- "${image_link}")" == '0:0' ]] || return 1
67
fi
68
}
69
70
check() {
71
local iso="${srcdir}/${_iso}"
72
local iso_listing="${srcdir}/check-iso-list"
73
local squashfs="${srcdir}/check-airootfs.sfs"
74
local squashfs_hash_file="${srcdir}/check-airootfs.sha512"
75
local squashfs_root="${srcdir}/check-squashfs-root"
76
local image_size
77
local pvd_type
78
local pvd_magic
79
local pvd_version
80
local volume_sectors
81
local actual_version
82
local expected_squashfs_hash
83
local expected_squashfs_name
84
local actual_squashfs_hash
85
local required_path
86
87
printf '%s\n' 'check: ISO size and ISO9660 header'
88
image_size="$(stat -Lc '%s' -- "${iso}")" || return 1
89
(( image_size > 0 && image_size % 2048 == 0 )) || return 1
90
91
pvd_type="$(od -An -tu1 -j $((16 * 2048)) -N1 -- "${iso}" | tr -d ' ')" || return 1
92
pvd_magic="$(dd if="${iso}" bs=1 skip=$((16 * 2048 + 1)) count=5 status=none)" || return 1
93
pvd_version="$(od -An -tu1 -j $((16 * 2048 + 6)) -N1 -- "${iso}" | tr -d ' ')" || return 1
94
volume_sectors="$(od -An -tu4 -j $((16 * 2048 + 80)) -N4 -- "${iso}" | tr -d ' ')" || return 1
95
96
[[ "${pvd_type}" == '1' ]] || return 1
97
[[ "${pvd_magic}" == 'CD001' ]] || return 1
98
[[ "${pvd_version}" == '1' ]] || return 1
99
(( volume_sectors > 0 && volume_sectors * 2048 == image_size )) || return 1
100
101
printf '%s\n' 'check: file(1) ISO and bootability'
102
file -L --brief -- "${iso}" | grep -Fq 'ISO 9660' || return 1
103
file -L --brief -- "${iso}" | grep -Fq 'bootable' || return 1
104
105
printf '%s\n' 'check: ISO directory and required EndeavourOS files'
106
bsdtar -tf "${iso}" > "${iso_listing}" || return 1
107
for required_path in \
108
"arch/boot/${CARCH}/vmlinuz-linux" \
109
"arch/boot/${CARCH}/initramfs-linux.img" \
110
"arch/${CARCH}/airootfs.sfs" \
111
"arch/${CARCH}/airootfs.sha512" \
112
'arch/pkglist.x86_64.txt' \
113
'arch/version' \
114
'EFI/BOOT/BOOTx64.EFI'; do
115
grep -Fxq -- "${required_path}" "${iso_listing}" || return 1
116
done
117
118
actual_version="$(bsdtar -xOf "${iso}" arch/version)" || return 1
119
[[ "${actual_version}" == "${pkgver}" ]] || return 1
120
121
printf '%s\n' 'check: full ISO read'
122
bsdtar -xOf "${iso}" > /dev/null || return 1
123
124
printf '%s\n' 'check: SquashFS checksum and full decompression'
125
bsdtar -xOf "${iso}" "arch/${CARCH}/airootfs.sha512" > "${squashfs_hash_file}" || return 1
126
read -r expected_squashfs_hash expected_squashfs_name < "${squashfs_hash_file}" || return 1
127
expected_squashfs_name="${expected_squashfs_name#\*}"
128
[[ "${expected_squashfs_hash}" =~ ^[0-9a-f]{128}$ ]] || return 1
129
[[ "${expected_squashfs_name##*/}" == 'airootfs.sfs' ]] || return 1
130
131
bsdtar -xOf "${iso}" "arch/${CARCH}/airootfs.sfs" > "${squashfs}" || return 1
132
actual_squashfs_hash="$(sha512sum -- "${squashfs}" | awk '{print $1}')" || return 1
133
[[ "${actual_squashfs_hash}" == "${expected_squashfs_hash}" ]] || return 1
134
135
rm -rf -- "${squashfs_root}"
136
unsquashfs -no-xattrs -d "${squashfs_root}" "${squashfs}" > /dev/null || return 1
137
if [[ -f "${squashfs_root}/usr/lib/os-release" ]]; then
138
grep -Eq '^ID="?endeavouros"?$' "${squashfs_root}/usr/lib/os-release" || return 1
139
elif [[ -f "${squashfs_root}/etc/os-release" ]]; then
140
grep -Eq '^ID="?endeavouros"?$' "${squashfs_root}/etc/os-release" || return 1
141
else
142
return 1
143
fi
144
145
}
146
147
package() {
148
_install_payload "${pkgdir}"
149
_check_payload "${pkgdir}" true
150
}
151
Changes since previous scan
--- PKGBUILD @ 2026-09-25 00:03+++ PKGBUILD @ 2026-09-28 15:21@@ -4,7 +4,7 @@ _release_name='Titan-Nova' pkgname="libvirt-iso-${_pkgname}-bin" pkgver=2026.08.15-pkgrel=1+pkgrel=2 pkgdesc='Official EndeavourOS installation ISO for libvirt' arch=('x86_64') url='https://endeavouros.com/'@@ -73,7 +73,6 @@ local squashfs="${srcdir}/check-airootfs.sfs" local squashfs_hash_file="${srcdir}/check-airootfs.sha512" local squashfs_root="${srcdir}/check-squashfs-root"- local package_root="${srcdir}/check-package-root" local image_size local pvd_type local pvd_magic@@ -143,10 +142,6 @@ return 1 fi - printf '%s\n' 'check: staged package payload'- rm -rf -- "${package_root}"- _install_payload "${package_root}"- _check_payload "${package_root}" } package() {Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 15:21:17 | Low | 1 |
| 2026-09-25 00:03:36 | Clean | 2 |
| 2026-09-24 21:44:41 | Low | 1 |