libvirt-iso-kde-linux-bin
LOW
maintainer RubenKelevra
0 votes
scanned 2026-09-28 15:21:17.813621
Why flagged
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
Triggered rules
Low
Few votes, recently uploaded
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
PKGBUILD
1
# Maintainer: @RubenKelevra <rubenkelevra@gmail.com>
2
3
_pkgname='kde-linux'
4
pkgname="libvirt-iso-${_pkgname}-bin"
5
pkgver=202609200254
6
pkgrel=1
7
pkgdesc='Official KDE Linux Testing installation ISO for libvirt'
8
arch=('x86_64')
9
url='https://linux.kde.org/'
10
license=('LicenseRef-Various')
11
checkdepends=(
12
'7zip'
13
'gptfdisk'
14
'mtools'
15
)
16
_iso="${_pkgname}_${pkgver}.iso"
17
_base_url='https://files.kde.org/kde-linux'
18
19
# KDE publishes SHA256SUMS.gpg, but not the public key required to verify it.
20
# Their impressively decorative signature has been documented here:
21
# https://invent.kde.org/kde-linux/kde-linux/-/issues/223
22
#
23
# If KDE ever finds its public key again, uncomment the quoted lines below to
24
# restore signature verification. The signed SHA256SUMS is then tied back to
25
# the pinned ISO digest in check(). Keep this disabled until the key is actually
26
# obtainable; SHA256SUMS is also rolling, so old package versions depend on KDE
27
# retaining the selected ISO entry there.
28
source=(
29
"${_iso}::${_base_url}/${_iso}"
30
'DISTRIBUTION-LICENSE'
31
# "SHA256SUMS::${_base_url}/SHA256SUMS"
32
# "SHA256SUMS.sig::${_base_url}/SHA256SUMS.gpg"
33
)
34
noextract=("${_iso}")
35
sha256sums=(
36
'697cac07865236b456c76c2f1d1db7dc360936992787a0a1cf796f2e671f2adf'
37
'9280ddacc03cb58f09b31483a06dba9216a0cfde2fe53091ff571504c4095160'
38
# 'SKIP'
39
# 'SKIP'
40
)
41
# validpgpkeys=('15AB3EE61CE450CFED1407BF4121B5F4EAEB53CA')
42
43
_install_payload() {
44
local root="${1:?missing package root}"
45
local image_dir="${root}/var/lib/libvirt/images"
46
47
install -Dm644 -- "${srcdir}/${_iso}" "${image_dir}/${_iso}"
48
ln -s -- "${_iso}" "${image_dir}/${_pkgname}-${CARCH}.iso"
49
install -Dm644 -- "${srcdir}/DISTRIBUTION-LICENSE" \
50
"${root}/usr/share/licenses/${pkgname}/LICENSE"
51
}
52
53
_check_payload() {
54
local root="${1:?missing package root}"
55
local check_owner="${2:-false}"
56
local image_path="${root}/var/lib/libvirt/images/${_iso}"
57
local image_link="${root}/var/lib/libvirt/images/${_pkgname}-${CARCH}.iso"
58
local license_path="${root}/usr/share/licenses/${pkgname}/LICENSE"
59
local manifest
60
61
[[ -f "${image_path}" ]] || return 1
62
[[ -L "${image_link}" ]] || return 1
63
[[ "$(readlink -- "${image_link}")" == "${_iso}" ]] || return 1
64
[[ -f "${license_path}" ]] || return 1
65
[[ "$(stat -c '%a' -- "${image_path}")" == '644' ]] || return 1
66
[[ "$(stat -c '%a' -- "${license_path}")" == '644' ]] || return 1
67
68
manifest="$(find "${root}" \( -type f -o -type l \) -printf '%P\n' | sort)"
69
[[ "${manifest}" == "$(printf '%s\n' \
70
"usr/share/licenses/${pkgname}/LICENSE" \
71
"var/lib/libvirt/images/${_iso}" \
72
"var/lib/libvirt/images/${_pkgname}-${CARCH}.iso")" ]] || return 1
73
74
if [[ "${check_owner}" == 'true' ]]; then
75
[[ "$(stat -c '%u:%g' -- "${image_path}")" == '0:0' ]] || return 1
76
[[ "$(stat -c '%u:%g' -- "${license_path}")" == '0:0' ]] || return 1
77
[[ "$(stat -c '%u:%g' -- "${image_link}")" == '0:0' ]] || return 1
78
fi
79
}
80
81
_partition_start() {
82
local iso="${1:?missing ISO path}"
83
local partition="${2:?missing partition number}"
84
local start
85
86
start="$(LC_ALL=C sgdisk -i "${partition}" "${iso}" |
87
sed -n 's/^First sector: \([0-9][0-9]*\).*/\1/p')" || return 1
88
[[ "${start}" =~ ^[0-9]+$ ]] || return 1
89
(( start > 0 )) || return 1
90
printf '%s\n' "${start}"
91
}
92
93
_check_partition() {
94
local iso="${1:?missing ISO path}"
95
local partition="${2:?missing partition number}"
96
local type_guid="${3:?missing type GUID}"
97
local name="${4:?missing partition name}"
98
local info
99
100
info="$(LC_ALL=C sgdisk -i "${partition}" "${iso}")" || return 1
101
grep -Fq "Partition GUID code: ${type_guid} " <<< "${info}" || return 1
102
grep -Fq "Partition name: '${name}'" <<< "${info}" || return 1
103
}
104
105
check() {
106
local iso="${srcdir}/${_iso}"
107
# grep -Fxq "${sha256sums[0]} ${_iso}" "${srcdir}/SHA256SUMS" || return 1
108
local esp_boot="${srcdir}/check-BOOTX64.EFI"
109
local partition_head="${srcdir}/check-partition-head"
110
local image_size
111
local image_description
112
local gpt_report
113
local partition_count
114
local esp_start
115
local root_start
116
local extension_start
117
118
printf '%s\n' 'check: ISO identity and bootability'
119
image_size="$(stat -Lc '%s' -- "${iso}")" || return 1
120
(( image_size > 0 && image_size % 2048 == 0 )) || return 1
121
image_description="$(file -L --brief -- "${iso}")" || return 1
122
grep -Fq 'ISO 9660 CD-ROM filesystem data' <<< "${image_description}" || return 1
123
grep -Fq "'KDE LINUX ${pkgver}'" <<< "${image_description}" || return 1
124
grep -Fq '(bootable)' <<< "${image_description}" || return 1
125
126
printf '%s\n' 'check: GPT integrity and KDE Linux partition contract'
127
gpt_report="$(LC_ALL=C sgdisk -v "${iso}")" || return 1
128
grep -Fq 'No problems found.' <<< "${gpt_report}" || return 1
129
partition_count="$(LC_ALL=C sgdisk -p "${iso}" |
130
awk '/^[[:space:]]*[0-9]+[[:space:]]/ {count++} END {print count + 0}')" || return 1
131
[[ "${partition_count}" == '3' ]] || return 1
132
133
_check_partition "${iso}" 1 'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' 'esp'
134
_check_partition "${iso}" 2 '4F68BCE3-E8CD-4DB1-96E7-FBCAF984B709' 'KDELinuxLive'
135
_check_partition "${iso}" 3 '0FC63DAF-8483-4772-8E79-3D69D8477DE4' 'KDELinuxLiveExt'
136
137
esp_start="$(_partition_start "${iso}" 1)" || return 1
138
root_start="$(_partition_start "${iso}" 2)" || return 1
139
extension_start="$(_partition_start "${iso}" 3)" || return 1
140
141
printf '%s\n' 'check: EFI system partition and x86-64 bootloader'
142
mdir -i "${iso}@@$((esp_start * 512))" ::/EFI/BOOT/BOOTX64.EFI > /dev/null || return 1
143
rm -f -- "${esp_boot}"
144
mcopy -i "${iso}@@$((esp_start * 512))" ::/EFI/BOOT/BOOTX64.EFI "${esp_boot}" || return 1
145
file -L --brief -- "${esp_boot}" | grep -Fq 'PE32+ executable for EFI (application), x86-64' || return 1
146
147
printf '%s\n' 'check: EROFS system partitions'
148
for root_start in "${root_start}" "${extension_start}"; do
149
dd if="${iso}" of="${partition_head}" bs=512 skip="${root_start}" count=8192 status=none || return 1
150
file -L --brief -- "${partition_head}" | grep -Fq 'EROFS filesystem' || return 1
151
done
152
rm -f -- "${partition_head}" "${esp_boot}"
153
154
printf '%s\n' 'check: full ISO filesystem traversal'
155
7z t -bd -bb0 -- "${iso}" > /dev/null || return 1
156
}
157
158
package() {
159
_install_payload "${pkgdir}"
160
_check_payload "${pkgdir}" true
161
}
162
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-28 15:21:17 | Low | 1 |