linux-libre-docs
linux-libre
scanned 2026-10-02 00:00:32.890515
The package builds Linux Libre from source hosted on its official project domain (linux-libre.fsfla.org), which is legitimate despite not being on a standard host whitelist; the downloaded content is source code and patches, not executables, and the build process is transparent and follows standard kernel compilation practices.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds Linux Libre from source hosted on its official project domain (linux-libre.fsfla.org), which is legitimate despite not being on a standard host whitelist; the downloaded content is source code and patches, not executables, and the build process is transparent and follows standard kernel compilation practices.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:42
source=("https://linux-libre.fsfla.org/pub/linux-libre/releases/${_basever}-gnu/linux-libre-${_basever}-gnu.tar.lz"{,.sign} -
PKGBUILD:44
'https://repo.parabola.nu/other/linux-libre/logos/logo_linux_'{clut224.ppm,vga16.ppm,mono.pbm}{,.sig})
PKGBUILD
2 offending line(s) highlighted# Maintainer : Daniel Bermond <dbermond@archlinux.org>
# Contributor: Jonas Heinrich <onny@project-insanity.org>
# Contributor: André Silva <emulatorman@riseup.net>
# Contributor: Márcio Silva <coadde@riseup.net>
# Contributor (Parabola): Nicolás Reynolds <fauno@kiwwwi.com.ar>
# Contributor (Parabola): Sorin-Mihai Vârgolici <smv@yobicore.org>
# Contributor (Parabola): Michał Masłowski <mtjm@mtjm.eu>
# Contributor (Parabola): Luke Shumaker <lukeshu@sbcglobal.net>
# Contributor (Parabola): Luke R. <g4jc@openmailbox.org>
pkgbase=linux-libre
pkgver=7.2.7
pkgrel=1
pkgdesc='Linux Libre'
url='https://linux-libre.fsfla.org/'
arch=(x86_64)
license=(GPL-2.0-only)
makedepends=(
bc
cpio
gettext
libelf
pahole
perl
python
rust
rust-bindgen
rust-src
tar
xz
# htmldocs
graphviz
imagemagick
python-sphinx
python-yaml
texlive-latexextra
)
options=('!debug' '!strip')
_basever="$({ grep -Eq '[0-9]\.[0-9]+\.[0-9]+' <<< "$pkgver" && printf '%s' "${pkgver%.*}"; } || printf '%s' "$pkgver")"
_srcname="linux-${_basever}"
source=("https://linux-libre.fsfla.org/pub/linux-libre/releases/${_basever}-gnu/linux-libre-${_basever}-gnu.tar.lz"{,.sign}
"https://linux-libre.fsfla.org/pub/linux-libre/releases/${pkgver}-gnu/patch-${_basever}-gnu-${pkgver}-gnu.bz2"{,.sign}
'https://repo.parabola.nu/other/linux-libre/logos/logo_linux_'{clut224.ppm,vga16.ppm,mono.pbm}{,.sig})
source_x86_64=('config.x86_64')
sha256sums=('235b6a5e23a8beadd6a35c28a92e59e04075cdbbdfa234ac84408706b8662638'
'SKIP'
'2e087c2bfa5f5a389df8ec24768ae6ceb34ba77e624eb5fb799720e845deffec'
'SKIP'
'bfd4a7f61febe63c880534dcb7c31c5b932dde6acf991810b41a939a93535494'
'SKIP'
'6de8a8319271809ffdb072b68d53d155eef12438e6d04ff06a5a4db82c34fa8a'
'SKIP'
'13bd7a8d9ed6b6bc971e4cd162262c5a20448a83796af39ce394d827b0e5de74'
'SKIP')
sha256sums_x86_64=('44dcf7f2f45cc69423e85f0079acf60216cc4af5068a5e5cd1fb0782c108d78b')
b2sums=('2009ed4bec5643a4166790cf98cee098fc092732c41b8e8f356c02b0addb5a35300bdc0f5db9cbd2f96b45100653b3f18bc299f6b1d5524d5b15347efa57ff43'
'SKIP'
'9b108543d67b8c1e0651d57dadaf7671c013b3afbbcb8f545911dc8854f2343d3d4417c7e7e55a9e0c0ddeb68c66b8230e29861dc3171b9f4f346b4e9a470883'
'SKIP'
'73fee2ae5cb1ffd3e6584e56da86a8b1ff6c713aae54d77c0dab113890fc673dc5f300eb9ed93fb367b045ece8fa80304ff277fe61665eccf7b7ce24f0c045eb'
'SKIP'
'd02a1153a4285b32c774dca4560fe37907ccf30b8e487a681b717ed95ae9bed5988875c0a118938e5885ae9d2857e53a6f216b732b6fa3368e3c5fe08c86382c'
'SKIP'
'580911af9431c066bbc072fd22d5e2ef65f12d8358cec5ff5a4f1b7deebb86cef6b5c1ad631f42350af72c51d44d2093c71f761234fb224a8b9dbb3b64b8201d'
'SKIP')
b2sums_x86_64=('38da8371c1c6f236a9f3b2431801e3c8060d2e83dcda68f0b1383e156cf4f474533c90a582155846419ffb6761a9a7afb483fa42625800b3006d26949dac748a')
validpgpkeys=('474402C8C582DAFBE389C427BCB7CF877E7D47A7' # Alexandre Oliva
'6DB9C4B4F0D8C0DC432CF6E4227CA7C556B2BA78') # David P.
export KBUILD_BUILD_HOST=archlinux
export KBUILD_BUILD_USER=$pkgbase
export KBUILD_BUILD_TIMESTAMP="$(date -Ru${SOURCE_DATE_EPOCH:+d @$SOURCE_DATE_EPOCH})"
prepare() {
cd "$_srcname"
# freedo boot logo
install -m644 -t drivers/video/logo ../logo_linux_{clut224.ppm,vga16.ppm,mono.pbm}
echo "Setting version..."
echo "-$pkgrel" > localversion.10-pkgrel
echo "${pkgbase#linux}" > localversion.20-pkgname
sed -i 's|^-libre||' localversion.20-pkgname # minimize diff
local _src
for _src in "${source[@]}"
do
_src="${_src%%::*}"
_src="${_src##*/}"
_src="${_src%*.bz2}"
[[ "$_src" = *.patch ]] || { [[ "$_src" = patch-* ]] && [[ "$_src" != *.sign ]]; } || continue
echo "Applying patch $_src..."
patch -Np1 < "../$_src"
done
echo "Setting config..."
cp "../config.${CARCH}" .config
make olddefconfig
diff -u "../config.${CARCH}" .config || :
make -s kernelrelease > version
echo "Prepared $pkgbase version $(<version)"
}
build() {
make -C "$_srcname" htmldocs SPHINXOPTS='-QT' all
make -C "${_srcname}/tools/bpf/bpftool" vmlinux.h feature-clang-bpf-co-re='1'
}
_package() {
pkgdesc="The $pkgdesc kernel and modules"
depends=(
coreutils
initramfs
kmod
)
optdepends=(
"${pkgbase}-headers: headers and scripts for building modules"
'linux-firmware: firmware images needed for some devices'
'scx-scheds: to use sched-ext schedulers'
'wireless-regdb: to set the correct wireless channels of your country'
)
provides=(
KSMBD-MODULE
NTSYNC-MODULE
VIRTUALBOX-GUEST-MODULES
WIREGUARD-MODULE
)
replaces=(
virtualbox-guest-modules-arch
wireguard-arch
)
cd "$_srcname"
local _modulesdir="$pkgdir/usr/lib/modules/$(<version)"
echo "Installing boot image..."
# systemd expects to find the kernel here to allow hibernation
# https://github.com/systemd/systemd/commit/edda44605f06a41fb86b7ab8128dcf99161d2344
install -Dm644 "$(make -s image_name)" "$_modulesdir/vmlinuz"
# Used by mkinitcpio to name the kernel
echo "$pkgbase" | install -Dm644 /dev/stdin "$_modulesdir/pkgbase"
echo "Installing modules..."
ZSTD_CLEVEL=19 make INSTALL_MOD_PATH="$pkgdir/usr" INSTALL_MOD_STRIP=1 \
DEPMOD=/doesnt/exist modules_install # Suppress depmod
# remove build link
rm "$_modulesdir"/build
}
_package-headers() {
pkgdesc="Headers and scripts for building modules for the $pkgdesc kernel"
depends=(pahole)
provides=(LINUX-HEADERS)
cd "$_srcname"
local _builddir="$pkgdir/usr/lib/modules/$(<version)/build"
local _karch
case "$CARCH" in
x86_64) _karch='x86' ;;
*) echo "Unknown CARCH ${CARCH}"; exit 1 ;;
esac
echo "Installing build files..."
install -Dt "$_builddir" -m644 .config Makefile Module.symvers System.map \
localversion.* version vmlinux tools/bpf/bpftool/vmlinux.h
install -Dt "$_builddir/kernel" -m644 kernel/Makefile
install -Dt "$_builddir/arch/${_karch}" -m644 "arch/${_karch}/Makefile"
cp -t "$_builddir" -a scripts
ln -srt "$_builddir" "$_builddir/scripts/gdb/vmlinux-gdb.py"
if [[ "$(scripts/config -s CONFIG_HAVE_STACK_VALIDATION)" = 'y' ]]; then
install -Dt "${_builddir}/tools/objtool" tools/objtool/objtool
fi
if [[ "$(scripts/config -s CONFIG_DEBUG_INFO_BTF_MODULES)" = 'y' ]]; then
install -Dt "${_builddir}/tools/bpf/resolve_btfids" tools/bpf/resolve_btfids/resolve_btfids
fi
echo "Installing headers..."
cp -t "$_builddir" -a include
cp -t "$_builddir/arch/${_karch}" -a "arch/${_karch}/include"
install -Dt "$_builddir/arch/${_karch}/kernel" -m644 "arch/${_karch}/kernel/asm-offsets.s"
install -Dt "$_builddir/drivers/md" -m644 drivers/md/*.h
install -Dt "$_builddir/net/mac80211" -m644 net/mac80211/*.h
# https://bugs.archlinux.org/task/13146
install -Dt "$_builddir/drivers/media/i2c" -m644 drivers/media/i2c/msp3400-driver.h
# https://bugs.archlinux.org/task/20402
install -Dt "$_builddir/drivers/media/usb/dvb-usb" -m644 drivers/media/usb/dvb-usb/*.h
install -Dt "$_builddir/drivers/media/dvb-frontends" -m644 drivers/media/dvb-frontends/*.h
install -Dt "$_builddir/drivers/media/tuners" -m644 drivers/media/tuners/*.h
# https://bugs.archlinux.org/task/71392
install -Dt "$_builddir/drivers/iio/common/hid-sensors" -m644 drivers/iio/common/hid-sensors/*.h
echo "Installing KConfig files..."
find . -name 'Kconfig*' -exec install -Dm644 {} "$_builddir/{}" \;
echo "Installing Rust files..."
if [[ "$(scripts/config -s CONFIG_RUST)" = 'y' ]]; then
install -Dt "${_builddir}/rust" -m644 rust/*.rmeta
install -Dt "${_builddir}/rust" rust/*.so
fi
echo "Installing unstripped VDSO..."
make INSTALL_MOD_PATH="${pkgdir}/usr" vdso_install \
link= # Suppress build-id symlinks
echo "Removing unneeded architectures..."
local arch
for arch in "$_builddir"/arch/*/; do
[[ $arch = */"${_karch}/" ]] && continue
echo "Removing $(basename "$arch")"
rm -r "$arch"
done
echo "Removing documentation..."
rm -r "$_builddir/Documentation"
echo "Removing broken symlinks..."
find -L "$_builddir" -type l -printf 'Removing %P\n' -delete
echo "Removing loose objects..."
find "$_builddir" -type f -name '*.o' -printf 'Removing %P\n' -delete
echo "Stripping build tools..."
local file
while read -rd '' file; do
case "$(file -Sib "$file")" in
application/x-sharedlib\;*) # Libraries (.so)
strip -v $STRIP_SHARED "$file" ;;
application/x-archive\;*) # Libraries (.a)
strip -v $STRIP_STATIC "$file" ;;
application/x-executable\;*) # Binaries
strip -v $STRIP_BINARIES "$file" ;;
application/x-pie-executable\;*) # Relocatable binaries
strip -v $STRIP_SHARED "$file" ;;
esac
done < <(find "$_builddir" -type f -perm -u+x ! -name vmlinux -print0)
echo "Stripping vmlinux..."
strip -v $STRIP_STATIC "$_builddir/vmlinux"
echo "Adding symlink..."
mkdir -p "$pkgdir/usr/src"
ln -sr "$_builddir" "$pkgdir/usr/src/$pkgbase"
}
_package-docs() {
pkgdesc="Documentation for the $pkgdesc kernel"
cd "$_srcname"
local _builddir="$pkgdir/usr/lib/modules/$(<version)/build"
echo "Installing documentation..."
local src dst
while read -rd '' src; do
dst="${src#Documentation/}"
dst="$_builddir/Documentation/${dst#output/}"
install -Dm644 "$src" "$dst"
done < <(find Documentation -name '.*' -prune -o ! -type d -print0)
echo "Adding symlink..."
mkdir -p "$pkgdir/usr/share/doc"
ln -sr "$_builddir/Documentation" "$pkgdir/usr/share/doc/$pkgbase"
}
pkgname=(
"$pkgbase"
"$pkgbase-headers"
"$pkgbase-docs"
)
for _p in "${pkgname[@]}"; do
eval "package_$_p() {
$(declare -f "_package${_p#$pkgbase}")
_package${_p#$pkgbase}
}"
done
Changes since previous scan
--- PKGBUILD @ 2026-09-26 00:12+++ PKGBUILD @ 2026-10-02 00:00@@ -9,7 +9,7 @@ # Contributor (Parabola): Luke R. <g4jc@openmailbox.org> pkgbase=linux-libre-pkgver=7.2.6+pkgver=7.2.7 pkgrel=1 pkgdesc='Linux Libre' url='https://linux-libre.fsfla.org/'@@ -45,7 +45,7 @@ source_x86_64=('config.x86_64') sha256sums=('235b6a5e23a8beadd6a35c28a92e59e04075cdbbdfa234ac84408706b8662638' 'SKIP'- '7439a0ecffa8633265a1df083781adddb99dcc657cebcffee88f033b7ee1653d'+ '2e087c2bfa5f5a389df8ec24768ae6ceb34ba77e624eb5fb799720e845deffec' 'SKIP' 'bfd4a7f61febe63c880534dcb7c31c5b932dde6acf991810b41a939a93535494' 'SKIP'@@ -53,10 +53,10 @@ 'SKIP' '13bd7a8d9ed6b6bc971e4cd162262c5a20448a83796af39ce394d827b0e5de74' 'SKIP')-sha256sums_x86_64=('290990d223b96346bd5d8e049552d7601d2dd6257fc8c647bf15775e215d9f66')+sha256sums_x86_64=('44dcf7f2f45cc69423e85f0079acf60216cc4af5068a5e5cd1fb0782c108d78b') b2sums=('2009ed4bec5643a4166790cf98cee098fc092732c41b8e8f356c02b0addb5a35300bdc0f5db9cbd2f96b45100653b3f18bc299f6b1d5524d5b15347efa57ff43' 'SKIP'- '573c84c78c13291a81e9f9824e93bb8544b3f3dd892e6248280cae77882605b1c4fc991d0d486e64c147c4dd551c35f691d10c0130623304a585973d36abb9c0'+ '9b108543d67b8c1e0651d57dadaf7671c013b3afbbcb8f545911dc8854f2343d3d4417c7e7e55a9e0c0ddeb68c66b8230e29861dc3171b9f4f346b4e9a470883' 'SKIP' '73fee2ae5cb1ffd3e6584e56da86a8b1ff6c713aae54d77c0dab113890fc673dc5f300eb9ed93fb367b045ece8fa80304ff277fe61665eccf7b7ce24f0c045eb' 'SKIP'@@ -64,7 +64,7 @@ 'SKIP' '580911af9431c066bbc072fd22d5e2ef65f12d8358cec5ff5a4f1b7deebb86cef6b5c1ad631f42350af72c51d44d2093c71f761234fb224a8b9dbb3b64b8201d' 'SKIP')-b2sums_x86_64=('c036e526b7ee522888525aad79590e2c658db4048e76711f28d7d57c2f3fe21dfc603afabbdfa42aca52885e55f6abdf6efae6611eb2ffa8a998d7c091f8f48a')+b2sums_x86_64=('38da8371c1c6f236a9f3b2431801e3c8060d2e83dcda68f0b1383e156cf4f474533c90a582155846419ffb6761a9a7afb483fa42625800b3006d26949dac748a') validpgpkeys=('474402C8C582DAFBE389C427BCB7CF877E7D47A7' # Alexandre Oliva '6DB9C4B4F0D8C0DC432CF6E4227CA7C556B2BA78') # David P. Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 01:13:50 | Medium | 1 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 15:30:39 | Medium | 1 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |