mips-harvard-os161-gcc48

LOW
maintainer gerito 1 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The source is a tarball from the official project domain (os161.eecs.harvard.edu) used to build a cross-compiler for an academic course;虽 host not whitelisted, it is plausibly official, and building from source is normal AUR practice.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a tarball from the official project domain (os161.eecs.harvard.edu) used to build a cross-compiler for an academic course;虽 host not whitelisted, it is plausibly official, and building from source is normal AUR practice.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:18 source=(http://os161.eecs.harvard.edu/download/gcc-${_pkgver}.tar.gz

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Geronimo Bareiro <gero dot bare at gmail dot com>
2
3_target="mips-harvard-os161"
4pkgname=${_target}-gcc48
5_pkgver=4.8.3+os161-2.1
6pkgver=${_pkgver/os161-/os161_}
7pkgrel=1
8pkgdesc="The GNU Compiler Collection - cross compiler for ${_target} arquitecture. This is part of toolset for the course os161 from Harvard."
9arch=(i686 x86_64)
10url="http://os161.eecs.harvard.edu/"
11license=('GPL' 'LGPL')
12groups=('mips-harvard-os161-toolchain')
13depends=('mips-harvard-os161-binutils>=2.24' 'gmp' 'mpfr' 'libmpc')
14makedepends=('flex' 'bison')
15provides=('mips-harvard-os161-gcc')
16conflicts=('mips-harvard-os161-gcc')
17options=(staticlibs !libtool !emptydirs !strip zipman docs)
18source=(http://os161.eecs.harvard.edu/download/gcc-${_pkgver}.tar.gz
19gcc.patch)
20md5sums=('a81f7f6fdfa319723efaf444088fd6d7'
21'SKIP')
22
23prepare() {
24 cd gcc-${_pkgver}
25
26 patch -p1 -i ${srcdir}/gcc.patch
27 mkdir ${srcdir}/gcc-build
28}
29
30build() {
31 cd gcc-build
32
33 export CFLAGS="-O2"
34 export CXXFLAGS="-O2"
35 unset CPPFLAGS
36
37 ../gcc-${_pkgver}/configure --prefix=/usr \
38 --program-prefix=${_target}- \
39 --with-local-prefix=/usr/lib/${_target} \
40 --target=${_target} --host=${CHOST} --build=${CHOST} \
41 --with-build-sysroot=/usr/${_target} \
42 --with-as=/usr/bin/${_target}-as \
43 --with-ld=/usr/bin/${_target}-ld \
44 --enable-languages=c,lto \
45 --disable-nls --nfp \
46 --disable-shared --disable-threads \
47 --disable-libmudflap --disable-libssp \
48 --disable-libstdcxx \
49 --disable-werror
50
51 make
52}
53
54package() {
55 cd ${srcdir}/gcc-build
56 make prefix=${pkgdir}/usr tooldir=${pkgdir}/usr install
57
58 # Delete the things we don't need
59 rm -rf ${pkgdir}/usr/share
60 # libiberty.a conflicts with host version
61 rm -f $pkgdir/usr/lib/libiberty.a
62}
63
64# vim: set ts=2 sw=2 ft=sh et:
65

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 00:16:27 Low 2
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2
2026-08-31 00:19:57 Low 2
2026-08-30 00:04:14 Low 2
2026-08-29 00:29:17 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion