netkeep

LOW
maintainer mohamadkhani 0 votes scanned 2026-10-06 00:19:23.678998
View on AUR
Why flagged

The PKGBUILD builds from the project's own GitHub source tarball with a real checksum; the only notable concern is that `cargo install bpf-linker` fetches a pinned crate from crates.io at build time, which is a normal Rust build pattern but does pull external code not covered by the source checksum — low risk overall as it's a well-known tool from the Rust ecosystem, and the package is otherwise straightforward.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 70%): The PKGBUILD builds from the project's own GitHub source tarball with a real checksum; the only notable concern is that `cargo install bpf-linker` fetches a pinned crate from crates.io at build time, which is a normal Rust build pattern but does pull external code not covered by the source checksum — low risk overall as it's a well-known tool from the Rust ecosystem, and the package is otherwise straightforward.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium External install via pipx/uv/poetry/cargo/go/gem alt_pkg_manager_install

A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:51 cargo install bpf-linker --version 0.10.4 --locked

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Mohammadreza Khani <mohamadkhani14@gmail.com>
2# This PKGBUILD is updated by CI on tagged releases (see packaging/arch/publish-aur.sh).
3# Hand-edits are fine but will be overwritten on the next tagged release.
4# Builds the whole workspace from the release tag tarball: eBPF objects first
5# (dns-tracker embeds them via include_bytes!), then the Rust binaries.
6# The prebuilt variant lives in packaging/arch/netkeep-bin/PKGBUILD.
7
8pkgname=netkeep
9pkgver=0.1.0
10pkgrel=1
11pkgdesc='Linux desktop network flow authorization (daemon, CLI, GPUI tray)'
12arch=('x86_64')
13url='https://github.com/mohamadkhani/netkeep'
14license=('GPL-3.0-or-later')
15depends=(
16 'gcc-libs'
17 'glibc'
18 'gtk-update-icon-cache'
19 'hicolor-icon-theme'
20 'libxkbcommon'
21 'libxcb'
22 'sqlite'
23 'xdotool'
24)
25optdepends=(
26 'vulkan-driver: GPU rendering for GPUI'
27 'systemd-resolved: disable stub listener if using NETKEEP_DNS_FORWARDER on port 53'
28)
29makedepends=(
30 'cargo'
31 'rust' # Arch rust ships rust-src, needed for -Z build-std=core
32 'git' # cargo fetches the gpui fork from GitHub
33 'clang'
34 'llvm'
35 'pkgconf'
36)
37options=('!lto' '!debug')
38
39source=("$pkgname-$pkgver.tar.gz::https://github.com/mohamadkhani/netkeep/archive/refs/tags/v${pkgver}.tar.gz")
40# Checksum is injected by CI from the real tag tarball (not SKIP).
41b2sums=('7e04f4df44e0138602dbd2e292ae0493681e0b0f2009b870d9283fa43d3f74eb5070a76e92688a084b4a64e39806b753570ba1e6a645fae59b0f0e5edf83f350')
42
43build() {
44 cd "$srcdir/$pkgname-$pkgver"
45
46 # Isolated CARGO_HOME for bpf-linker (0.11 regressed: rejects memset
47 # libcalls — pin 0.10.4, same as packaging/archlinux/PKGBUILD).
48 export CARGO_HOME="$srcdir/cargo-home"
49 mkdir -p "$CARGO_HOME"
50 export PATH="$CARGO_HOME/bin:$PATH"
51 cargo install bpf-linker --version 0.10.4 --locked
52
53 export CARGO_TARGET_DIR="$srcdir/$pkgname-$pkgver/target"
54 # eBPF first: xtask pins its own CARGO_TARGET_DIR for the bpfel objects
55 # (the include_bytes! paths in dns-tracker hardcode them). RUSTC_BOOTSTRAP=1
56 # unlocks -Z build-std=core on the stable toolchain.
57 RUSTC_BOOTSTRAP=1 cargo xtask build-ebpf-release
58 cargo build --workspace --release --locked
59}
60
61package() {
62 cd "$srcdir/$pkgname-$pkgver"
63
64 local target="$srcdir/$pkgname-$pkgver/target"
65 install -Dm755 "$target/release/netkeep-daemon" "$pkgdir/usr/bin/netkeepd"
66 install -Dm755 "$target/release/netkeep-cli" "$pkgdir/usr/bin/netkeep-cli"
67 install -Dm755 "$target/release/netkeep-gpui" "$pkgdir/usr/bin/netkeep-gpui"
68
69 install -Dm644 resources/linux/systemd/netkeepd.service \
70 "$pkgdir/usr/lib/systemd/system/netkeepd.service"
71 install -Dm644 resources/linux/applications/io.logicamp.Netkeep.desktop \
72 "$pkgdir/usr/share/applications/io.logicamp.Netkeep.desktop"
73 install -Dm644 resources/linux/icons/hicolor/scalable/apps/io.logicamp.Netkeep.svg \
74 "$pkgdir/usr/share/icons/hicolor/scalable/apps/io.logicamp.Netkeep.svg"
75 install -Dm644 packaging/archlinux/environment.d-netkeep.conf \
76 "$pkgdir/etc/environment.d/netkeep.conf"
77
78 install -Dm644 LICENSE \
79 "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
80}
81

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:19:23 Low 3
2026-10-06 00:13:36 Low 3
2026-10-05 23:40:58 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion