oceanus-bin

LOW
maintainer cmach_socket 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package installs a prebuilt binary from the project's official GitHub release, which is a normal practice for Flutter apps; the only risk is reliance on an unverifiable binary, but it comes from the legitimate upstream source and no malicious behavior is present.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package installs a prebuilt binary from the project's official GitHub release, which is a normal practice for Flutter apps; the only risk is reliance on an unverifiable binary, but it comes from the legitimate upstream source and no malicious behavior is present.

PKGBUILD

1# Maintainer: cmach_socket <solaris@cmach.top>
2
3pkgname=oceanus-bin
4_pkgname=${pkgname%-bin}
5pkgver="1.3.7"
6pkgrel=1
7pkgdesc="一个 Flutter 网易云音乐客户端"
8arch=('x86_64')
9url='https://github.com/cmachsocket/oceanus'
10license=('GPL-3.0-or-later')
11
12# ---------------------------------------------------------------------------
13# Layout note (upstream-fixed /opt/oceanus/):
14# The upstream .deb ships ELF files under opt/oceanus/ and a
15# /usr/bin/oceanus -> /opt/oceanus/oceanus symlink, which the .desktop
16# Exec= line relies on. Relocating the tree to /usr/lib/oceanus would
17# diverge from upstream packaging and force re-patching every DT_NEEDED
18# string in the Flutter binaries; we therefore preserve the Debian layout.
19# namcap flags this as 'ELF files outside of a valid path'; this is
20# intentional and required for the bundled libs to resolve each other.
21# ---------------------------------------------------------------------------
22
23depends=(
24 # Explicitly required by the app / its bundled plugins:
25 'gtk3' # bundled libflutter_linux_gtk.so + GTK UI
26 'mpv' # libapp.so dlopen()s libmpv.so.{1,2} via media_kit
27 'nodejs' # DesktopNcmBridge spawns 'node' to run
28 # flutter_assets/.../bundle.js (ncm_api_enhanced)
29 'gcc-libs' # libstdc++.so.6, libgcc_s.so.1 pulled in transitively
30
31 # Explicitly listing what namcap would otherwise flag as "implicitly
32 # satisfied" (the linked libs are hard NEEDED in the Flutter binaries):
33 'glib2' # libglib-2.0.so.0, libgobject-2.0.so.0, libgio-2.0.so.0
34 'gdk-pixbuf2' # libgdk_pixbuf-2.0.so.0
35 'zlib' # libz.so.1
36 'harfbuzz' # libharfbuzz.so.0
37 'fontconfig' # libfontconfig.so.1 (libflutter_linux_gtk.so)
38 'pango' # libpango-1.0.so.0, libpangocairo-1.0.so.0
39 'at-spi2-core' # libatk-1.0.so.0
40 'cairo' # libcairo.so.2, libcairo-gobject.so.2
41 'libepoxy' # libepoxy.so.0 (libflutter_linux_gtk.so)
42 'hicolor-icon-theme' # we ship usr/share/icons/hicolor/512x512/apps/oceanus.png
43 'dbus' # libdbus-1.so.3 (StatusNotifierItem + MPRIS)
44)
45optdepends=(
46 'gnome-shell-extension-appindicator: show the tray icon on GNOME'
47)
48makedepends=('patchelf')
49options=('strip' 'debug')
50
51provides=("${_pkgname}")
52conflicts=("${_pkgname}")
53
54source=(
55 "${_pkgname}_${pkgver}+1_amd64.deb::https://github.com/cmachsocket/oceanus/releases/download/v${pkgver}/oceanus_${pkgver}+1_amd64.deb"
56 # GPL-3.0-or-later text from the SPDX license list (not bundled in the
57 # upstream .deb; we ship it ourselves to satisfy /usr/share/licenses).
58 'GPL-3.0-or-later.txt::https://raw.githubusercontent.com/spdx/license-list-data/main/text/GPL-3.0-or-later.txt'
59)
60sha512sums=('ddd3cf3a4e00803526685a9dbf02dcb024f87fd6db686055b366c5258baeee22d7e559fad9b13b91f3b4d764cf8b1c067e5ba1fd3c56df609b4fd0912e40e2b3'
61 '165f8007d3397e1fd4c30a42039122c3ed8f9f5d45274d682f4707fadb093ab7a8f9336724db6eb7653acb9cee42d39fd98fb72811afce635af03a9f2ef66181')
62
63# ---------------------------------------------------------------------------
64# Known upstream issues that namcap reports but cannot be fixed without
65# rebuilding from source (kept here for review transparency):
66#
67# * "ELF file lacks FULL RELRO" on libapp.so, libdartjni.so,
68# libmedia_kit_libs_linux_plugin.so, and the oceanus binary itself.
69# Upstream Flutter Linux release artefacts do not enable -z now/-z relro.
70#
71# * Many "Unused shared library" warnings (libdl, libpthread, libgtk-3,
72# libgdk-3, libstdc++, libm, ...). These are false positives: Flutter's
73# engine and the media_kit plugin dlopen()/load lazily, which namcap's
74# static DT_NEEDED walker does not see.
75#
76# * checkpkg: 'target not found: oceanus-bin'. Expected on first AUR
77# submission; there is no previous version to diff against.
78# ---------------------------------------------------------------------------
79
80package() {
81 local _debdir="${srcdir}/deb-extract"
82 local _datadir="${srcdir}/deb-data"
83 local _data_archive
84
85 rm -rf "${_debdir}" "${_datadir}"
86 mkdir -p "${_debdir}" "${_datadir}"
87
88 cd "${_debdir}"
89 ar x "${srcdir}/${_pkgname}_${pkgver}+1_amd64.deb"
90
91 _data_archive=$(printf '%s\n' data.tar.*)
92 bsdtar -xf "${_data_archive}" -C "${_datadir}"
93
94 cp -a "${_datadir}/." "${pkgdir}/"
95
96 # Strip the insecure RUNPATH that leaked from the upstream CI runner
97 # build directory (/home/runner/work/...). The plugins do not need any
98 # rpath because their NEEDED entries (libflutter_linux_gtk.so etc.) are
99 # colocated in the same directory and resolved via the main executable's
100 # $ORIGIN/lib RUNPATH at dlopen() time.
101 #
102 # Note: apply this to every bundled ELF, not just the media_kit plugin --
103 # libwindow_manager_plugin.so and libscreen_retriever_linux_plugin.so
104 # carry the same leaked CI path.
105 local _elf
106 while IFS= read -r -d '' _elf; do
107 case "$(patchelf --print-rpath "${_elf}" 2>/dev/null)" in
108 /home/runner/*) patchelf --remove-rpath "${_elf}" ;;
109 esac
110 done < <(find "${pkgdir}/opt/oceanus" -type f \
111 \( -name 'oceanus' -o -name '*.so' \) -print0)
112
113 # Ship the actual GPL-3.0-or-later text. The upstream .deb only carries
114 # a symlink to /usr/share/licenses/common/GPL-3, which is a Debian-ism
115 # and does not exist on Arch.
116 install -Dm644 \
117 "${srcdir}/GPL-3.0-or-later.txt" \
118 "${pkgdir}/usr/share/licenses/${pkgname}/LICENSE"
119}
120

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 23:40:58 Low 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion