openssh-hpn-shim

maintainer zer0def · 15 votes · base openssh-hpn · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is from the well-known HPN-SSH project (rapier1/hpn-ssh on GitHub), which is a legitimate, long-standing performance-patched fork of OpenSSH maintained by Pittsburgh Supercomputing Center researchers. The PKGBUILD itself is transparent about what it does and even includes an explicit security warning to users. The fork is a real, publicly auditable project — not an obscure personal repo. The secondary source from eworm.de is a patch file (data, not a binary). All sources have sha512, b2, and b3 checksums. The risk here is purely operational (using a fork instead of upstream OpenSSH may lag on security fixes), not a supply-chain attack. The cheaper model's MEDIUM rating is a false positive; this is a legitimate, well-documented packaging choice with appropriate user warnings.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 85%): The source is from the well-known HPN-SSH project (rapier1/hpn-ssh on GitHub), which is a legitimate, long-standing performance-patched fork of OpenSSH maintained by Pittsburgh Supercomputing Center researchers. The PKGBUILD itself is transparent about what it does and even includes an explicit security warning to users. The fork is a real, publicly auditable project — not an obscure personal repo. The secondary source from eworm.de is a patch file (data, not a binary). All sources have sha512, b2, and b3 checksums. The risk here is purely operational (using a fork instead of upstream OpenSSH may lag on security fixes), not a supply-chain attack. The cheaper model's MEDIUM rating is a false positive; this is a legitimate, well-documented packaging choice with appropriate user warnings.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:66 'http://www.eworm.de/download/linux/openssh-tests-scp.patch'

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: zer0def <zer0def@libera>
2# Maintainer: Björn Wiedenmann <archlinux cat xorxor dog de>
3# Contributor: Jonathan Yantis <yantis cat yantis dog net>
4# Contributor: Christian Hesse <mail cat eworm dog de>
5# Contributor: Gaetan Bisson <bisson cat archlinux dog org>
6# Contributor: Caspar Verhey <caspar at verhey dot net>
7# Contributor: Seth Fulton <seth cat sysfu dog com>
8# Contributor: Aaron Griffin <aaron cat archlinux dog org>
9# Contributor: judd <jvinet cat zeroflux dog org>
10# Contributor: benetnash <benetnash cat mail dog icpnet dog pl>
11# Contributor: Thomas Haider <t.haider cat vcnc dog org>
12
13# Note: The bulk of this PKGBUILD is based off:
14# https://aur.archlinux.org/packages/op/openssh-git/PKGBUILD
15# https://aur.archlinux.org/packages/op/openssh-hpn/PKGBUILD
16
17# IMPORTANT SECURITY NOTE:
18# This PKGBUILD does NOT (!!!) follow the upstream
19# OpenSSH-Portable distribution (at
20# https://github.com/openssh/openssh-portable ) but rather a
21# fork which is maintained by rapier (primarily for Gentoo
22# Linux I believe). The fork includes the HPN patches and can be
23# found at https://github.com/rapier1/openssh-portable
24#
25# Since I do NOT maintain this fork in any way, but merely
26# package it for Arch Linux, there is absolutely no warranty for
27# this code. It is very possible that the current version of the
28# fork still contains open security bugs which have already been
29# fixed in upstream OpenSSH.
30#
31# USE THIS PKGBUILD AT YOUR OWN RISK AND ONLY IF YOU FULLY
32# UNDERSTAND THE SECURITY IMPLICATIONS OF NOT USING THE MOST
33# RECENT OFFICIAL OPENSSH !
34#
35# Consider yourself warned.
36#
37# If security is paramount for you or in case of any doubt,
38# please use the official OpenSSH distribution instead.
39
40# This package should probably follow chutzpah@gentoo's patches in the future
41
42pkgbase=openssh-hpn
43pkgname=(
44 openssh-hpn
45 openssh-hpn-shim
46)
47#git_rev="ab9495715b35116df3ee123d2d0f84013f79ca84" # 9.3p2-hpn17v14
48openssh_rev="V_10_3_P1";
49_openssh_rev="${openssh_rev//V_/}"; _openssh_rev="${_openssh_rev//_P/p}";
50git_rev="hpn-18.9.0"
51pkgver=10.3p1_hpn18.9.0
52pkgrel=1
53pkgdesc='A Secure SHell server/client fork with High Performance patches included'
54url='https://www.psc.edu/index.php/hpn-ssh/'
55license=('BSD-2-Clause' 'BSD-3-Clause' 'ISC' 'MIT')
56arch=('x86_64' 'i486' 'i686' 'arm' 'armv6h' 'armv7h' 'aarch64')
57depends=('krb5' 'ldns' 'libedit' 'openssl')
58makedepends=('git' 'libfido2')
59optdepends=('xorg-xauth: X11 forwarding'
60 'x11-ssh-askpass: input passphrase in X'
61 'libfido2: FIDO/U2F support')
62conflicts=('openssh-hpn-git')
63source=(
64 "https://github.com/rapier1/hpn-ssh/archive/${git_rev}.tar.gz"
65 "hpn-revert-default-port-2222.patch"
66 'http://www.eworm.de/download/linux/openssh-tests-scp.patch'
67 #'openssl11.patch'
68 #'hpn-banner.patch'
69 'glibc-2.31.patch'
70 #'hpn14v22-globals-cleanup.patch'
71 'hpnsshdgenkeys.service'
72 'hpnsshd.service'
73 'hpnssh-agent.service'
74 'sshdgenkeys.service'
75 'sshd.service'
76 'ssh-agent.service'
77
78 'sshd.pam'
79 'sshd.conf'
80)
81
82sha512sums=(
83 'd8474e4c9a3341c8c10352316f29356f5741e549b0b4792d4ef204192f7c1151b18d9d24103453469e86cf54fff4f2863e5e04f75d8cd8ce72b643eb1416902d'
84 '4e4cff34a096e6966f92341c14b2283d726268f76172d6265d077278b93094e598eca5f1e8c2bc806f54048840e5c48f532d2dfc12fd3c9c4ce1c169648c80da'
85 '62e2d60fdd39243e6245d90a0940b67ac4e72d042d8146203d50cdaa2df51611d91831d3b152d42302490afd677ae3433a3eba975dee68dbf7c06728167bb6d4'
86 #'5d96a288ae925584cdcde0305c511b18e3cfaed6cae49f5fc6f062f62100d10a087144e8263380d19a14dca71c745065ddaa0062542c2e2cfa1db04811d40dc7'
87 #'a9ee92fd135c47a27ac260ab40c057f0e35c118efcb281e98e235158ffd8599acede67dcce6da4c2589b2a0bd794c587af80d4ce4f85c1b9823cb9acfbbe9050'
88 'aeee097dbf46aa22f411d78a49b9db7b2451dd0351bb5f57c7b3159c7ddc29aa994cd43046c187033c474f8fb2952165536197139eb7c495db99f6697f41637d'
89 #'beaa201496c1c670f5fe1e99b88308fff16502ed5ac0d6dce3077be9ea44f6e30d5cd0946e5bf5f11c4b174f9afe372fa198c8ef278f5c5511aa2410d3441ec2'
90 '6438c063d8785babb33e18ee082ea96168a56a4e02099b521015dfc764d3411b97d911e0cc577cdb9ac7a572e8cf0b86a9d4fa1e3c83166055690fa3f551dc7d'
91 '3abe76d3ed971f4ef69013732f5be4cdfb8de0a12705b5d7190907a543c6d044bf064ff637f4511e4d95fbab58066ede8d0cce996d1adb1c2ec917be980f228a'
92 'c773ed58c986982416923228f6a3325c90f130ff8e79ebf6bfd6e28c00bd34b7a22add828b46b5577979435bb0d68f3cb3611ce6a1986215d07dae8246a78cf5'
93 '2eec0760fb680ea0c1967e1560b9b16579a0b6fa3b1b1579188ceb8b02ec12ecc5d763b51ca694f2392cdd6a468b212c58cac0541f92ae51f26f2f19988c315b'
94 'aaa3f0e9ee686b7208ef94e373007a57e5f62020339399d6abbbeba276acedb1868d62c0401c901fd021f9287b263347b699c0d4b65f503fa57bafef5f4b8829'
95 '1f1384d527a34ad2eaae604e93f5874c4df58a95505e8108df09fadfb8e67f90676845644eee73394981fd0dc8e888b78ac2caf761abea16be8213297ae62088'
96 '7000f06ac19e87c48ba95d19c76a298d9532f3c9d706537a58382d4f70cfc8f9163156bf5b112e46a1f414d5bf0df26aab9b22c330d9c65ee52affe6488f130a'
97 '838252ca7bfa69797cba8e31340321ece06a58428b47002cb835678d8e29c6f23f6521269a2b5b17820860a56df308185bc651484db24327cc58191e5f83222a'
98)
99
100b2sums=(
101 '9d5af14a49ef1603aefccaa193a078833fc93eb2a34a3b2be80a580e35adca8e5ff889c02049113d3e5a75058c40475554c63e4d901a5a2f93d77f03cd5bf4e7'
102 '61f29a5fe568e1e3c1d0b4b122f16943b2cd5f27eecc855d07d40b7f91100c73a93f310c37668d8147985618e4390040d7915455921863e18cc87ba92219d1e8'
103 '1e6c8d39052bdc268c584488341e260a2695d4b9afabca41919710bb34833dd580ff1813c01b8ba91f2629273c8101ce0ed3b2749dabce054137b4ef37b2a548'
104 #'051b7c350333ce57a4a5e57ba0f693aed4491a241fd9e65cf2a861773571b44b8d4ffa06506a0c4a05399a46108ec05321e69f210637f32e25c76e683b224505'
105 #'b46019363a19e2a0c397d66b6f1dc24d1c1219372b7fd699d92a9c382b24b02437b37cb12b3bba7e3ca97cfe98170ad21fff5871daf2070bc3d175fe0b31680b'
106 'a6ff4e82a92e7dba08f0e6c14ad1d280ad2dbc1d5ebdc7dc70eaa1b7963ddd5d5491fdf4c83cde1bec183b335ed20edaf101ac8bdb3c0f480adc72d41251723b'
107 #'74fc72fe0f028e7b495b2a96df26ef9fd76648f2701bbfc2b271f5b55968b82951f1b7232435c2bdf9e92b74a69f0d8cf804c8ef1be7f9c226896cb17ba57166'
108 'e6c672505b37fe915a4dd2f5a1503b8be88a124aed22cc736cccbc88573b23eba36e7702136b009c6209c1079f4520e4ee1233fa8a2bbb82f2ea1d8be388ea1f'
109 '211234dd60995873e00952c29fcb77ee6f1e9519fda5abce0b1f3a26193f580ad0c948482fcc66769abf55e347f95a6e4ba2dde98257e6ddb97b6a18550aff5b'
110 'e61b11024ccb8fdf89dba2a6e62b19657f433d9fd324b0f3048a3bc8042a9b7756a602fae1d661d15d9e12bd5659bfbcff264ec06eb811b5221c47930a16eb93'
111 'f3cd6d8bf7a0861f2c70de9cd52619bd6777b67943b3dd84eb9f87ab95734bbc653f68aa4b9ee5ab353524c5621d06016fd5af7ee42e21c81c89bb68d5d8cf1f'
112 '0b2ec199c7d772d4cfa6db12a653963727b01efea764fe364bb9138c983c56d1a33cc5e002b7edfeff957118d162e0c53c8d1b038a2f643bca38821b0ee8c3f6'
113 'dc5f22dab6fe8ba68d2c71808195fdcaec6f5b4dc54da0a81eef688df64378b556f7cde47dcc4f6d735cc82e54f527f2011ae522445f094f3527d96fd4a4f730'
114 'a61b50849a4efe66b3341fd312531dde54917cf138ddb458973632de7ff815dddeeff432ff84fb0d63d94a46a331b6bb736ae0e260f8cc7f82beb3c0a9c0d602'
115 '27571f728c3c10834a81652f3917188436474b588f8b047462e44b6c7a424f60d06ce8cb74839b691870177d7261592207d7f35d4ae6c79af87d6a7ea156d395'
116)
117
118b3sums=(
119 'af515f2de581f36fc10127ebd80f4456587730639cb6c9b37953669c29ce028e'
120 '4d3b697b24197c5ca50d8f251ca6cd1f8737f6d85689f343358f3d5b4fe28eb0'
121 'db9e75e396c8f45aacb0e14003aabdcf29b812e468a5a40b371957ffe9c7f52f'
122 #'145f9d17920d7b3b1ef935e3a735171ac9783cbd94ee47eec86f3fb96a6a34c6'
123 #'86f8ba9e3469c86c2ced236240d9ba9a253d82b8b6732d8592db481d984de258'
124 'f76459d09d1cfd92acc212ae1d4fee73b31ab795ff605c8717b3ee0a6fa9dcf9'
125 #'bb4b93c1ffa13df6d5d5441646cd6acb49464d5512ee8f36a7bc0e6f5097edb4'
126 'e19a65db3153fad5b7ce20d7316d7207c90303e15e54dc9ea0e1a8255c53b134'
127 '7f766a97ab867f1f7c5c2fc2770c0d7c7831a6422dfbc89e47f69d4d786a233f'
128 'ea689aadd712e06e202c6543ca3b8370de54788b0be4bb0c9184b2cd3f6c73da'
129 '55f5587e33dc8328f1c406224d6e61e479b7ec93a5b5bfc155af073d3e23f309'
130 'f03929c8964f2df4f4768745322a4c53b4105c2452a5b92c4c6655cf022193a9'
131 '7b5ce6fb321f4adf5b536ae482968e3b6daea3f67aa35afe27dbae3bdc358178'
132 '4efe8b926ba4251ca092042e640fa2fbec133aa311cea6e670968807bc1c5d8a'
133 '50ac93718a139e60fbda1cf54a531f0053f05f61f62f398573770da047babed7'
134)
135
136pkgver() {
137 cd "${srcdir}/hpn-ssh-${git_rev}/"
138 local version="$( awk -F_ '/^#define SSH_VERSION/ {print $NF}' version.h)"
139 local portable="$(awk '/^#define SSH_PORTABLE/{print $NF}' version.h)"
140 local hpn="$( awk '/^#define SSH_HPN/ {print $NF}' version.h)"
141 echo "${version//\"/}${portable//\"/}${hpn//\"/}"
142}
143
144prepare() {
145 cd "${srcdir}/hpn-ssh-${git_rev}/"
146
147 # fix building if scp is not installed on host
148 if [ ! -x /usr/bin/scp ]; then
149 patch -Np1 < ${srcdir}/openssh-tests-scp.patch
150 fi
151 # https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=371794f20c7eb2b88cae2619b6fa3444452aafb4
152 #patch -Np1 < ${srcdir}/openssl11.patch
153
154 # not needed anymore, HPN advertises itself properly through an in-place update on 2020-04-21
155 #patch -Np1 < ${srcdir}/hpn-banner.patch
156
157 patch -Np1 < ${srcdir}/glibc-2.31.patch
158
159 # double define fixed upstream in 4afe5ad21dd5a9a01cda3007cdd0af5bbe6b608c for 8.3p1-hpn14v22 on 2020-09-24
160 #patch -Np1 < ${srcdir}/hpn14v22-globals-cleanup.patch
161
162 patch -Np1 < "${srcdir}/hpn-revert-default-port-2222.patch"
163
164 autoreconf -fi
165}
166
167build() {
168 cd "${srcdir}/hpn-ssh-${git_rev}/"
169
170 autoreconf -fi
171 ./configure \
172 --prefix=/usr \
173 --sbindir=/usr/bin \
174 --libexecdir=/usr/lib/hpnssh \
175 --sysconfdir=/etc \
176 --disable-strip \
177 --with-ldns \
178 --with-libedit \
179 --with-security-key-builtin \
180 --with-ssl-engine \
181 --with-pam \
182 --with-privsep-user=nobody \
183 --with-kerberos5=/usr \
184 --with-xauth=/usr/bin/xauth \
185 --with-mantype=man \
186 --with-md5-passwords \
187 --with-pid-dir=/run \
188 --without-zlib-version-check \
189 --host="${CHOST}"
190 make
191}
192
193#check() {
194# cd "${srcdir}/hpn-ssh-${git_rev}/"
195#
196# # Tests require openssh to be already installed system-wide,
197# # also connectivity tests will fail under makechrootpkg since
198# # it runs as nobody which has /bin/false as login shell.
199#
200# if [[ -e /usr/bin/scp && ! -e /.arch-chroot ]]; then
201# make tests
202# fi
203#}
204
205package_openssh-hpn() {
206 install="openssh-hpn.install"
207 backup=(
208 'etc/hpnssh/ssh_config'
209 'etc/hpnssh/sshd_config'
210 'etc/pam.d/hpnsshd'
211 )
212 cd "${srcdir}/hpn-ssh-${git_rev}/"
213
214 make DESTDIR="${pkgdir}" install
215
216 install -Dm644 LICENCE "${pkgdir}/usr/share/licenses/${pkgname}/LICENCE"
217
218 install -Dm644 ../hpnsshdgenkeys.service "${pkgdir}"/usr/lib/systemd/system/hpnsshdgenkeys.service
219 install -Dm644 ../hpnsshd.service "${pkgdir}"/usr/lib/systemd/system/hpnsshd.service
220 install -Dm644 ../hpnssh-agent.service "${pkgdir}"/usr/lib/systemd/system/hpnssh-agent.service
221 install -Dm644 ../sshd.conf "${pkgdir}"/var/lib/tmpfiles.d/hpnsshd.conf
222 install -Dm644 ../sshd.pam "${pkgdir}"/etc/pam.d/hpnsshd
223
224 install -Dm755 contrib/findssl.sh "${pkgdir}"/usr/bin/hpnfindssl.sh
225 install -Dm755 contrib/hpnssh-copy-id "${pkgdir}"/usr/bin/hpnssh-copy-id
226 install -Dm644 contrib/hpnssh-copy-id.1 "${pkgdir}"/usr/share/man/man1/hpnssh-copy-id.1
227
228 sed \
229 -e '/^#ChallengeResponseAuthentication yes$/c ChallengeResponseAuthentication no' \
230 -e '/^#PrintMotd yes$/c PrintMotd no # pam does that' \
231 -e '/^#UsePAM no$/c UsePAM yes' \
232 -i "${pkgdir}"/etc/hpnssh/sshd_config
233}
234
235package_openssh-hpn-shim(){
236 depends=('openssh-hpn')
237 provides=('openssh')
238 conflicts=('openssh' 'openssh-hpn-git')
239 install="openssh-hpn-shim.install"
240 backup=(
241 'etc/ssh/ssh_config'
242 'etc/ssh/sshd_config'
243 'etc/pam.d/sshd'
244 )
245
246 cd "${srcdir}/hpn-ssh-${git_rev}/"
247
248 install -dm0755 "${pkgdir}/usr/bin" "${pkgdir}/usr/share/man/man1"
249 for i in scp sftp ssh ssh-add ssh-agent ssh-copy-id ssh-keygen ssh-keyscan; do
250 pushd "${pkgdir}/usr/bin" &>/dev/null; ln -s "hpn${i}" "${i}"; popd &>/dev/null
251 pushd "${pkgdir}/usr/share/man/man1" &>/dev/null; ln -s "hpn${i}.1.gz" "${i}.1.gz"; popd &>/dev/null
252 done
253 pushd "${pkgdir}/usr/bin" &>/dev/null; for i in findssl.sh sshd; do ln -s "hpn${i}" "${i}"; done; popd &>/dev/null
254 pushd "${pkgdir}/usr/share/man/man1" &>/dev/null; ln -sf hpnssh.1.gz slogin.1.gz; popd &>/dev/null
255
256 install -dm0755 "${pkgdir}/usr/lib/ssh" "${pkgdir}/usr/share/man/man8"
257 for i in sftp-server ssh-keysign ssh-pkcs11-helper ssh-sk-helper; do
258 pushd "${pkgdir}/usr/lib/ssh" &>/dev/null; ln -s "../hpnssh/hpn${i}" "${i}"; popd &>/dev/null
259 pushd "${pkgdir}/usr/share/man/man8" &>/dev/null; ln -s "hpn${i}.8.gz" "${i}.8.gz"; popd &>/dev/null
260 done
261 pushd "${pkgdir}/usr/share/man/man8" &>/dev/null; ln -s "hpnsshd.8.gz" "sshd.8.gz"; popd &>/dev/null
262
263 install -dm0755 "${pkgdir}/usr/share/man/man5" "${pkgdir}/etc/ssh"
264 for i in moduli ssh_config sshd_config; do
265 pushd "${pkgdir}/usr/share/man/man5" &>/dev/null; ln -s "hpn${i}.5.gz" "${i}.5.gz"; popd &>/dev/null
266
267 # apparently configs need to exist in target package for pacman to not stomp
268 # them, instead of following previous package's `backup` entry *on removal*
269 pushd "${pkgdir}/etc/ssh" &>/dev/null; ln -s "../hpnssh/${i}" "${i}"; popd &>/dev/null
270 done
271
272 install -Dm644 ../sshdgenkeys.service "${pkgdir}"/usr/lib/systemd/system/sshdgenkeys.service
273 install -Dm644 ../sshd.service "${pkgdir}"/usr/lib/systemd/system/sshd.service
274 install -Dm644 ../sshd.pam "${pkgdir}"/etc/pam.d/sshd
275 install -Dm644 ../ssh-agent.service "${pkgdir}"/usr/lib/systemd/system/ssh-agent.service
276}
277

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion