openssh-selinux
maintainer IooNag
· 20 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The source is a legitimate OpenSSH portable release tarball from the official OpenBSD FTP server, which is a trusted and standard host for OpenSSH sources; the non-whitelisted host flag is a false positive as ftp.openbsd.org is an official project domain.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate OpenSSH portable release tarball from the official OpenBSD FTP server, which is a trusted and standard host for OpenSSH sources; the non-whitelisted host flag is a false positive as ftp.openbsd.org is an official project domain.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:58
https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: David Runge <dvzrv@archlinux.org>
2
# Maintainer: Levente Polyak <anthraxx[at]archlinux[dot]org>
3
# Maintainer: Giancarlo Razzolini <grazzolini@archlinux.org>
4
# Contributor: Gaetan Bisson <bisson@archlinux.org>
5
# Contributor: Aaron Griffin <aaron@archlinux.org>
6
# Contributor: judd <jvinet@zeroflux.org>
7
# SELinux Maintainer: Nicolas Iooss (nicolas <dot> iooss <at> m4x <dot> org)
8
# SELinux Contributor: Timothée Ravier <tim@siosm.fr>
9
# SELinux Contributor: Nicky726 <Nicky726@gmail.com>
10
#
11
# This PKGBUILD is maintained on https://github.com/archlinuxhardened/selinux.
12
# If you want to help keep it up to date, please open a Pull Request there.
13
14
pkgname=openssh-selinux
15
pkgver=10.4p1
16
pkgrel=3
17
pkgdesc="SSH protocol implementation for remote login, command execution and file transfer, with SELinux support"
18
arch=(x86_64 aarch64)
19
url='https://www.openssh.com/portable.html'
20
license=(
21
0BSD
22
BSD-2-Clause
23
BSD-3-Clause
24
ISC
25
LicenseRef-Public-Domain
26
MIT
27
)
28
depends=(
29
glibc
30
libselinux
31
)
32
makedepends=(
33
krb5
34
libedit
35
libfido2
36
libxcrypt
37
linux-headers
38
openssl
39
pam
40
zlib
41
)
42
optdepends=(
43
'libfido2: FIDO/U2F support'
44
'sh: for ssh-copy-id and findssl.sh'
45
'x11-ssh-askpass: input passphrase in X'
46
'xorg-xauth: X11 forwarding'
47
)
48
backup=(
49
etc/pam.d/sshd
50
etc/ssh/ssh_config
51
etc/ssh/sshd_config
52
)
53
conflicts=("${pkgname/-selinux}" "selinux-${pkgname/-selinux}")
54
provides=("${pkgname/-selinux}=${pkgver}-${pkgrel}"
55
"selinux-${pkgname/-selinux}=${pkgver}-${pkgrel}")
56
groups=('selinux')
57
source=(
58
https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}
59
0001-fix-GSSAPI-option-names.patch
60
99-archlinux.conf
61
${pkgname/-selinux}.tmpfiles
62
sshdgenkeys.service
63
10-openssh-mark-sshd-for-restart.hook
64
sshd.service
65
sshd@.service
66
ssh-agent.service
67
ssh-agent.socket
68
sshd.pam
69
LICENSE
70
)
71
sha256sums=('ef6026dd2aea8d56059638d5d3262902c892ceba9f88395835e0d06d3fb63238'
72
'SKIP'
73
'67ad6f713dc45f8a746c726319e085db76e7aa1b46761cde21980f610b130181'
74
'78b806c38bc1e246daaa941bfe7880e6eb6f53f093bea5d5868525ae6d223d30'
75
'fadd31c107aee3fc6b501ca046aeb5e6fb1b0256cc5cdcade4e2c95205823a28'
76
'e4dbff8e04a363a557c19d150e7e3a4317126a0371375771ae800bddf26860a7'
77
'52e23d53c1967ecce1d2f1010e965e5583dfad51590ab3af490223ad8a4bc4a9'
78
'25aea12c4c7fcc3636cae75b3b3cdb1c1bf513659b1e62b8ed67e02afeefc1b4'
79
'048c07e2085147a7626c2d3f82c9523b1bec6890c1173486de44b2b70624d3e3'
80
'824bf888ad0cb20ff3c2e13292389eb355ab91c3d9cc2fe0c8c5c60365d4a9c7'
81
'a16492e1eb9219d47a9053f0c83cdc323bff3c6f5b573bc6509ec40e40e4d04b'
82
'633e24cbfcb045ba777d3e06d5f85dfaa06d44f4727d38c7fb2187c57498221d'
83
'7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3')
84
b2sums=('3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74'
85
'SKIP'
86
'a443d46d1e38ff36ec76ca43b5327e72063266bdbe04394acb53880a437c3a8e3e8ede0c7f4f989ac4ca19beb57ba4ecad884a86890e76f7de3e121a3fa82367'
87
'1ff8cd4ae22efed2b4260f1e518de919c4b290be4e0b5edbc8e2225ffe63788678d1961e6f863b85974c4697428ee827bcbabad371cfc91cc8b36eae9402eb97'
88
'57e77e55fcbd9d7b9951adbafe11ba62e4b8b7338c2a6fe3f163afe5b84458db042024cefbc55f9393cf17d97d067f1c2d9c61880516501bfa4e5c92371e494a'
89
'2031e10746edb77c190fb762ab82ff9dae2ad801d06d4c5eff2a8fcc459b873cf7c653e320c289f075f440d2079dd2430e0996a87511d3c8587903c622e8b44c'
90
'120dd272dde778fee749b1606d26c2caeaba40d875231f6f1398b990fa80adba1658cd6da91e336b5fd45d7703cdbf12294e7528e1d3f90a2a33c108e84a4dbb'
91
'f0687d2acfbe81af6b26f93d5fa507f4a4566a79e7c5e27796698b81d2b5aaf56be54a3a519680f9df076adff2455ecce9ffb789a05af9fd353b69c17742b362'
92
'8c843c40bf98703fb1eb6280ce1fb4aee7bd3c8632aaaa8598afc02921c4aa9906fde97850e150fd7c67e91a562c7578b17250589be5ad592ac89ccff9da9d99'
93
'6a80552260bc016757725602638478345565e1466335da8a70e0b4e49fe2e9d3b863df83764696cd91637c17dd137ed7c26188a1d795af3d024d89c9c229829b'
94
'f161cdb54609bd4521d9517c5c9d97a87f7de5c7504bf46d870ee814624817050ca9f68d42a1e661ecc7c3ede1a440b5b159df18f3b16b3c2e90ecfbd0dfd258'
95
'1d24cc029eccf71cee54dda84371cf9aa8d805433e751575ab237df654055dd869024b50facd8b73390717e63100c76bca28b493e0c8be9791c76a2e0d60990a'
96
'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101')
97
validpgpkeys=('7168B983815A5EEF59A4ADFD2A3F414E736060BA') # Damien Miller <djm@mindrot.org>
98
99
prepare() {
100
cd ${pkgname/-selinux}-$pkgver
101
# remove variable (but useless) first line in config (related to upstream VCS)
102
sed '/^#.*\$.*\$$/d' -i ssh{,d}_config
103
104
# prepend configuration option to include drop-in configuration files for sshd_config
105
printf "# Include drop-in configurations\nInclude /etc/ssh/sshd_config.d/*.conf\n" | cat - sshd_config > sshd_config.tmp
106
mv -v sshd_config.tmp sshd_config
107
# prepend configuration option to include drop-in configuration files for ssh_config
108
printf "# Include drop-in configurations\nInclude /etc/ssh/ssh_config.d/*.conf\n" | cat - ssh_config > ssh_config.tmp
109
mv -v ssh_config.tmp ssh_config
110
111
# extract separate licenses
112
sed -n '89,113p' LICENCE > ../rijndael.Public-Domain.txt
113
sed -n '116,145p' LICENCE > ../ssh.BSD-3-Clause.txt
114
sed -n '148,209p' LICENCE > ../BSD-2-Clause.txt
115
sed -n '213,218p' LICENCE > ../snprintf.Public-Domain.txt
116
sed -n '222,258p' LICENCE > ../openbsd-compat.BSD-3-Clause.txt
117
sed -n '260,278p' LICENCE > ../openbsd-compat.ISC.txt
118
sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt
119
sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt
120
sed -n '310,338p' LICENCE > ../blowfish.BSD-3-Clause.txt
121
sed -n '340,368p' LICENCE > ../replacement.BSD-2-Clause.txt
122
123
# fix GSSAPI option name
124
patch -Np1 < ../0001-fix-GSSAPI-option-names.patch
125
}
126
127
build() {
128
local configure_options=(
129
--disable-lastlog
130
--disable-strip
131
--libexecdir=/usr/lib/ssh
132
--prefix=/usr
133
--sbindir=/usr/bin
134
--sysconfdir=/etc/ssh
135
--with-default-path='/usr/local/sbin:/usr/local/bin:/usr/bin'
136
--with-kerberos5=/usr
137
--with-libedit
138
--with-pam
139
--with-pid-dir=/run
140
--with-privsep-path=/usr/share/empty.sshd
141
--with-privsep-user=nobody
142
--with-security-key-builtin
143
--with-ssl-engine
144
--with-xauth=/usr/bin/xauth
145
--without-zlib-version-check
146
--with-selinux
147
)
148
149
cd ${pkgname/-selinux}-$pkgver
150
151
./configure "${configure_options[@]}"
152
make
153
}
154
155
check() {
156
# NOTE: make t-exec does not work in our build environment
157
make file-tests interop-tests unit -C ${pkgname/-selinux}-$pkgver
158
}
159
160
package() {
161
depends+=(
162
krb5 libkrb5.so libgssapi_krb5.so
163
libedit libedit.so
164
libxcrypt libcrypt.so
165
openssl libcrypto.so
166
pam libpam.so
167
zlib libz.so
168
)
169
170
cd ${pkgname/-selinux}-$pkgver
171
172
make DESTDIR="$pkgdir" install
173
174
install -vDm 644 ../99-archlinux.conf -t "$pkgdir/etc/ssh/sshd_config.d/"
175
install -vdm 755 "$pkgdir/etc/ssh/ssh_config.d"
176
177
install -Dm644 LICENCE -t "$pkgdir/usr/share/licenses/${pkgname/-selinux}/"
178
install -Dm644 ../*.txt -t "$pkgdir/usr/share/licenses/${pkgname/-selinux}/"
179
180
install -Dm644 ../sshdgenkeys.service -t "$pkgdir"/usr/lib/systemd/system/
181
install -Dm644 ../sshd.service -t "$pkgdir"/usr/lib/systemd/system/
182
install -Dm644 ../sshd@.service -t "$pkgdir"/usr/lib/systemd/system/
183
install -Dm644 ../ssh-agent.{service,socket} -t "$pkgdir"/usr/lib/systemd/user/
184
install -Dm644 ../sshd.pam "$pkgdir"/etc/pam.d/sshd
185
install -vDm 644 ../10-openssh-mark-sshd-for-restart.hook -t "$pkgdir/usr/share/libalpm/hooks/"
186
187
# factory files
188
install -Dm644 ../sshd.pam "$pkgdir"/usr/share/factory/etc/pam.d/sshd
189
install -Dm644 "$pkgdir/etc/ssh/moduli" -t "$pkgdir"/usr/share/factory/etc/ssh/
190
install -Dm644 "$pkgdir/etc/ssh/ssh_config" -t "$pkgdir"/usr/share/factory/etc/ssh/
191
install -Dm644 "$pkgdir/etc/ssh/sshd_config" -t "$pkgdir"/usr/share/factory/etc/ssh/
192
install -vDm 644 ../99-archlinux.conf -t "$pkgdir/usr/share/factory/etc/ssh/sshd_config.d/"
193
194
install -vDm 644 ../${pkgname/-selinux}.tmpfiles "$pkgdir/usr/lib/tmpfiles.d/${pkgname/-selinux}.conf"
195
install -vDm 644 ../LICENSE "$pkgdir/usr/share/licenses/$pkgname/0BSD.txt"
196
197
install -Dm755 contrib/findssl.sh -t "$pkgdir"/usr/bin/
198
install -Dm755 contrib/ssh-copy-id -t "$pkgdir"/usr/bin/
199
install -Dm644 contrib/ssh-copy-id.1 -t "$pkgdir"/usr/share/man/man1/
200
}
201
202
# vim: ts=2 sw=2 et:
203
Changes since previous scan
--- PKGBUILD @ 2026-06-19 19:07+++ PKGBUILD @ 2026-08-03 00:08@@ -12,8 +12,8 @@ # If you want to help keep it up to date, please open a Pull Request there. pkgname=openssh-selinux-pkgver=10.2p1-pkgrel=2+pkgver=10.4p1+pkgrel=3 pkgdesc="SSH protocol implementation for remote login, command execution and file transfer, with SELinux support" arch=(x86_64 aarch64) url='https://www.openssh.com/portable.html'@@ -56,54 +56,47 @@ groups=('selinux') source=( https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}+ 0001-fix-GSSAPI-option-names.patch 99-archlinux.conf ${pkgname/-selinux}.tmpfiles sshdgenkeys.service- 70-openssh-restart-sshd.hook+ 10-openssh-mark-sshd-for-restart.hook sshd.service sshd@.service ssh-agent.service ssh-agent.socket sshd.pam LICENSE- ${pkgname/-selinux}-10.2p1-error-to-debug-pkcs11_fetch_certs.patch::https://github.com/openssh/openssh-portable/commit/607f337637f2077b34a9f6f96fc24237255fe175.patch- ${pkgname/-selinux}-10.2p1-pinentry-pkcs11provider.patch::https://github.com/openssh/openssh-portable/commit/434ba7684054c0637ce8f2486aaacafe65d9b8aa.patch-)-sha256sums=('ccc42c0419937959263fa1dbd16dafc18c56b984c03562d2937ce56a60f798b2'+)+sha256sums=('ef6026dd2aea8d56059638d5d3262902c892ceba9f88395835e0d06d3fb63238' 'SKIP'+ '67ad6f713dc45f8a746c726319e085db76e7aa1b46761cde21980f610b130181' '78b806c38bc1e246daaa941bfe7880e6eb6f53f093bea5d5868525ae6d223d30' 'fadd31c107aee3fc6b501ca046aeb5e6fb1b0256cc5cdcade4e2c95205823a28' 'e4dbff8e04a363a557c19d150e7e3a4317126a0371375771ae800bddf26860a7'- '1d55162a0a35ecbbad9deb0e6108510bcb9cb9e4c6b5813217816bf2be3b8f7e'+ '52e23d53c1967ecce1d2f1010e965e5583dfad51590ab3af490223ad8a4bc4a9' '25aea12c4c7fcc3636cae75b3b3cdb1c1bf513659b1e62b8ed67e02afeefc1b4' '048c07e2085147a7626c2d3f82c9523b1bec6890c1173486de44b2b70624d3e3' '824bf888ad0cb20ff3c2e13292389eb355ab91c3d9cc2fe0c8c5c60365d4a9c7' 'a16492e1eb9219d47a9053f0c83cdc323bff3c6f5b573bc6509ec40e40e4d04b' '633e24cbfcb045ba777d3e06d5f85dfaa06d44f4727d38c7fb2187c57498221d'- '7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3'- '8a059f4895a9da4a2425425a1f1be1a2ee790b52626b412db8987fa6772a9a22'- '35b019c4af919d068ec444774273db7af0009ffb8615f66db90e337710382a80')-b2sums=('8c031b10b1642e21b46f7d1db84ba42692e378a54af3d8e5b5c8706c3a0a06d442a02ed8803063121e7ff325ea275cad4432b9eaa6a7f47a4d7cfad504953ab6'+ '7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3')+b2sums=('3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74' 'SKIP'+ 'a443d46d1e38ff36ec76ca43b5327e72063266bdbe04394acb53880a437c3a8e3e8ede0c7f4f989ac4ca19beb57ba4ecad884a86890e76f7de3e121a3fa82367' '1ff8cd4ae22efed2b4260f1e518de919c4b290be4e0b5edbc8e2225ffe63788678d1961e6f863b85974c4697428ee827bcbabad371cfc91cc8b36eae9402eb97' '57e77e55fcbd9d7b9951adbafe11ba62e4b8b7338c2a6fe3f163afe5b84458db042024cefbc55f9393cf17d97d067f1c2d9c61880516501bfa4e5c92371e494a' '2031e10746edb77c190fb762ab82ff9dae2ad801d06d4c5eff2a8fcc459b873cf7c653e320c289f075f440d2079dd2430e0996a87511d3c8587903c622e8b44c'- '2073efe002a178670920a68a43eb16430de6c8921efde0dc272c6c5e4b9b6f7ea06186f7ceec8b3d94af226ffd00f96c8212d9873741e5305b8e94ebc8e15ee7'+ '120dd272dde778fee749b1606d26c2caeaba40d875231f6f1398b990fa80adba1658cd6da91e336b5fd45d7703cdbf12294e7528e1d3f90a2a33c108e84a4dbb' 'f0687d2acfbe81af6b26f93d5fa507f4a4566a79e7c5e27796698b81d2b5aaf56be54a3a519680f9df076adff2455ecce9ffb789a05af9fd353b69c17742b362' '8c843c40bf98703fb1eb6280ce1fb4aee7bd3c8632aaaa8598afc02921c4aa9906fde97850e150fd7c67e91a562c7578b17250589be5ad592ac89ccff9da9d99' '6a80552260bc016757725602638478345565e1466335da8a70e0b4e49fe2e9d3b863df83764696cd91637c17dd137ed7c26188a1d795af3d024d89c9c229829b' 'f161cdb54609bd4521d9517c5c9d97a87f7de5c7504bf46d870ee814624817050ca9f68d42a1e661ecc7c3ede1a440b5b159df18f3b16b3c2e90ecfbd0dfd258' '1d24cc029eccf71cee54dda84371cf9aa8d805433e751575ab237df654055dd869024b50facd8b73390717e63100c76bca28b493e0c8be9791c76a2e0d60990a'- 'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101'- '72c4115bee487869bed7a543817c9ab3e3e17c2c884446314f9f4828cf6ce46c759bbf7dfae9194612931e2ead1ae9e4e52bdbe750bfcb22dfe5583b8168a379'- '88a62f93d6a7a58c0f170333cd279d339342a898d51cdd5aeb1488bee53cc5d7cf6f0468a2f9b098b8f7977cd4cf81ad706a12942b6dac33b3fa5406592f6963')+ 'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101') validpgpkeys=('7168B983815A5EEF59A4ADFD2A3F414E736060BA') # Damien Miller <djm@mindrot.org> prepare() {- # Fix an issue with PKCS#11 provided keys: https://gitlab.archlinux.org/archlinux/packaging/packages/openssh/-/issues/23- patch -Np1 -d ${pkgname/-selinux}-$pkgver -i ../${pkgname/-selinux}-10.2p1-error-to-debug-pkcs11_fetch_certs.patch- patch -Np1 -d ${pkgname/-selinux}-$pkgver -i ../${pkgname/-selinux}-10.2p1-pinentry-pkcs11provider.patch- cd ${pkgname/-selinux}-$pkgver # remove variable (but useless) first line in config (related to upstream VCS) sed '/^#.*\$.*\$$/d' -i ssh{,d}_config@@ -126,6 +119,9 @@ sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt sed -n '310,338p' LICENCE > ../blowfish.BSD-3-Clause.txt sed -n '340,368p' LICENCE > ../replacement.BSD-2-Clause.txt++ # fix GSSAPI option name+ patch -Np1 < ../0001-fix-GSSAPI-option-names.patch } build() {@@ -186,7 +182,7 @@ install -Dm644 ../sshd@.service -t "$pkgdir"/usr/lib/systemd/system/ install -Dm644 ../ssh-agent.{service,socket} -t "$pkgdir"/usr/lib/systemd/user/ install -Dm644 ../sshd.pam "$pkgdir"/etc/pam.d/sshd- install -vDm 644 ../70-openssh-restart-sshd.hook -t "$pkgdir/usr/share/libalpm/hooks/"+ install -vDm 644 ../10-openssh-mark-sshd-for-restart.hook -t "$pkgdir/usr/share/libalpm/hooks/" # factory files install -Dm644 ../sshd.pam "$pkgdir"/usr/share/factory/etc/pam.d/sshdScan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 21:18:45 | MEDIUM | 1 |
| 2026-06-19 19:07:35 | CLEAN | 2 |
| 2026-06-18 16:11:54 | MEDIUM | 1 |