openssh-selinux

maintainer IooNag · 20 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The source is a legitimate OpenSSH portable release tarball from the official OpenBSD FTP server, which is a trusted and standard host for OpenSSH sources; the non-whitelisted host flag is a false positive as ftp.openbsd.org is an official project domain.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a legitimate OpenSSH portable release tarball from the official OpenBSD FTP server, which is a trusted and standard host for OpenSSH sources; the non-whitelisted host flag is a false positive as ftp.openbsd.org is an official project domain.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:58 https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: David Runge <dvzrv@archlinux.org>
2# Maintainer: Levente Polyak <anthraxx[at]archlinux[dot]org>
3# Maintainer: Giancarlo Razzolini <grazzolini@archlinux.org>
4# Contributor: Gaetan Bisson <bisson@archlinux.org>
5# Contributor: Aaron Griffin <aaron@archlinux.org>
6# Contributor: judd <jvinet@zeroflux.org>
7# SELinux Maintainer: Nicolas Iooss (nicolas <dot> iooss <at> m4x <dot> org)
8# SELinux Contributor: Timothée Ravier <tim@siosm.fr>
9# SELinux Contributor: Nicky726 <Nicky726@gmail.com>
10#
11# This PKGBUILD is maintained on https://github.com/archlinuxhardened/selinux.
12# If you want to help keep it up to date, please open a Pull Request there.
13
14pkgname=openssh-selinux
15pkgver=10.4p1
16pkgrel=3
17pkgdesc="SSH protocol implementation for remote login, command execution and file transfer, with SELinux support"
18arch=(x86_64 aarch64)
19url='https://www.openssh.com/portable.html'
20license=(
21 0BSD
22 BSD-2-Clause
23 BSD-3-Clause
24 ISC
25 LicenseRef-Public-Domain
26 MIT
27)
28depends=(
29 glibc
30 libselinux
31)
32makedepends=(
33 krb5
34 libedit
35 libfido2
36 libxcrypt
37 linux-headers
38 openssl
39 pam
40 zlib
41)
42optdepends=(
43 'libfido2: FIDO/U2F support'
44 'sh: for ssh-copy-id and findssl.sh'
45 'x11-ssh-askpass: input passphrase in X'
46 'xorg-xauth: X11 forwarding'
47)
48backup=(
49 etc/pam.d/sshd
50 etc/ssh/ssh_config
51 etc/ssh/sshd_config
52)
53conflicts=("${pkgname/-selinux}" "selinux-${pkgname/-selinux}")
54provides=("${pkgname/-selinux}=${pkgver}-${pkgrel}"
55 "selinux-${pkgname/-selinux}=${pkgver}-${pkgrel}")
56groups=('selinux')
57source=(
58 https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}
59 0001-fix-GSSAPI-option-names.patch
60 99-archlinux.conf
61 ${pkgname/-selinux}.tmpfiles
62 sshdgenkeys.service
63 10-openssh-mark-sshd-for-restart.hook
64 sshd.service
65 sshd@.service
66 ssh-agent.service
67 ssh-agent.socket
68 sshd.pam
69 LICENSE
70)
71sha256sums=('ef6026dd2aea8d56059638d5d3262902c892ceba9f88395835e0d06d3fb63238'
72 'SKIP'
73 '67ad6f713dc45f8a746c726319e085db76e7aa1b46761cde21980f610b130181'
74 '78b806c38bc1e246daaa941bfe7880e6eb6f53f093bea5d5868525ae6d223d30'
75 'fadd31c107aee3fc6b501ca046aeb5e6fb1b0256cc5cdcade4e2c95205823a28'
76 'e4dbff8e04a363a557c19d150e7e3a4317126a0371375771ae800bddf26860a7'
77 '52e23d53c1967ecce1d2f1010e965e5583dfad51590ab3af490223ad8a4bc4a9'
78 '25aea12c4c7fcc3636cae75b3b3cdb1c1bf513659b1e62b8ed67e02afeefc1b4'
79 '048c07e2085147a7626c2d3f82c9523b1bec6890c1173486de44b2b70624d3e3'
80 '824bf888ad0cb20ff3c2e13292389eb355ab91c3d9cc2fe0c8c5c60365d4a9c7'
81 'a16492e1eb9219d47a9053f0c83cdc323bff3c6f5b573bc6509ec40e40e4d04b'
82 '633e24cbfcb045ba777d3e06d5f85dfaa06d44f4727d38c7fb2187c57498221d'
83 '7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3')
84b2sums=('3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74'
85 'SKIP'
86 'a443d46d1e38ff36ec76ca43b5327e72063266bdbe04394acb53880a437c3a8e3e8ede0c7f4f989ac4ca19beb57ba4ecad884a86890e76f7de3e121a3fa82367'
87 '1ff8cd4ae22efed2b4260f1e518de919c4b290be4e0b5edbc8e2225ffe63788678d1961e6f863b85974c4697428ee827bcbabad371cfc91cc8b36eae9402eb97'
88 '57e77e55fcbd9d7b9951adbafe11ba62e4b8b7338c2a6fe3f163afe5b84458db042024cefbc55f9393cf17d97d067f1c2d9c61880516501bfa4e5c92371e494a'
89 '2031e10746edb77c190fb762ab82ff9dae2ad801d06d4c5eff2a8fcc459b873cf7c653e320c289f075f440d2079dd2430e0996a87511d3c8587903c622e8b44c'
90 '120dd272dde778fee749b1606d26c2caeaba40d875231f6f1398b990fa80adba1658cd6da91e336b5fd45d7703cdbf12294e7528e1d3f90a2a33c108e84a4dbb'
91 'f0687d2acfbe81af6b26f93d5fa507f4a4566a79e7c5e27796698b81d2b5aaf56be54a3a519680f9df076adff2455ecce9ffb789a05af9fd353b69c17742b362'
92 '8c843c40bf98703fb1eb6280ce1fb4aee7bd3c8632aaaa8598afc02921c4aa9906fde97850e150fd7c67e91a562c7578b17250589be5ad592ac89ccff9da9d99'
93 '6a80552260bc016757725602638478345565e1466335da8a70e0b4e49fe2e9d3b863df83764696cd91637c17dd137ed7c26188a1d795af3d024d89c9c229829b'
94 'f161cdb54609bd4521d9517c5c9d97a87f7de5c7504bf46d870ee814624817050ca9f68d42a1e661ecc7c3ede1a440b5b159df18f3b16b3c2e90ecfbd0dfd258'
95 '1d24cc029eccf71cee54dda84371cf9aa8d805433e751575ab237df654055dd869024b50facd8b73390717e63100c76bca28b493e0c8be9791c76a2e0d60990a'
96 'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101')
97validpgpkeys=('7168B983815A5EEF59A4ADFD2A3F414E736060BA') # Damien Miller <djm@mindrot.org>
98
99prepare() {
100 cd ${pkgname/-selinux}-$pkgver
101 # remove variable (but useless) first line in config (related to upstream VCS)
102 sed '/^#.*\$.*\$$/d' -i ssh{,d}_config
103
104 # prepend configuration option to include drop-in configuration files for sshd_config
105 printf "# Include drop-in configurations\nInclude /etc/ssh/sshd_config.d/*.conf\n" | cat - sshd_config > sshd_config.tmp
106 mv -v sshd_config.tmp sshd_config
107 # prepend configuration option to include drop-in configuration files for ssh_config
108 printf "# Include drop-in configurations\nInclude /etc/ssh/ssh_config.d/*.conf\n" | cat - ssh_config > ssh_config.tmp
109 mv -v ssh_config.tmp ssh_config
110
111 # extract separate licenses
112 sed -n '89,113p' LICENCE > ../rijndael.Public-Domain.txt
113 sed -n '116,145p' LICENCE > ../ssh.BSD-3-Clause.txt
114 sed -n '148,209p' LICENCE > ../BSD-2-Clause.txt
115 sed -n '213,218p' LICENCE > ../snprintf.Public-Domain.txt
116 sed -n '222,258p' LICENCE > ../openbsd-compat.BSD-3-Clause.txt
117 sed -n '260,278p' LICENCE > ../openbsd-compat.ISC.txt
118 sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt
119 sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt
120 sed -n '310,338p' LICENCE > ../blowfish.BSD-3-Clause.txt
121 sed -n '340,368p' LICENCE > ../replacement.BSD-2-Clause.txt
122
123 # fix GSSAPI option name
124 patch -Np1 < ../0001-fix-GSSAPI-option-names.patch
125}
126
127build() {
128 local configure_options=(
129 --disable-lastlog
130 --disable-strip
131 --libexecdir=/usr/lib/ssh
132 --prefix=/usr
133 --sbindir=/usr/bin
134 --sysconfdir=/etc/ssh
135 --with-default-path='/usr/local/sbin:/usr/local/bin:/usr/bin'
136 --with-kerberos5=/usr
137 --with-libedit
138 --with-pam
139 --with-pid-dir=/run
140 --with-privsep-path=/usr/share/empty.sshd
141 --with-privsep-user=nobody
142 --with-security-key-builtin
143 --with-ssl-engine
144 --with-xauth=/usr/bin/xauth
145 --without-zlib-version-check
146 --with-selinux
147 )
148
149 cd ${pkgname/-selinux}-$pkgver
150
151 ./configure "${configure_options[@]}"
152 make
153}
154
155check() {
156 # NOTE: make t-exec does not work in our build environment
157 make file-tests interop-tests unit -C ${pkgname/-selinux}-$pkgver
158}
159
160package() {
161 depends+=(
162 krb5 libkrb5.so libgssapi_krb5.so
163 libedit libedit.so
164 libxcrypt libcrypt.so
165 openssl libcrypto.so
166 pam libpam.so
167 zlib libz.so
168 )
169
170 cd ${pkgname/-selinux}-$pkgver
171
172 make DESTDIR="$pkgdir" install
173
174 install -vDm 644 ../99-archlinux.conf -t "$pkgdir/etc/ssh/sshd_config.d/"
175 install -vdm 755 "$pkgdir/etc/ssh/ssh_config.d"
176
177 install -Dm644 LICENCE -t "$pkgdir/usr/share/licenses/${pkgname/-selinux}/"
178 install -Dm644 ../*.txt -t "$pkgdir/usr/share/licenses/${pkgname/-selinux}/"
179
180 install -Dm644 ../sshdgenkeys.service -t "$pkgdir"/usr/lib/systemd/system/
181 install -Dm644 ../sshd.service -t "$pkgdir"/usr/lib/systemd/system/
182 install -Dm644 ../sshd@.service -t "$pkgdir"/usr/lib/systemd/system/
183 install -Dm644 ../ssh-agent.{service,socket} -t "$pkgdir"/usr/lib/systemd/user/
184 install -Dm644 ../sshd.pam "$pkgdir"/etc/pam.d/sshd
185 install -vDm 644 ../10-openssh-mark-sshd-for-restart.hook -t "$pkgdir/usr/share/libalpm/hooks/"
186
187 # factory files
188 install -Dm644 ../sshd.pam "$pkgdir"/usr/share/factory/etc/pam.d/sshd
189 install -Dm644 "$pkgdir/etc/ssh/moduli" -t "$pkgdir"/usr/share/factory/etc/ssh/
190 install -Dm644 "$pkgdir/etc/ssh/ssh_config" -t "$pkgdir"/usr/share/factory/etc/ssh/
191 install -Dm644 "$pkgdir/etc/ssh/sshd_config" -t "$pkgdir"/usr/share/factory/etc/ssh/
192 install -vDm 644 ../99-archlinux.conf -t "$pkgdir/usr/share/factory/etc/ssh/sshd_config.d/"
193
194 install -vDm 644 ../${pkgname/-selinux}.tmpfiles "$pkgdir/usr/lib/tmpfiles.d/${pkgname/-selinux}.conf"
195 install -vDm 644 ../LICENSE "$pkgdir/usr/share/licenses/$pkgname/0BSD.txt"
196
197 install -Dm755 contrib/findssl.sh -t "$pkgdir"/usr/bin/
198 install -Dm755 contrib/ssh-copy-id -t "$pkgdir"/usr/bin/
199 install -Dm644 contrib/ssh-copy-id.1 -t "$pkgdir"/usr/share/man/man1/
200}
201
202# vim: ts=2 sw=2 et:
203

Changes since previous scan

--- PKGBUILD @ 2026-06-19 19:07
+++ PKGBUILD @ 2026-08-03 00:08
@@ -12,8 +12,8 @@
# If you want to help keep it up to date, please open a Pull Request there.
pkgname=openssh-selinux
-pkgver=10.2p1
-pkgrel=2
+pkgver=10.4p1
+pkgrel=3
pkgdesc="SSH protocol implementation for remote login, command execution and file transfer, with SELinux support"
arch=(x86_64 aarch64)
url='https://www.openssh.com/portable.html'
@@ -56,54 +56,47 @@
groups=('selinux')
source=(
https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/${pkgname/-selinux}-${pkgver}.tar.gz{,.asc}
+ 0001-fix-GSSAPI-option-names.patch
99-archlinux.conf
${pkgname/-selinux}.tmpfiles
sshdgenkeys.service
- 70-openssh-restart-sshd.hook
+ 10-openssh-mark-sshd-for-restart.hook
sshd.service
sshd@.service
ssh-agent.service
ssh-agent.socket
sshd.pam
LICENSE
- ${pkgname/-selinux}-10.2p1-error-to-debug-pkcs11_fetch_certs.patch::https://github.com/openssh/openssh-portable/commit/607f337637f2077b34a9f6f96fc24237255fe175.patch
- ${pkgname/-selinux}-10.2p1-pinentry-pkcs11provider.patch::https://github.com/openssh/openssh-portable/commit/434ba7684054c0637ce8f2486aaacafe65d9b8aa.patch
-)
-sha256sums=('ccc42c0419937959263fa1dbd16dafc18c56b984c03562d2937ce56a60f798b2'
+)
+sha256sums=('ef6026dd2aea8d56059638d5d3262902c892ceba9f88395835e0d06d3fb63238'
'SKIP'
+ '67ad6f713dc45f8a746c726319e085db76e7aa1b46761cde21980f610b130181'
'78b806c38bc1e246daaa941bfe7880e6eb6f53f093bea5d5868525ae6d223d30'
'fadd31c107aee3fc6b501ca046aeb5e6fb1b0256cc5cdcade4e2c95205823a28'
'e4dbff8e04a363a557c19d150e7e3a4317126a0371375771ae800bddf26860a7'
- '1d55162a0a35ecbbad9deb0e6108510bcb9cb9e4c6b5813217816bf2be3b8f7e'
+ '52e23d53c1967ecce1d2f1010e965e5583dfad51590ab3af490223ad8a4bc4a9'
'25aea12c4c7fcc3636cae75b3b3cdb1c1bf513659b1e62b8ed67e02afeefc1b4'
'048c07e2085147a7626c2d3f82c9523b1bec6890c1173486de44b2b70624d3e3'
'824bf888ad0cb20ff3c2e13292389eb355ab91c3d9cc2fe0c8c5c60365d4a9c7'
'a16492e1eb9219d47a9053f0c83cdc323bff3c6f5b573bc6509ec40e40e4d04b'
'633e24cbfcb045ba777d3e06d5f85dfaa06d44f4727d38c7fb2187c57498221d'
- '7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3'
- '8a059f4895a9da4a2425425a1f1be1a2ee790b52626b412db8987fa6772a9a22'
- '35b019c4af919d068ec444774273db7af0009ffb8615f66db90e337710382a80')
-b2sums=('8c031b10b1642e21b46f7d1db84ba42692e378a54af3d8e5b5c8706c3a0a06d442a02ed8803063121e7ff325ea275cad4432b9eaa6a7f47a4d7cfad504953ab6'
+ '7056c04df17a4e0f0bac9f787f347c9cd892cee6323d1c89528090afd0b934a3')
+b2sums=('3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74'
'SKIP'
+ 'a443d46d1e38ff36ec76ca43b5327e72063266bdbe04394acb53880a437c3a8e3e8ede0c7f4f989ac4ca19beb57ba4ecad884a86890e76f7de3e121a3fa82367'
'1ff8cd4ae22efed2b4260f1e518de919c4b290be4e0b5edbc8e2225ffe63788678d1961e6f863b85974c4697428ee827bcbabad371cfc91cc8b36eae9402eb97'
'57e77e55fcbd9d7b9951adbafe11ba62e4b8b7338c2a6fe3f163afe5b84458db042024cefbc55f9393cf17d97d067f1c2d9c61880516501bfa4e5c92371e494a'
'2031e10746edb77c190fb762ab82ff9dae2ad801d06d4c5eff2a8fcc459b873cf7c653e320c289f075f440d2079dd2430e0996a87511d3c8587903c622e8b44c'
- '2073efe002a178670920a68a43eb16430de6c8921efde0dc272c6c5e4b9b6f7ea06186f7ceec8b3d94af226ffd00f96c8212d9873741e5305b8e94ebc8e15ee7'
+ '120dd272dde778fee749b1606d26c2caeaba40d875231f6f1398b990fa80adba1658cd6da91e336b5fd45d7703cdbf12294e7528e1d3f90a2a33c108e84a4dbb'
'f0687d2acfbe81af6b26f93d5fa507f4a4566a79e7c5e27796698b81d2b5aaf56be54a3a519680f9df076adff2455ecce9ffb789a05af9fd353b69c17742b362'
'8c843c40bf98703fb1eb6280ce1fb4aee7bd3c8632aaaa8598afc02921c4aa9906fde97850e150fd7c67e91a562c7578b17250589be5ad592ac89ccff9da9d99'
'6a80552260bc016757725602638478345565e1466335da8a70e0b4e49fe2e9d3b863df83764696cd91637c17dd137ed7c26188a1d795af3d024d89c9c229829b'
'f161cdb54609bd4521d9517c5c9d97a87f7de5c7504bf46d870ee814624817050ca9f68d42a1e661ecc7c3ede1a440b5b159df18f3b16b3c2e90ecfbd0dfd258'
'1d24cc029eccf71cee54dda84371cf9aa8d805433e751575ab237df654055dd869024b50facd8b73390717e63100c76bca28b493e0c8be9791c76a2e0d60990a'
- 'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101'
- '72c4115bee487869bed7a543817c9ab3e3e17c2c884446314f9f4828cf6ce46c759bbf7dfae9194612931e2ead1ae9e4e52bdbe750bfcb22dfe5583b8168a379'
- '88a62f93d6a7a58c0f170333cd279d339342a898d51cdd5aeb1488bee53cc5d7cf6f0468a2f9b098b8f7977cd4cf81ad706a12942b6dac33b3fa5406592f6963')
+ 'a29664104e1ee73ca0aee1d633e9095d92a57c92787f8d8740bdb7211ba3205782ed8677f539bdb8cae3dd75a3694be3132e185fa3fc4b3f401e1f88eb776101')
validpgpkeys=('7168B983815A5EEF59A4ADFD2A3F414E736060BA') # Damien Miller <djm@mindrot.org>
prepare() {
- # Fix an issue with PKCS#11 provided keys: https://gitlab.archlinux.org/archlinux/packaging/packages/openssh/-/issues/23
- patch -Np1 -d ${pkgname/-selinux}-$pkgver -i ../${pkgname/-selinux}-10.2p1-error-to-debug-pkcs11_fetch_certs.patch
- patch -Np1 -d ${pkgname/-selinux}-$pkgver -i ../${pkgname/-selinux}-10.2p1-pinentry-pkcs11provider.patch
-
cd ${pkgname/-selinux}-$pkgver
# remove variable (but useless) first line in config (related to upstream VCS)
sed '/^#.*\$.*\$$/d' -i ssh{,d}_config
@@ -126,6 +119,9 @@
sed -n '280,308p' LICENCE > ../openbsd-compat.MIT.txt
sed -n '310,338p' LICENCE > ../blowfish.BSD-3-Clause.txt
sed -n '340,368p' LICENCE > ../replacement.BSD-2-Clause.txt
+
+ # fix GSSAPI option name
+ patch -Np1 < ../0001-fix-GSSAPI-option-names.patch
}
build() {
@@ -186,7 +182,7 @@
install -Dm644 ../sshd@.service -t "$pkgdir"/usr/lib/systemd/system/
install -Dm644 ../ssh-agent.{service,socket} -t "$pkgdir"/usr/lib/systemd/user/
install -Dm644 ../sshd.pam "$pkgdir"/etc/pam.d/sshd
- install -vDm 644 ../70-openssh-restart-sshd.hook -t "$pkgdir/usr/share/libalpm/hooks/"
+ install -vDm 644 ../10-openssh-mark-sshd-for-restart.hook -t "$pkgdir/usr/share/libalpm/hooks/"
# factory files
install -Dm644 ../sshd.pam "$pkgdir"/usr/share/factory/etc/pam.d/sshd

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 21:18:45 MEDIUM 1
2026-06-19 19:07:35 CLEAN 2
2026-06-18 16:11:54 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion