pam-selinux
The package grants elevated privileges or installs an update path outside pacman: a /etc/sudoers.d rule (often passwordless), a setuid/setgid binary, or a self-update script/service that can fetch and run future code with no checksum verification. The initial install may be verified, but the ongoing privilege + update surface is a real supply-chain / privilege-escalation risk.
Triggered rules
privileged_install
The package grants elevated privileges or installs an update path outside pacman: a /etc/sudoers.d rule (often passwordless), a setuid/setgid binary, or a self-update script/service that can fetch and run future code with no checksum verification. The initial install may be verified, but the ongoing privilege + update surface is a real supply-chain / privilege-escalation risk.
-
PKGBUILD:103
chmod +s "${pkgdir}"/usr/bin/unix_chkpwd
PKGBUILD
1 offending line(s) highlighted# Maintainer: Tobias Powalowski <tpowa@archlinux.org>
# Maintainer: Levente Polyak <anthraxx[at]archlinux[dot]org>
# Contributor: judd <jvinet@zeroflux.org>
# SELinux Maintainer: Nicolas Iooss (nicolas <dot> iooss <at> m4x <dot> org)
# SELinux Contributor: Timothée Ravier <tim@siosm.fr>
# SELinux Contributor: Nicky726 <nicky726@gmail.com>
#
# This PKGBUILD is maintained on https://github.com/archlinuxhardened/selinux.
# If you want to help keep it up to date, please open a Pull Request there.
pkgname=pam-selinux
pkgver=1.7.3
pkgrel=1
pkgdesc="SELinux aware PAM (Pluggable Authentication Modules) library"
arch=('x86_64' 'aarch64')
license=('GPL-2.0-only')
url="http://linux-pam.org"
depends=(
audit
glibc
libaudit.so
libcrypt.so
libnsl
libselinux
libtirpc
libxcrypt
pambase-selinux
systemd-libs
)
makedepends=(
docbook-xml
docbook-xsl
docbook5-xml
flex
fop
git
libxslt
meson
w3m
)
conflicts=("${pkgname/-selinux}" "selinux-${pkgname/-selinux}")
provides=(
libpam.so
libpamc.so
libpam_misc.so
"${pkgname/-selinux}=${pkgver}-${pkgrel}"
"selinux-${pkgname/-selinux}=${pkgver}-${pkgrel}"
)
backup=(
etc/security/{access.conf,faillock.conf,group.conf,limits.conf,namespace.conf,namespace.init,pwhistory.conf,pam_env.conf,time.conf}
etc/environment
)
groups=('selinux')
source=("pam::git+https://github.com/linux-pam/linux-pam?signed#tag=v${pkgver}"
"${pkgname/-selinux}.tmpfiles")
validpgpkeys=(
'8C6BFD92EE0F42EDF91A6A736D1A7F052E5924BB' # Thorsten Kukuk
'296D6F29A020808E8717A8842DB5BD89A340AEB7' # Dimitry V. Levin <ldv@altlinux.org>
'7BECFE3AF7B280BB52FF77F104BA4521C996DDE1' # Dmitry V. Levin <ldv@strace.io
)
b2sums=('a533679b3362f9ebb67a7652454af9402ee845e1bd6f99064b870b38f9dc7a6ec62a73d65af2086e863448742714b6eb6a91d0ad2209e77325fd127635230648'
'36582c80020008c3810b311a2e126d2fb4ffc94e565ea4c0c0ab567fdb92943e269781ffa548550742feb685847c26c340906c7454dcc31df4e1e47d511d8d6f')
options=('!emptydirs')
prepare() {
cd "${pkgname/-selinux}"
# apply patch from the source array (should be a pacman feature)
local src
for src in "${source[@]}"; do
src="${src%%::*}"
src="${src##*/}"
[[ $src = *.patch ]] || continue
echo "Applying patch ${src}..."
patch -Np1 < "../${src}"
done
}
build() {
arch-meson "${pkgname/-selinux}" \
-Dlogind=enabled \
-Deconf=disabled \
-Dselinux=enabled \
-Delogind=disabled \
-Dpam_userdb=disabled \
-Dpwaccess=disabled \
-Dvendordir='' \
build
meson compile -C build
}
check() {
meson test -C build
}
package() {
meson install -C build --destdir "${pkgdir}"
install -Dm 644 ${pkgname/-selinux}.tmpfiles "${pkgdir}"/usr/lib/tmpfiles.d/${pkgname/-selinux}.conf
# remove unreproducible pdf files
rm "${pkgdir}"/usr/share/doc/Linux-PAM/*.pdf
# set unix_chkpwd uid
chmod +s "${pkgdir}"/usr/bin/unix_chkpwd
}
Changes since previous scan
--- PKGBUILD @ 2026-06-18 16:11+++ PKGBUILD @ 2026-10-05 23:40@@ -9,8 +9,8 @@ # If you want to help keep it up to date, please open a Pull Request there. pkgname=pam-selinux-pkgver=1.7.2-pkgrel=2+pkgver=1.7.3+pkgrel=1 pkgdesc="SELinux aware PAM (Pluggable Authentication Modules) library" arch=('x86_64' 'aarch64') license=('GPL-2.0-only')@@ -58,7 +58,7 @@ '296D6F29A020808E8717A8842DB5BD89A340AEB7' # Dimitry V. Levin <ldv@altlinux.org> '7BECFE3AF7B280BB52FF77F104BA4521C996DDE1' # Dmitry V. Levin <ldv@strace.io )-b2sums=('7fac16161ee8abab8639f5661badcf29536f0df71fec085075b657f91264fa7e616ae74c60e77fd8503d767517847dda877f583f20ca354e2ba45a381d89c998'+b2sums=('a533679b3362f9ebb67a7652454af9402ee845e1bd6f99064b870b38f9dc7a6ec62a73d65af2086e863448742714b6eb6a91d0ad2209e77325fd127635230648' '36582c80020008c3810b311a2e126d2fb4ffc94e565ea4c0c0ab567fdb92943e269781ffa548550742feb685847c26c340906c7454dcc31df4e1e47d511d8d6f') options=('!emptydirs') Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-05 23:40:58 | Medium | 1 |
| 2026-06-18 16:11:54 | Clean | 0 |