s32-design-studio

MEDIUM
maintainer Bonnee 0 votes scanned 2026-09-28 17:23:17.479743
View on AUR
Why flagged

The source URL points to a FlexNet/Flexera license delivery host (freescaleesd.flexnetoperations.com) with a session-specific signed download token, and the pkgver/filename in the source= URL (3.6.11/D2609) mismatches the declared pkgver/installer variable (3.6.10/D2607), meaning the PKGBUILD actually downloads a different version than it claims; the installer is a large proprietary prebuilt binary run at build time, and the single sha256sum provided cannot be independently verified against any official NXP release page, making this an unverifiable prebuilt executable from a non-standard host with a version mismatch.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:54 source=("$installer::https://freescaleesd.flexnetoperations.com/337170/607/20142607/SW32_S32DS_3.6.11_RFP_D2609_linux.x86_64.bin?ftpRequestID=4480565751&server=freescaleesd.flexnetoperations.com&ext=.bin")
Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 70%): The source URL points to a FlexNet/Flexera license delivery host (freescaleesd.flexnetoperations.com) with a session-specific signed download token, and the pkgver/filename in the source= URL (3.6.11/D2609) mismatches the declared pkgver/installer variable (3.6.10/D2607), meaning the PKGBUILD actually downloads a different version than it claims; the installer is a large proprietary prebuilt binary run at build time, and the single sha256sum provided cannot be independently verified against any official NXP release page, making this an unverifiable prebuilt executable from a non-standard host with a version mismatch.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Matteo Bonora <bonora.matteo@gmail.com>
2pkgname=s32-design-studio
3pkgver=3.6.10
4pkgrel=1
5pkgdesc="IDE for editing, compiling, debugging and flashing NXP S32 designs (Kinetis, LPC, S32K, S32G, SAF)"
6arch=('x86_64')
7url="https://www.nxp.com/design/design-center/software/automotive-software-and-tools/s32-design-studio-ide:S32-DESIGN-STUDIO-IDE"
8# The vendor binaries are shipped as they are: the cross toolchains, the
9# bundled gdb and the S32 debugger need the symbol and debug information that
10# makepkg would remove, and repackaging them is not this package's business.
11# The libtool and staticlibs options are inverted in makepkg (they enable the
12# removal of the *.la and *.a files of the cross toolchain sysroots), so they
13# are turned on here to keep them.
14options=('!strip' '!debug' 'libtool' 'staticlibs')
15# The product is proprietary; the EULA and the third party licenses NXP
16# redistributes with it are installed in /opt/s32-design-studio/License.
17license=('LicenseRef-NXP-S32DS-EULA')
18depends=('alsa-lib'
19 'at-spi2-core'
20 'cairo'
21 'fontconfig'
22 'freetype2'
23 'gcc-libs'
24 'gdk-pixbuf2'
25 'glib2'
26 'gtk3'
27 'libglvnd'
28 'libnet'
29 'libusb'
30 'libusb-compat'
31 'libx11'
32 'libxext'
33 'libxft'
34 'libxi'
35 'libxrender'
36 'libxss'
37 'libxtst'
38 'libxxf86vm'
39 'ncurses'
40 'pango'
41 'pcsclite'
42 'xz'
43 'zlib'
44 'zstd')
45optdepends=('gtk2: legacy JavaFX GTK2 backend shipped with the IDE'
46 'python: python helpers of the S32 Debugger and of the PEmicro GDB client'
47 'tcl: TCL scripts of the Project_Settings container'
48 'dos2unix: unix2dos helper used by some project settings scripts')
49# NXP ships the installer as a self extracting binary that is not downloadable
50# without an nxp.com account, so it has to be placed next to this PKGBUILD (or
51# fetched with your own account) before running makepkg. It is 2.9 GB and
52# needs roughly 20 GB of free space while it is being built.
53installer="SW32_S32DS_${pkgver}_RFP_D2607_linux.$arch.bin"
54source=("$installer::https://freescaleesd.flexnetoperations.com/337170/607/20142607/SW32_S32DS_3.6.11_RFP_D2609_linux.x86_64.bin?ftpRequestID=4480565751&server=freescaleesd.flexnetoperations.com&ext=.bin")
55sha256sums=('4b4d760f0400080ba59d628f923d45bad936e066638d21862266ce4b154b2ed3')
56# Reloads the udev rules of the debug probes after install, so they are usable
57# without a reboot. The installation itself is made writable in build(), see
58# _allow_extension_installs(), so this scriptlet is only about udev. makepkg
59# only embeds it when it is declared here, the $pkgname.install of the start
60# directory is not picked up implicitly.
61install=s32-design-studio.install
62
63_installdir="/opt/$pkgname"
64_scratchdir="s32ds-build"
65
66# $srcdir only exists once the PKGBUILD has been sourced and makepkg sources it
67# again before package(), so no path is resolved at the top level and both
68# functions have to ask for the layout of the scratch area themselves.
69_stage_paths() {
70 _builddir="$srcdir/$_scratchdir"
71 _stage="$_builddir$_installdir/S32DS"
72 _fakehome="$_builddir/home"
73 _iatemp="$_builddir/ia-temp"
74 _sandbox="$_builddir/bin"
75}
76
77# The vendor installer is an InstallAnywhere 22 self extractor. A few of its
78# actions cannot be influenced from the response file, so the installer is run
79# inside a sandbox that keeps every side effect inside the build directory:
80#
81# * IATEMPDIR/HOME/TMPDIR are redirected, otherwise ~2.9 GB are unpacked into
82# /tmp (or $HOME when /tmp is too small) and desktop entries are written to
83# the real home directory of the build user.
84# * A response file instead of the interactive panels, so the build is
85# reproducible.
86# * TYPICAL=0 plus explicit component switches. With TYPICAL=1 the installer
87# forces INSTALL_PNE_DEBUGGER_DRIVERS and INSTALL_SEGGER_DRIVERS back to 1
88# and then runs `sudo ./inst_drivers_temp.sh`, which copies udev rules and
89# libraries into the running system.
90# * sudo, pkexec and friends are stubbed out as a second line of defence, in
91# case a future installer revision adds another privileged action.
92_normalize_permissions() {
93 local root=$1 f magic
94
95 find "$root" -type d -exec chmod 0755 {} +
96 while IFS= read -r -d '' f; do
97 magic=
98 read -r -N 16 magic < "$f" 2>/dev/null || true
99 case $magic in
100 # native binaries, shared objects and scripts keep their exec bit
101 $'\177ELF'*|'#!'*) chmod 0755 "$f" ;;
102 *) chmod 0644 "$f" ;;
103 esac
104 done < <(find "$root" -type f -print0)
105}
106
107# S32 Design Studio installs extensions into its own installation directory, and
108# that is what the metadata of the NXP update site asks for. Every extension
109# pack carries instructions like
110#
111# com.nxp.s32ds.ext.rcp.p2.native.install(source:@artifact,
112# target:${installFolder}/../S32DS/build_tools/gcc_v10.2,overwrite:true);
113#
114# which org.eclipse.equinox.internal.p2.touchpoint.natives.actions.CopyAction
115# runs as mkdirs() of the parent of the target followed by a plain
116# FileOutputStream on the target itself. The first needs write permission on
117# the directory, the second on a file that often already exists, so a tree that
118# is read only for the user running the IDE fails with
119#
120# Target: Path /opt/s32-design-studio/.../gcc-9.2-arm32-eabi could not be created
121#
122# for every toolchain, debugger, help and pack install. Across the 28
123# repositories of the update site all 512 path expressions resolve to
124# S32DS/{build_tools,config,examples,help,integration,software,tools}, the
125# S32DS directory itself and the p2 managed directories below eclipse, so the
126# whole tree is made writable here.
127#
128# a+rwX rather than a dedicated group: the group would have to be created by an
129# install scriptlet, since makepkg can only record ownership as numbers and the
130# gid of a group that does not exist yet differs from machine to machine, and a
131# group every user has to be added to is a step that is easy to forget and
132# impossible to debug from the IDE. NXP's own Linux image ships the
133# installation world writable, chmod -R 777, for the same reason. Ownership
134# stays with root and nothing else in the package is touched.
135_allow_extension_installs() {
136 local root=$1
137
138 # X only adds the execute bit to directories and to files that already have
139 # one, so binaries stay executable and data files stay non-executable
140 find "$root" -type d -exec chmod a+rwX {} +
141 find "$root" -type f -exec chmod a+rw {} +
142}
143
144# NXP builds the product on a Jenkins agent and bakes the paths of that agent
145# into the p2 metadata it ships. The "Bundle pool", the download cache and the
146# product repository registered in the preferences of the installation point at
147# /opt/jenkins/..., and so do the 84 references inside the gzipped profile state
148# (the profile property that holds the location of the download cache). p2
149# therefore does not see the ~1600 bundles that are already installed, goes
150# looking for their artifacts in the update sites, and every extension install
151# ends with
152#
153# No repository found containing: binary,com.nxp.s32ds.brc.arm....
154#
155# because the update sites do not carry the exact versions that are installed.
156# The build paths are replaced with the location of this package. The target is
157# a parameter so that the rewrite can be exercised outside of /opt.
158_relocate_p2() {
159 local target=$1 prefs profile build_pool build_repo
160 local profiles="$_stage/eclipse/p2/org.eclipse.equinox.p2.engine/profileRegistry/DefaultProfile.profile"
161
162 prefs="$_stage/eclipse/p2/org.eclipse.equinox.p2.engine/.settings/org.eclipse.equinox.p2.artifact.repository.prefs"
163
164 # the product directory of the build agent and the repository it was built
165 # from, read back out of the preferences of the installation (the URIs are
166 # stored with the colon of the scheme escaped)
167 build_pool=$(sed -n 's|.*uri=file\\:\(.*\)/eclipse/*$|\1|p' "$prefs" | head -n1)
168 build_repo=$(sed -n 's|.*uri=file\\:\(.*target/repository\)/*$|\1|p' "$prefs" | head -n1)
169
170 if [ -z "$build_pool" ] || [ -z "$build_repo" ]; then
171 error "the build paths of the vendor p2 metadata are not in $prefs"
172 fi
173
174 # everything the build agent registered that this package can serve itself
175 # becomes the shipped eclipse directory: it holds the bundle pool, the pool
176 # metadata (artifacts.xml) and, once an extension has been installed, the
177 # directories of the new artifact classes. The repository the product was
178 # built from is dropped instead, it is not part of the installation: NXP
179 # ships the metadata of the product nowhere and a registered metadata
180 # repository that cannot be loaded makes p2 refuse to install anything.
181 for prefs in \
182 "$_stage/eclipse/p2/org.eclipse.equinox.p2.engine/.settings/org.eclipse.equinox.p2.artifact.repository.prefs" \
183 "$_stage/eclipse/p2/org.eclipse.equinox.p2.engine/.settings/org.eclipse.equinox.p2.metadata.repository.prefs"; do
184 sed -i -e '/^repositories\/.*target_repository\//d' \
185 -e "s|$build_pool|$target|g" -e "s|$build_repo|$target|g" "$prefs"
186 done
187
188 for profile in "$profiles"/*.profile.gz; do
189 gzip -dc "$profile" |
190 sed -e "s|$build_pool|$target|g" -e "s|$build_repo|$target|g" |
191 gzip -9 > "$profile.new"
192 mv "$profile.new" "$profile"
193 done
194
195 # The vendor ships the download cache of p2 as an empty directory. p2 wants
196 # to write there as its first action and the directory has to exist in a fresh
197 # install, so it is put back if the payload does not have it.
198 if [ ! -d "$_stage/eclipse/p2/org.eclipse.equinox.p2.core/cache" ]; then
199 install -d "$_stage/eclipse/p2/org.eclipse.equinox.p2.core/cache"
200 fi
201}
202
203build() {
204 local tool
205
206 cd "$srcdir"
207 _stage_paths
208 rm -rf "$_builddir"
209 mkdir -p "$_stage" "$_fakehome/Desktop" "$_iatemp" "$_sandbox"
210
211 for tool in sudo pkexec pkaction gksudo gksu kdesu xhost; do
212 printf '#!/bin/sh\nexit 1\n' > "$_sandbox/$tool"
213 chmod 0755 "$_sandbox/$tool"
214 done
215
216 cat > "$_builddir/installer.properties" <<-EOF
217 INSTALLER_UI=silent
218 UPGRADE_INSTALL=0
219 USER_INSTALL_DIR=$_stage
220 USER_HOME=$_fakehome
221 DESKTOP=$_fakehome/Desktop
222 USER_SHORTCUTS=$_fakehome/Desktop
223 TYPICAL=0
224 INSTALL_GCC=1
225 INSTALL_PNE_DEBUGGER=1
226 INSTALL_PNE_DEBUGGER_DRIVERS=0
227 INSTALL_S32DEBUGGER=1
228 INSTALL_S32DEBUGGER_DRIVERS=0
229 INSTALL_SEGGER_DRIVERS=0
230 EOF
231
232 echo "Running the NXP installer"
233 HOME="$_fakehome" \
234 XDG_CONFIG_HOME="$_fakehome/.config" \
235 XDG_CACHE_HOME="$_fakehome/.cache" \
236 XDG_DATA_HOME="$_fakehome/.local/share" \
237 TMPDIR="$_builddir" \
238 IATEMPDIR="$_iatemp" \
239 PATH="$_sandbox:$PATH" \
240 sh "./$installer" -i silent -f "$_builddir/installer.properties" \
241 > "$_builddir/installer.log" 2>&1 || {
242 tail -n 40 "$_builddir/installer.log" >&2
243 error "the NXP installer failed, see $_builddir/installer.log"
244 }
245
246 if [ ! -x "$_stage/eclipse/s32ds" ]; then
247 error "the NXP installer did not produce $_stage/eclipse/s32ds"
248 fi
249
250 # pacman owns the lifecycle of the package, so the InstallAnywhere
251 # uninstaller, its registry and its logs have no place in it. A copy of the
252 # install log is kept in the build directory, it is the only record of what
253 # the installer did.
254 find "$_stage/_S32 Design Studio for S32 Platform ${pkgver}_installation/Logs" \
255 -type f -name '*.log' -exec cp {} "$_builddir/vendor-install.log" \; 2>/dev/null
256 rm -rf "$_stage/_S32 Design Studio for S32 Platform ${pkgver}_installation"
257
258 # The installer bakes its own installation directory into the launcher
259 # configuration. Only the java.library.path line refers to an absolute
260 # path, the rest of s32ds.ini is relative to the eclipse directory.
261 sed -i \
262 "s|^-Djava.library.path=.*|-Djava.library.path=$_installdir/S32DS/cll/x64:$_installdir/S32DS/tools/S32Trace/bin:../S32DS/cll/x64:../S32DS/tools/S32Trace/bin|" \
263 "$_stage/eclipse/s32ds.ini"
264
265 # The vendor p2 metadata still points at the build agent of NXP, see
266 # _relocate_p2().
267 _relocate_p2 "$_installdir"
268
269 # The installer runs `chmod a+rwx -R` over everything it unpacks.
270 _normalize_permissions "$_stage"
271
272 # and the IDE then installs extensions into the result, see
273 # _allow_extension_installs().
274 _allow_extension_installs "$_stage"
275}
276
277package() {
278 _stage_paths
279
280 # $srcdir and $pkgdir live in the same build directory, so the staging tree
281 # is moved instead of copied.
282 install -d "$pkgdir/opt"
283 mv "$_stage" "$pkgdir$_installdir"
284
285 install -Dm755 "$startdir/s32ds" "$pkgdir/usr/bin/s32ds"
286 # installed executable on request: the entry point has to be a usable
287 # regular file, not a symlink into /opt
288 install -Dm755 "$startdir/s32-design-studio.desktop" \
289 "$pkgdir/usr/share/applications/s32-design-studio.desktop"
290 install -Dm644 "$startdir/60-s32-design-studio.rules" \
291 "$pkgdir/usr/lib/udev/rules.d/60-s32-design-studio.rules"
292 install -Dm644 "$pkgdir$_installdir/nxpicon.png" \
293 "$pkgdir/usr/share/icons/hicolor/48x48/apps/s32-design-studio.png"
294 install -Dm644 "$startdir/LICENSE.PKGBUILD" \
295 "$pkgdir/usr/share/licenses/$pkgname/LICENSE.PKGBUILD"
296}
297

Scan history

Scanned at (UTC)SeverityRules
2026-09-28 17:23:17 Medium 3
2026-09-28 17:21:20 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion