salt-onedir
maintainer spookfish
· 3 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package installs additional pip packages only if the user sets an environment variable, which is a user-controlled opt-in and does not automatically fetch untrusted code; the main binaries come from official GitHub releases.
Triggered rules
LOW
AI review of an ambiguous pattern
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (qwen/qwen3-235b-a22b-07-25) reviewed it and judged it LOW (confidence 95%): The package installs additional pip packages only if the user sets an environment variable, which is a user-controlled opt-in and does not automatically fetch untrusted code; the main binaries come from official GitHub releases.
-
PKGBUILD:63
"${onedir}"/bin/pip3 install ${SALT_ADDITIONAL_PIP_PACKAGES}
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Fabian Leditzky <spookfish@ldsoft.dev>
2
# Maintainer: Sven Rueß <github@sven-ruess.de>
3
4
# Parts of this PKGBUILD are based on the PKGBUILD for extra/salt
5
6
# NOTES:
7
# - Set env var SALT_ADDITIONAL_PIP_PACKAGES for additional onedir pip packages.
8
# Example: SALT_ADDITIONAL_PIP_PACKAGES='gitpython pynacl' makepkg
9
# The additional packages are listed in the package description.
10
# - makepkg will complain about packaging issues because the .pyc files (python bytecode)
11
# contain the absolute path of the resource during the build, meaning $srcdir references
12
# are found in the final build. This does not appear to cause any real issues.
13
#
14
15
pkgname=salt-onedir
16
provides=('salt')
17
pkgver=3008.2
18
pkgrel=1
19
pkgdesc="Central system and configuration manager (onedir installation +[${SALT_ADDITIONAL_PIP_PACKAGES}])"
20
arch=('x86_64' 'aarch64')
21
url='https://saltproject.io'
22
license=('Apache-2.0')
23
replaces=('salt-zmq' 'salt-raet')
24
conflicts=('salt-zmq' 'salt-raet' 'salt')
25
depends=()
26
makedepends=('rsync')
27
optdepends=('dmidecode: decode SMBIOS/DMI tables')
28
backup=('etc/logrotate.d/salt'
29
'etc/salt/master'
30
'etc/salt/minion')
31
32
source_x86_64=("https://github.com/saltstack/salt/releases/download/v${pkgver}/salt-${pkgver}-onedir-linux-x86_64.tar.xz")
33
sha256sums_x86_64=('e968745d2b122ea9d5a16f286b5aaef086347edf293ecdda38ea27f67da89d8b')
34
35
source_aarch64=("https://github.com/saltstack/salt/releases/download/v${pkgver}/salt-${pkgver}-onedir-linux-arm64.tar.xz")
36
sha256sums_aarch64=('d4ae948582fc0f32d2feaa741daf49d44537a6ab7e97074b594c3f92c951a9eb')
37
38
# The source tarball is downloaded because we need various files from pkg/common that are not included in the onedir tarball
39
source=("https://github.com/saltstack/salt/releases/download/v${pkgver}/salt-${pkgver}.tar.gz"
40
salt.logrotate
41
0000-services.patch)
42
sha256sums=('44a1e206a955bf57aaffbe3f1dfb5f4476c9442d64f3a103ce7ac0aa68bfa907'
43
'abecc3c1be124c4afffaaeb3ba32b60dfee8ba6dc32189edfa2ad154ecb7a215'
44
'6eb7d8840c40da7070167d3c742e7337c45f80d639fb7ef72f196fcaa2843469')
45
46
47
prepare() {
48
# Extracted salt source tarball
49
saltsrc="${srcdir}/salt-${pkgver}"
50
cd "${saltsrc}"
51
52
# patch services to run /opt/salt/bin/* binaries directly
53
# not strictly required as we symlink into /usr/bin
54
patch -Np1 -i ../0000-services.patch
55
}
56
57
build() {
58
# Extracted salt-onedir tarball
59
onedir="${srcdir}/salt"
60
61
# Add additional python deps for Salt
62
if [[ -n ${SALT_ADDITIONAL_PIP_PACKAGES} ]]; then
63
"${onedir}"/bin/pip3 install ${SALT_ADDITIONAL_PIP_PACKAGES}
64
fi
65
}
66
67
package() {
68
# Extracted salt-onedir tarball
69
onedir="${srcdir}/salt"
70
# Extracted salt source tarball
71
saltsrc="${srcdir}/salt-${pkgver}"
72
73
# Copy over our onedir package
74
mkdir "${pkgdir}"/opt
75
rsync -a "${onedir}/" "${pkgdir}"/opt/salt
76
77
# Create relative symlinks in /usr/bin for all relevant binaries
78
# These will link into the /opt/salt/bin directory
79
mkdir "${pkgdir}"/usr/bin -p
80
for bin in "${pkgdir}"/opt/salt/{salt,spm}*; do
81
ln -sr "${bin}" "${pkgdir}"/usr/bin
82
done
83
84
install -Dm644 salt.logrotate "$pkgdir"/etc/logrotate.d/salt
85
86
# Install various files from the source tarball into the package
87
cd "${saltsrc}"
88
89
# default config
90
install -v -Dm644 conf/master "$pkgdir/etc/salt/master"
91
install -v -Dm644 conf/minion "$pkgdir/etc/salt/minion"
92
93
# systemd services
94
for _svc in salt-master.service salt-syndic.service salt-minion.service salt-api.service; do
95
install -v -Dm644 pkg/common/$_svc "$pkgdir/usr/lib/systemd/system/$_svc"
96
done
97
98
# completions
99
# For some reason there is no more pkg/common/salt.bash
100
# The rpm one has the same content.
101
install -v -Dm644 pkg/rpm/salt.bash "$pkgdir/usr/share/bash-completion/completions/salt"
102
install -v -Dm644 pkg/common/salt.zsh "$pkgdir/usr/share/zsh/site-functions/_salt"
103
install -v -Dm644 -t "$pkgdir/usr/share/fish/vendor_completions.d" pkg/common/fish-completions/*
104
}
105
106
# vim:set ts=2 sw=2 et:
107
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 1 |
| 2026-08-02 00:16:08 | LOW | 1 |
| 2026-08-01 00:11:18 | LOW | 1 |
| 2026-07-31 00:14:10 | LOW | 1 |
| 2026-07-30 00:17:23 | LOW | 1 |
| 2026-07-29 00:25:53 | LOW | 1 |
| 2026-07-28 00:07:28 | LOW | 1 |
| 2026-07-27 00:24:32 | LOW | 1 |
| 2026-07-26 00:07:32 | LOW | 1 |
| 2026-07-25 00:13:44 | LOW | 1 |
| 2026-07-24 00:02:28 | LOW | 1 |
| 2026-07-23 00:14:47 | LOW | 1 |
| 2026-07-22 00:29:32 | LOW | 1 |
| 2026-07-21 00:24:15 | LOW | 1 |
| 2026-07-20 00:19:49 | LOW | 1 |
| 2026-07-19 00:17:08 | LOW | 1 |
| 2026-07-18 00:14:48 | LOW | 1 |
| 2026-07-17 00:06:16 | LOW | 1 |
| 2026-07-16 00:05:41 | LOW | 1 |
| 2026-07-15 00:09:25 | LOW | 1 |