skywire

LOW
maintainer moe_narrow 1 votes scanned 2026-10-08 00:28:03.132797
View on AUR
Why flagged

The flagged pattern involves building a Go project from source using `go install` with a version tag, which is a standard and safe practice for AUR packages; no external untrusted binaries or scripts are downloaded or executed.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The flagged pattern involves building a Go project from source using `go install` with a version tag, which is a standard and safe practice for AUR packages; no external untrusted binaries or scripts are downloaded or executed.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium External install via pipx/uv/poetry/cargo/go/gem alt_pkg_manager_install

A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.

  • PKGBUILD:55 go install -trimpath --ldflags="" --ldflags " -s -w -linkmode external -extldflags '-static' -buildid=" github.com/skycoin/skywire/cmd/skywire@${_ref}

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Moses Narrow <moe_narrow@use.startmail.com>
2_projectname=skycoin
3pkgname=skywire
4_pkgname=${pkgname}
5_githuborg=${FORK:-$_projectname}
6pkgdesc="Software defined networking with public keys. Skycoin.com"
7_pkggopath=github.com/${_githuborg}/${_pkgname}
8pkgver='1.3.99'
9pkgrel='1'
10_rc=''
11#_rc='-pr1'
12_pkgver="${pkgver}${_rc}"
13_tag_ver="v${_pkgver}"
14arch=( 'i686' 'x86_64' 'aarch64' 'armv8' 'armv7' 'armv7l' 'armv7h' 'armv6h' 'armhf' 'armel' 'arm' 'riscv64' )
15url=https://${_pkggopath}
16license=('license-free')
17makedepends=("git" "go>=1.24" "musl" "kernel-headers-musl")
18[[ ${REBUILDUI} == "1" ]] && makedepends=(${makedepends[@]} "npm")
19install=skywire.install
20# /etc/skywire.conf is generated by post_install/postinst on first
21# install only when missing — not shipped by the package, so no
22# backup= entry needed (and no .pacnew dance on upgrade).
23backup=()
24_script=("skywire-autoconfig")
25_desktop=("skywire.desktop" "skywirevpn.desktop" "skywire-tray.desktop")
26_icon=("skywirevpn.png" "skywire.png")
27_service=("skywire.service" "skywire-autoconfig.service" "skywire-sn.service" "skywire-ar.service" "skywire-rf.service" "skywire-tpd.service" "skywire-dmsgd.service" "skywire-dmsg.service" "skywire-sd.service" "dmsgpty-tcp.socket" "dmsgpty-tcp@.service")
28_source=("skywire-bin::git+https://aur.archlinux.org/skywire-bin")
29source=("${_source[@]}")
30#source=("skywire-${_tag_ver}.tar.gz::${url}/archive/refs/tags/${_tag_ver}.tar.gz")
31#"https://raw.githubusercontent.com/skycoin/skywire/develop/dmsghttp-config.json"
32#"all_servers.json"::"https://dmsgd.skywire.skycoin.com/dmsg-discovery/all_servers")
33sha256sums=('SKIP')
34
35_binaryscript=("skywire-cli" "skywire-visor")
36
37
38build() {
39mkdir -p "${srcdir}"/go/bin || true
40export GOPATH="${srcdir}/go"
41export GOBIN="${GOPATH}/bin"
42export GOOS=linux
43export CGO_ENABLED=1 #default anyways
44#use musl-gcc for static compilation
45export CC=musl-gcc
46_build
47}
48#_build function - used in build variants
49_build() {
50# _goref selects which module version `go install` fetches: the release
51# tag (v${pkgver}) by default; git.PKGBUILD overrides it to "develop" to
52# build the develop tip. Keep the log line and the command in sync.
53_ref="${_goref:-v${pkgver}}"
54_msg2 "go install -trimpath --ldflags=\"\" --ldflags \" -s -w -linkmode external -extldflags '-static' -buildid=\" github.com/skycoin/skywire/cmd/skywire@${_ref}"
55go install -trimpath --ldflags="" --ldflags " -s -w -linkmode external -extldflags '-static' -buildid=" github.com/skycoin/skywire/cmd/skywire@${_ref}
56_msg2 'creating launcher scripts'
57echo -e '#!/bin/bash\nexec /opt/skywire/bin/skywire cli "$@"' > "${GOBIN}/skywire-cli"
58echo -e '#!/bin/bash\nexec /opt/skywire/bin/skywire visor "$@"' > "${GOBIN}/skywire-visor"
59#binary transparency
60cd "$GOBIN" || exit
61_msg2 'binary sha256sum'
62sha256sum skywire
63}
64
65package() {
66#declare the _pkgdir and systemd directory
67_pkgdir="${pkgdir}"
68_systemddir="usr/lib/systemd/system"
69_skywirebin="skywire-bin/"
70_package
71if command -v tree &> /dev/null ; then
72_msg2 'package tree'
73 tree -a ${pkgdir}
74fi
75}
76#_package function - used in build variants
77_package() {
78_dir="opt/skywire"
79_apps="${_dir}/apps"
80_bin="${_dir}/bin"
81_scriptsdir="${_dir}/scripts"
82_msg2 'creating dirs'
83mkdir -p "${_pkgdir}/usr/bin"
84mkdir -p "${_pkgdir}/${_dir}/bin"
85mkdir -p "${_pkgdir}/${_dir}/scripts"
86mkdir -p "${_pkgdir}/${_systemddir}"
87_msg2 'installing scripts and binaries'
88install -Dm755 "${GOBIN}/skywire" "${_pkgdir}/${_bin}/"
89ln -rTsf "${_pkgdir}/${_bin}/skywire" "${_pkgdir}/usr/bin/skywire"
90install -Dm755 "${GOBIN}/skywire-cli" "${_pkgdir}/${_bin}/"
91ln -rTsf "${_pkgdir}/${_bin}/skywire-cli" "${_pkgdir}/usr/bin/skywire-cli"
92install -Dm755 "${GOBIN}/skywire-visor" "${_pkgdir}/${_bin}/"
93ln -rTsf "${_pkgdir}/${_bin}/skywire-visor" "${_pkgdir}/usr/bin/skywire-visor"
94for _i in "${_script[@]}" ; do
95 _msg3 ${_i}
96 install -Dm755 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/${_scriptsdir}/${_i}"
97 ln -rTsf "${_pkgdir}/${_scriptsdir}/${_i}" "${_pkgdir}/usr/bin/${_i}"
98done
99_msg2 'Installing systemd services'
100for _i in "${_service[@]}" ; do
101 _msg3 ${_i}
102 install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/${_systemddir}/${_i}"
103 install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/etc/skel/.config/systemd/user/${_i}"
104done
105
106# Pull the user-mode unit and sysusers/tmpfiles declarations from
107# the skywire-bin git checkout (same source tree). Keeps the file
108# shapes identical across both AUR packages — only the build step
109# differs (this one builds from source, skywire-bin uses upstream
110# release tarballs).
111_msg3 'skywire-user.service → /usr/lib/systemd/user/skywire.service'
112install -Dm644 "${srcdir}/${_skywirebin}skywire-user.service" "${_pkgdir}/usr/lib/systemd/user/skywire.service"
113install -Dm644 "${srcdir}/${_skywirebin}skywire-user.service" "${_pkgdir}/etc/skel/.config/systemd/user/skywire.service"
114
115_msg2 'Installing sysusers.d / tmpfiles.d (declarative user + dirs)'
116install -Dm644 "${srcdir}/${_skywirebin}skywire.sysusers" "${_pkgdir}/usr/lib/sysusers.d/skywire.conf"
117install -Dm644 "${srcdir}/${_skywirebin}skywire.tmpfiles" "${_pkgdir}/usr/lib/tmpfiles.d/skywire.conf"
118
119# /etc/skywire.conf is INTENTIONALLY not shipped by the package.
120# The postinst (deb) and post_install (arch) hooks generate it on
121# first install via `skywire cli config gen -pqQ /etc/skywire.conf`,
122# but only if it's missing — so operator edits survive upgrades
123# without a conffile / .pacnew dance.
124
125_msg2 'installing desktop files and icons'
126mkdir -p "${_pkgdir}/usr/share/applications/" "${_pkgdir}/usr/share/icons/hicolor/48x48/apps/"
127for _i in "${_desktop[@]}" ; do
128 _msg3 ${_i}
129 install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/usr/share/applications/${_i}"
130done
131# The tray is ALSO an XDG autostart entry so it launches in the user's desktop
132# session on login (the visor runs as a background service; the tray controls it
133# over RPC — see `skywire visor --systray-only`). The app-menu copy above lets the
134# user start it the first time (a root package install can't reach the already-
135# running session); autostart handles every login after.
136install -Dm644 "${srcdir}/${_skywirebin}skywire-tray.desktop" "${_pkgdir}/etc/xdg/autostart/skywire-tray.desktop"
137for _i in "${_icon[@]}" ; do
138 _msg3 ${_i}
139 install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/usr/share/icons/hicolor/48x48/apps/${_i}"
140done
141
142}
143
144_msg2() {
145(( QUIET )) && return
146local mesg=$1; shift
147printf "${BLUE} ->${ALL_OFF}${BOLD} ${mesg}${ALL_OFF}\n" "$@"
148}
149
150_msg3() {
151(( QUIET )) && return
152local mesg=$1; shift
153printf "${BLUE} -->${ALL_OFF} ${mesg}${ALL_OFF}\n" "$@"
154}
155
156# _gen_deb_scripts writes the canonical postinst.sh / prerm.sh /
157# postrm.sh under ${srcdir}/ for deb-package consumption. Shared
158# between skywire/deb.PKGBUILD and skywire-bin/cc.deb.PKGBUILD so
159# the two deb consumers stay in sync. Mirrored verbatim in
160# skywire-bin/PKGBUILD; keep both copies in sync.
161#
162# Idempotent: safe to call multiple times. Writes the same files
163# every time.
164#
165# Semantics (matches skywire.install on the arch side):
166# - postinst: systemd-sysusers + tmpfiles, setcap on the unified
167# binary, then idempotent `skywire autoconfig` (SK-preserving).
168# - prerm: case-aware. remove|deconfigure stops+disables;
169# upgrade|failed-upgrade only stops. Never touches /opt/skywire.
170# - postrm: case-aware. Only `purge` nukes /opt/skywire + drop-ins.
171# remove keeps state for possible reinstall.
172_gen_deb_scripts() {
173 cat > "${srcdir}/postinst.sh" <<'POSTINST_EOF'
174#!/bin/bash
175set -e
176
177# Process the sysusers.d / tmpfiles.d files we shipped, so the
178# _skywire user exists and /opt/skywire is owned by them BEFORE
179# autoconfig runs and tries to write into the dir. systemd-sysusers
180# creates the user; systemd-tmpfiles --create applies the d/Z lines.
181if command -v systemd-sysusers >/dev/null 2>&1 ; then
182 systemd-sysusers /usr/lib/sysusers.d/skywire.conf 2>/dev/null || true
183fi
184if command -v systemd-tmpfiles >/dev/null 2>&1 ; then
185 systemd-tmpfiles --create /usr/lib/tmpfiles.d/skywire.conf 2>/dev/null || true
186fi
187
188# File caps for VPN apps + low-port hypervisor binds. Survives
189# User= changes; required for the user-mode unit (which can't be
190# granted ambient caps).
191if command -v setcap >/dev/null 2>&1 ; then
192 setcap 'cap_net_admin,cap_net_bind_service+eip' /opt/skywire/bin/skywire 2>/dev/null || true
193fi
194
195# Generate the canonical /etc/skywire.conf template ONLY if it's
196# missing. Operator edits (SK, HYPERVISORPKS, SKYWIRE_USER, etc.)
197# are preserved by default across upgrades because the package no
198# longer ships the file — there's nothing for dpkg to overwrite.
199[[ ! -f /etc/skywire.conf ]] && skywire cli config gen -pqQ /etc/skywire.conf
200
201skywire autoconfig
202
203# On upgrade, restart every package-shipped service that's
204# currently active. try-restart is a noop on inactive units, so
205# operators who haven't enabled every shipped unit don't see
206# spurious starts. autoconfig already touched skywire.service via
207# its restart-if-active path; try-restart on a just-restarted
208# service is harmless.
209for _unit in skywire.service skywire-autoconfig.service \
210 skywire-sn.service skywire-ar.service \
211 skywire-rf.service skywire-tpd.service \
212 skywire-dmsgd.service skywire-dmsg.service \
213 skywire-sd.service dmsgpty-tcp.socket ; do
214 systemctl try-restart "$_unit" 2>/dev/null || true
215done
216POSTINST_EOF
217
218 cat > "${srcdir}/prerm.sh" <<'PRERM_EOF'
219#!/bin/bash
220set -e
221case "$1" in
222 remove|deconfigure)
223 # Genuine uninstall. Stop and disable the units but leave
224 # /opt/skywire alone: an operator running `apt remove`
225 # (not `apt purge`) may reinstall later and expect their
226 # identity / hypervisor accounts intact. postrm with
227 # $1=purge is where the actual nuke happens.
228 for _unit in skywire.service skywire-autoconfig.service \
229 skywire-sn.service skywire-ar.service \
230 skywire-rf.service skywire-tpd.service \
231 skywire-dmsgd.service skywire-dmsg.service \
232 skywire-sd.service dmsgpty-tcp.socket ; do
233 systemctl stop "$_unit" 2>/dev/null || true
234 systemctl disable "$_unit" 2>/dev/null || true
235 done
236 ;;
237 upgrade|failed-upgrade)
238 # No-op on upgrade. dpkg replaces files via unlink+rename,
239 # so running processes keep the old binary inode mapped
240 # until postinst's try-restart loop picks them up on the
241 # new binary.
242 ;;
243esac
244PRERM_EOF
245
246 cat > "${srcdir}/postrm.sh" <<'POSTRM_EOF'
247#!/bin/bash
248set -e
249case "$1" in
250 purge)
251 rm -rf /opt/skywire
252 rm -f /etc/systemd/system/skywire.service.d/skywire-user.conf
253 rmdir --ignore-fail-on-non-empty /etc/systemd/system/skywire.service.d 2>/dev/null || true
254 ;;
255 remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
256 # nothing: keep state for possible reinstall, and let the
257 # in-progress upgrade complete normally.
258 ;;
259esac
260systemctl daemon-reload 2>/dev/null || true
261POSTRM_EOF
262}
263

Changes since previous scan

--- PKGBUILD @ 2026-09-28 00:28
+++ PKGBUILD @ 2026-10-08 00:28
@@ -5,7 +5,7 @@
_githuborg=${FORK:-$_projectname}
pkgdesc="Software defined networking with public keys. Skycoin.com"
_pkggopath=github.com/${_githuborg}/${_pkgname}
-pkgver='1.3.96'
+pkgver='1.3.99'
pkgrel='1'
_rc=''
#_rc='-pr1'

Scan history

Scanned at (UTC)SeverityRules
2026-10-08 00:28:03 Low 2
2026-10-07 00:21:34 Low 2
2026-10-05 23:40:58 Medium 1
2026-09-28 00:28:32 Clean 2
2026-09-27 19:19:18 Medium 1
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 19:30:45 Medium 1
2026-09-19 00:25:36 Low 2
2026-09-18 23:29:28 Medium 1
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 23:20:44 Medium 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion