skywire
The flagged pattern involves building a Go project from source using `go install` with a version tag, which is a standard and safe practice for AUR packages; no external untrusted binaries or scripts are downloaded or executed.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The flagged pattern involves building a Go project from source using `go install` with a version tag, which is a standard and safe practice for AUR packages; no external untrusted binaries or scripts are downloaded or executed.
1 higher static finding superseded - not the current verdict (shown for transparency)
alt_pkg_manager_install
A non-pip/npm package manager (pipx, uv, poetry, cargo install, go install, gem, conda…) fetches and builds an external package at build time, outside source=() and makepkg's checksums.
-
PKGBUILD:55
go install -trimpath --ldflags="" --ldflags " -s -w -linkmode external -extldflags '-static' -buildid=" github.com/skycoin/skywire/cmd/skywire@${_ref}
PKGBUILD
1 offending line(s) highlighted# Maintainer: Moses Narrow <moe_narrow@use.startmail.com>
_projectname=skycoin
pkgname=skywire
_pkgname=${pkgname}
_githuborg=${FORK:-$_projectname}
pkgdesc="Software defined networking with public keys. Skycoin.com"
_pkggopath=github.com/${_githuborg}/${_pkgname}
pkgver='1.3.99'
pkgrel='1'
_rc=''
#_rc='-pr1'
_pkgver="${pkgver}${_rc}"
_tag_ver="v${_pkgver}"
arch=( 'i686' 'x86_64' 'aarch64' 'armv8' 'armv7' 'armv7l' 'armv7h' 'armv6h' 'armhf' 'armel' 'arm' 'riscv64' )
url=https://${_pkggopath}
license=('license-free')
makedepends=("git" "go>=1.24" "musl" "kernel-headers-musl")
[[ ${REBUILDUI} == "1" ]] && makedepends=(${makedepends[@]} "npm")
install=skywire.install
# /etc/skywire.conf is generated by post_install/postinst on first
# install only when missing — not shipped by the package, so no
# backup= entry needed (and no .pacnew dance on upgrade).
backup=()
_script=("skywire-autoconfig")
_desktop=("skywire.desktop" "skywirevpn.desktop" "skywire-tray.desktop")
_icon=("skywirevpn.png" "skywire.png")
_service=("skywire.service" "skywire-autoconfig.service" "skywire-sn.service" "skywire-ar.service" "skywire-rf.service" "skywire-tpd.service" "skywire-dmsgd.service" "skywire-dmsg.service" "skywire-sd.service" "dmsgpty-tcp.socket" "dmsgpty-tcp@.service")
_source=("skywire-bin::git+https://aur.archlinux.org/skywire-bin")
source=("${_source[@]}")
#source=("skywire-${_tag_ver}.tar.gz::${url}/archive/refs/tags/${_tag_ver}.tar.gz")
#"https://raw.githubusercontent.com/skycoin/skywire/develop/dmsghttp-config.json"
#"all_servers.json"::"https://dmsgd.skywire.skycoin.com/dmsg-discovery/all_servers")
sha256sums=('SKIP')
_binaryscript=("skywire-cli" "skywire-visor")
build() {
mkdir -p "${srcdir}"/go/bin || true
export GOPATH="${srcdir}/go"
export GOBIN="${GOPATH}/bin"
export GOOS=linux
export CGO_ENABLED=1 #default anyways
#use musl-gcc for static compilation
export CC=musl-gcc
_build
}
#_build function - used in build variants
_build() {
# _goref selects which module version `go install` fetches: the release
# tag (v${pkgver}) by default; git.PKGBUILD overrides it to "develop" to
# build the develop tip. Keep the log line and the command in sync.
_ref="${_goref:-v${pkgver}}"
_msg2 "go install -trimpath --ldflags=\"\" --ldflags \" -s -w -linkmode external -extldflags '-static' -buildid=\" github.com/skycoin/skywire/cmd/skywire@${_ref}"
go install -trimpath --ldflags="" --ldflags " -s -w -linkmode external -extldflags '-static' -buildid=" github.com/skycoin/skywire/cmd/skywire@${_ref}
_msg2 'creating launcher scripts'
echo -e '#!/bin/bash\nexec /opt/skywire/bin/skywire cli "$@"' > "${GOBIN}/skywire-cli"
echo -e '#!/bin/bash\nexec /opt/skywire/bin/skywire visor "$@"' > "${GOBIN}/skywire-visor"
#binary transparency
cd "$GOBIN" || exit
_msg2 'binary sha256sum'
sha256sum skywire
}
package() {
#declare the _pkgdir and systemd directory
_pkgdir="${pkgdir}"
_systemddir="usr/lib/systemd/system"
_skywirebin="skywire-bin/"
_package
if command -v tree &> /dev/null ; then
_msg2 'package tree'
tree -a ${pkgdir}
fi
}
#_package function - used in build variants
_package() {
_dir="opt/skywire"
_apps="${_dir}/apps"
_bin="${_dir}/bin"
_scriptsdir="${_dir}/scripts"
_msg2 'creating dirs'
mkdir -p "${_pkgdir}/usr/bin"
mkdir -p "${_pkgdir}/${_dir}/bin"
mkdir -p "${_pkgdir}/${_dir}/scripts"
mkdir -p "${_pkgdir}/${_systemddir}"
_msg2 'installing scripts and binaries'
install -Dm755 "${GOBIN}/skywire" "${_pkgdir}/${_bin}/"
ln -rTsf "${_pkgdir}/${_bin}/skywire" "${_pkgdir}/usr/bin/skywire"
install -Dm755 "${GOBIN}/skywire-cli" "${_pkgdir}/${_bin}/"
ln -rTsf "${_pkgdir}/${_bin}/skywire-cli" "${_pkgdir}/usr/bin/skywire-cli"
install -Dm755 "${GOBIN}/skywire-visor" "${_pkgdir}/${_bin}/"
ln -rTsf "${_pkgdir}/${_bin}/skywire-visor" "${_pkgdir}/usr/bin/skywire-visor"
for _i in "${_script[@]}" ; do
_msg3 ${_i}
install -Dm755 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/${_scriptsdir}/${_i}"
ln -rTsf "${_pkgdir}/${_scriptsdir}/${_i}" "${_pkgdir}/usr/bin/${_i}"
done
_msg2 'Installing systemd services'
for _i in "${_service[@]}" ; do
_msg3 ${_i}
install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/${_systemddir}/${_i}"
install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/etc/skel/.config/systemd/user/${_i}"
done
# Pull the user-mode unit and sysusers/tmpfiles declarations from
# the skywire-bin git checkout (same source tree). Keeps the file
# shapes identical across both AUR packages — only the build step
# differs (this one builds from source, skywire-bin uses upstream
# release tarballs).
_msg3 'skywire-user.service → /usr/lib/systemd/user/skywire.service'
install -Dm644 "${srcdir}/${_skywirebin}skywire-user.service" "${_pkgdir}/usr/lib/systemd/user/skywire.service"
install -Dm644 "${srcdir}/${_skywirebin}skywire-user.service" "${_pkgdir}/etc/skel/.config/systemd/user/skywire.service"
_msg2 'Installing sysusers.d / tmpfiles.d (declarative user + dirs)'
install -Dm644 "${srcdir}/${_skywirebin}skywire.sysusers" "${_pkgdir}/usr/lib/sysusers.d/skywire.conf"
install -Dm644 "${srcdir}/${_skywirebin}skywire.tmpfiles" "${_pkgdir}/usr/lib/tmpfiles.d/skywire.conf"
# /etc/skywire.conf is INTENTIONALLY not shipped by the package.
# The postinst (deb) and post_install (arch) hooks generate it on
# first install via `skywire cli config gen -pqQ /etc/skywire.conf`,
# but only if it's missing — so operator edits survive upgrades
# without a conffile / .pacnew dance.
_msg2 'installing desktop files and icons'
mkdir -p "${_pkgdir}/usr/share/applications/" "${_pkgdir}/usr/share/icons/hicolor/48x48/apps/"
for _i in "${_desktop[@]}" ; do
_msg3 ${_i}
install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/usr/share/applications/${_i}"
done
# The tray is ALSO an XDG autostart entry so it launches in the user's desktop
# session on login (the visor runs as a background service; the tray controls it
# over RPC — see `skywire visor --systray-only`). The app-menu copy above lets the
# user start it the first time (a root package install can't reach the already-
# running session); autostart handles every login after.
install -Dm644 "${srcdir}/${_skywirebin}skywire-tray.desktop" "${_pkgdir}/etc/xdg/autostart/skywire-tray.desktop"
for _i in "${_icon[@]}" ; do
_msg3 ${_i}
install -Dm644 "${srcdir}/${_skywirebin}${_i}" "${_pkgdir}/usr/share/icons/hicolor/48x48/apps/${_i}"
done
}
_msg2() {
(( QUIET )) && return
local mesg=$1; shift
printf "${BLUE} ->${ALL_OFF}${BOLD} ${mesg}${ALL_OFF}\n" "$@"
}
_msg3() {
(( QUIET )) && return
local mesg=$1; shift
printf "${BLUE} -->${ALL_OFF} ${mesg}${ALL_OFF}\n" "$@"
}
# _gen_deb_scripts writes the canonical postinst.sh / prerm.sh /
# postrm.sh under ${srcdir}/ for deb-package consumption. Shared
# between skywire/deb.PKGBUILD and skywire-bin/cc.deb.PKGBUILD so
# the two deb consumers stay in sync. Mirrored verbatim in
# skywire-bin/PKGBUILD; keep both copies in sync.
#
# Idempotent: safe to call multiple times. Writes the same files
# every time.
#
# Semantics (matches skywire.install on the arch side):
# - postinst: systemd-sysusers + tmpfiles, setcap on the unified
# binary, then idempotent `skywire autoconfig` (SK-preserving).
# - prerm: case-aware. remove|deconfigure stops+disables;
# upgrade|failed-upgrade only stops. Never touches /opt/skywire.
# - postrm: case-aware. Only `purge` nukes /opt/skywire + drop-ins.
# remove keeps state for possible reinstall.
_gen_deb_scripts() {
cat > "${srcdir}/postinst.sh" <<'POSTINST_EOF'
#!/bin/bash
set -e
# Process the sysusers.d / tmpfiles.d files we shipped, so the
# _skywire user exists and /opt/skywire is owned by them BEFORE
# autoconfig runs and tries to write into the dir. systemd-sysusers
# creates the user; systemd-tmpfiles --create applies the d/Z lines.
if command -v systemd-sysusers >/dev/null 2>&1 ; then
systemd-sysusers /usr/lib/sysusers.d/skywire.conf 2>/dev/null || true
fi
if command -v systemd-tmpfiles >/dev/null 2>&1 ; then
systemd-tmpfiles --create /usr/lib/tmpfiles.d/skywire.conf 2>/dev/null || true
fi
# File caps for VPN apps + low-port hypervisor binds. Survives
# User= changes; required for the user-mode unit (which can't be
# granted ambient caps).
if command -v setcap >/dev/null 2>&1 ; then
setcap 'cap_net_admin,cap_net_bind_service+eip' /opt/skywire/bin/skywire 2>/dev/null || true
fi
# Generate the canonical /etc/skywire.conf template ONLY if it's
# missing. Operator edits (SK, HYPERVISORPKS, SKYWIRE_USER, etc.)
# are preserved by default across upgrades because the package no
# longer ships the file — there's nothing for dpkg to overwrite.
[[ ! -f /etc/skywire.conf ]] && skywire cli config gen -pqQ /etc/skywire.conf
skywire autoconfig
# On upgrade, restart every package-shipped service that's
# currently active. try-restart is a noop on inactive units, so
# operators who haven't enabled every shipped unit don't see
# spurious starts. autoconfig already touched skywire.service via
# its restart-if-active path; try-restart on a just-restarted
# service is harmless.
for _unit in skywire.service skywire-autoconfig.service \
skywire-sn.service skywire-ar.service \
skywire-rf.service skywire-tpd.service \
skywire-dmsgd.service skywire-dmsg.service \
skywire-sd.service dmsgpty-tcp.socket ; do
systemctl try-restart "$_unit" 2>/dev/null || true
done
POSTINST_EOF
cat > "${srcdir}/prerm.sh" <<'PRERM_EOF'
#!/bin/bash
set -e
case "$1" in
remove|deconfigure)
# Genuine uninstall. Stop and disable the units but leave
# /opt/skywire alone: an operator running `apt remove`
# (not `apt purge`) may reinstall later and expect their
# identity / hypervisor accounts intact. postrm with
# $1=purge is where the actual nuke happens.
for _unit in skywire.service skywire-autoconfig.service \
skywire-sn.service skywire-ar.service \
skywire-rf.service skywire-tpd.service \
skywire-dmsgd.service skywire-dmsg.service \
skywire-sd.service dmsgpty-tcp.socket ; do
systemctl stop "$_unit" 2>/dev/null || true
systemctl disable "$_unit" 2>/dev/null || true
done
;;
upgrade|failed-upgrade)
# No-op on upgrade. dpkg replaces files via unlink+rename,
# so running processes keep the old binary inode mapped
# until postinst's try-restart loop picks them up on the
# new binary.
;;
esac
PRERM_EOF
cat > "${srcdir}/postrm.sh" <<'POSTRM_EOF'
#!/bin/bash
set -e
case "$1" in
purge)
rm -rf /opt/skywire
rm -f /etc/systemd/system/skywire.service.d/skywire-user.conf
rmdir --ignore-fail-on-non-empty /etc/systemd/system/skywire.service.d 2>/dev/null || true
;;
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
# nothing: keep state for possible reinstall, and let the
# in-progress upgrade complete normally.
;;
esac
systemctl daemon-reload 2>/dev/null || true
POSTRM_EOF
}
Changes since previous scan
--- PKGBUILD @ 2026-09-28 00:28+++ PKGBUILD @ 2026-10-08 00:28@@ -5,7 +5,7 @@ _githuborg=${FORK:-$_projectname} pkgdesc="Software defined networking with public keys. Skycoin.com" _pkggopath=github.com/${_githuborg}/${_pkgname}-pkgver='1.3.96'+pkgver='1.3.99' pkgrel='1' _rc='' #_rc='-pr1'Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-08 00:28:03 | Low | 2 |
| 2026-10-07 00:21:34 | Low | 2 |
| 2026-10-05 23:40:58 | Medium | 1 |
| 2026-09-28 00:28:32 | Clean | 2 |
| 2026-09-27 19:19:18 | Medium | 1 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 19:30:45 | Medium | 1 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 23:29:28 | Medium | 1 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 23:20:44 | Medium | 1 |