slack-desktop-wayland-jetm

LOW
maintainer jetm 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads a Slack .deb from Slack's official domain (slack-edge.com), which is a legitimate source; the download is used to extract and repurpose official Slack assets with a system Electron and Wayland support, a common and safe AUR pattern.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a Slack .deb from Slack's official domain (slack-edge.com), which is a legitimate source; the download is used to extract and repurpose official Slack assets with a system Electron and Wayland support, a common and safe AUR pattern.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:64 source=("https://downloads.slack-edge.com/desktop-releases/linux/x64/${pkgver}/${_debname}-${pkgver}-amd64.deb")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Javier Tia <floss@jetm.me>
2# Contributor: Chris Speck <chris.speck(at)annalise(dot)ai>
3# Contributor: "Amhairghin" Oscar Garcia Amor (https://ogarcia.me)
4
5# Fork of the AUR `slack-desktop-wayland`, which trails upstream by several
6# releases. The -jetm suffix is what keeps this installable: `provides` and
7# `conflicts` alone still let a `slack-desktop-wayland` upgrade take the slot.
8pkgname=slack-desktop-wayland-jetm
9_debname=slack-desktop
10pkgver=4.52.162
11pkgrel=1
12pkgdesc='Slack Desktop (Beta) for Linux, launched as a native Wayland client on the system Electron package'
13arch=('x86_64')
14url='https://slack.com/downloads'
15license=('LicenseRef-Slack')
16
17# Runs the deb's own app.asar under the system electron<N> package instead of
18# Slack's bundled Electron binary. Slack 4.52.155 bundles Electron 44.0.0,
19# which carries a since-fixed upstream Linux tray/StatusNotifierItem
20# regression (electron/electron#52674, #53213): the SNI object it registers
21# on hide comes back with empty introspection and the D-Bus connection drops
22# outright, so a hidden window has no tray icon to click back - matching
23# KDE Bug 524697 against this exact Slack version. Fixed upstream in Electron
24# 44.1.0 (electron/electron#53214); the `extra` repo's electron44 is 44.4.2 as
25# of this writing, well past it. `slack-electron` in the AUR already proves
26# this swap works (34 votes) - this package folds the same technique into the
27# one already carrying the Wayland fix below, rather than adopting a second
28# package with no Wayland hook to patch against.
29_electronver=44
30
31# Slack's own native code (the *.node modules under app.asar.unpacked) needs
32# these directly, independent of which Electron binary hosts them - dlopen
33# calls carry no DT_NEEDED entry, so they don't show up in the binary's own
34# dependency list. glibc/libstdc++/libx11/libxkbfile match the AUR
35# `slack-electron` package's own vetted set for the same reason: Slack's
36# native modules link them directly, not by way of electron44's dependency
37# graph. xdg-desktop-portal is what separates this package from plain
38# `slack-desktop`: under Wayland both the screen picker and the file chooser
39# go through it.
40depends=("electron${_electronver}" 'glibc' 'libstdc++' 'libx11' 'libxkbfile'
41 'libnotify' 'libpipewire' 'libsecret'
42 'xdg-desktop-portal' 'xdg-utils')
43optdepends=('org.freedesktop.secrets: keyring password store'
44 'pipewire: PipeWire daemon, required for screen sharing'
45 'xdg-desktop-portal-gnome: portal backend for GNOME'
46 'xdg-desktop-portal-gtk: portal backend for GNOME and GTK'
47 'xdg-desktop-portal-hyprland: portal backend for Hyprland'
48 'xdg-desktop-portal-kde: portal backend for KDE'
49 'xdg-desktop-portal-lxqt: portal backend for LXQt'
50 'xdg-desktop-portal-wlr: portal backend for wlroots compositors')
51
52provides=("slack-desktop=${pkgver}")
53conflicts=('slack-desktop' 'slack-desktop-wayland' 'slack-electron')
54replaces=('slack-desktop-wayland')
55
56# Slack's own *.node native modules under app.asar.unpacked are prebuilt
57# vendor binaries - stripping them can break them. This package no longer
58# carries a compiled Electron binary of its own to strip (electron44 hosts
59# the app.asar instead), but the *.node modules still need this. Also
60# suppresses the debug package on its own - makepkg gates that on `debug`
61# AND `strip`.
62options=('!strip')
63
64source=("https://downloads.slack-edge.com/desktop-releases/linux/x64/${pkgver}/${_debname}-${pkgver}-amd64.deb")
65noextract=("${_debname}-${pkgver}-amd64.deb")
66b2sums=('58be09bb5f84f9d3520d630137d7cf3a1a68180cb72486701c9f9e7dadcc23de524f41615c12ac7689066ebe03c84f81cab859cc9b9b0731147343541055872a')
67
68_archive="${_debname}-${pkgver}"
69
70prepare() {
71 # Extracted to a scratch tree rather than straight into $pkgdir: package()
72 # below installs an explicit allowlist (resources/, locales/, the few
73 # top-level files Slack's own code reads at runtime), not "everything minus
74 # a few directories" - the deb also carries Slack's own bundled Electron
75 # binary, its setuid chrome-sandbox helper, and its private copies of
76 # Chromium's *.pak/icudtl.dat/v8 snapshot files, none of which this package
77 # ships once electron44 is what actually runs the app.
78 mkdir -p "${_archive}"
79 bsdtar -O -xf "${srcdir}/${_debname}-${pkgver}-amd64.deb" 'data.tar.*' |
80 bsdtar -C "${_archive}" -xf -
81
82 # Refuse to build against a deb whose own Electron major does not match
83 # _electronver: the app.asar was built and tested against exactly one
84 # Electron major, and this package's whole point is running it under a
85 # different point release of that SAME major, not a different one.
86 grep -q "^${_electronver}" "${_archive}/usr/lib/slack/version" || {
87 echo "error: deb's Electron major (usr/lib/slack/version) does not match _electronver=${_electronver}" >&2
88 return 1
89 }
90
91 # Refuse to ship a headless package. With the unpacked native modules
92 # missing, Slack starts, draws no window, registers no tray icon and logs
93 # nothing - a failure that only surfaces after install.
94 local _natmod="${_archive}/usr/lib/slack/resources/app.asar.unpacked/node_modules/@tinyspeck/slack-desktop-utils/lib/binding/napi-v8/slackdesktoputils.node"
95 [[ -f $_natmod ]] || {
96 echo 'error: native modules missing under app.asar.unpacked after extraction' >&2
97 return 1
98 }
99
100 # Rewrite the launcher in place instead of carrying a context diff, which
101 # breaks every time upstream reflows this file. The grep restores the
102 # fail-loud property a patch would have given, since sed exits 0 when it
103 # matches nothing.
104 #
105 # --ozone-platform=wayland stays here, not in the /usr/bin/slack wrapper
106 # below - it's the entire reason this package exists. Slack's own Electron
107 # build ships neither --ozone-platform-hint nor
108 # ELECTRON_OZONE_PLATFORM_HINT, so with no switch it lands on XWayland, and
109 # electron44's own bundled Chromium defaults the same way.
110 #
111 # Icon=slack rather than the absolute /usr/share/pixmaps path upstream
112 # ships, so an icon theme can override it.
113 local _desktop="${_archive}/usr/share/applications/slack.desktop"
114 local _exec='Exec=/usr/bin/slack --ozone-platform=wayland -s %U'
115 sed -i -e "s|^Exec=.*|${_exec}|" -e 's|^Icon=.*|Icon=slack|' "$_desktop"
116 if ! grep -qxF "$_exec" "$_desktop" || ! grep -qxF 'Icon=slack' "$_desktop"; then
117 echo 'error: slack.desktop rewrite did not apply' >&2
118 return 1
119 fi
120}
121
122package() {
123 install -vdm755 "${pkgdir}/usr/lib/slack/resources/"
124 cp -va -t "${pkgdir}/usr/lib/slack/resources/" "${_archive}"/usr/lib/slack/resources/*
125
126 install -vdm755 "${pkgdir}/usr/lib/slack/locales/"
127 cp -va -t "${pkgdir}/usr/lib/slack/locales/" "${_archive}"/usr/lib/slack/locales/*
128
129 install -vDm644 -t "${pkgdir}/usr/lib/slack" \
130 "${_archive}/usr/lib/slack/LICENSES-linux.json" \
131 "${_archive}/usr/lib/slack/resources.pak" \
132 "${_archive}/usr/lib/slack/version"
133
134 # This package's own launcher, not the deb's: the deb's /usr/bin/slack is a
135 # symlink straight to its bundled Electron binary (usr/lib/slack/slack),
136 # which is intentionally not installed above - electron44 hosts the
137 # app.asar instead. Forwards "$@" untouched so the Wayland flag rewritten
138 # into slack.desktop's Exec above, and any flags a caller passes directly
139 # (e.g. this host's Hyprland keybind), still reach Chromium unchanged.
140 install -vDm755 /dev/stdin "${pkgdir}/usr/bin/slack" <<-EOF
141 #!/bin/sh
142 exec electron${_electronver} /usr/lib/slack/resources/app.asar "\$@"
143 EOF
144
145 install -vDm644 -t "${pkgdir}/usr/share/applications" "${_archive}/usr/share/applications/slack.desktop"
146 install -vDm644 -t "${pkgdir}/usr/share/pixmaps" "${_archive}/usr/share/pixmaps/slack.png"
147
148 install -dm755 "${pkgdir}/usr/share/licenses/${pkgname}"
149 install -vDm644 "${_archive}/usr/lib/slack/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/"
150 ln -s "/usr/share/licenses/${pkgname}/LICENSE" "${pkgdir}/usr/lib/slack/LICENSE"
151}
152

Changes since previous scan

--- PKGBUILD @ 2026-09-25 00:03
+++ PKGBUILD @ 2026-10-06 00:13
@@ -7,25 +7,40 @@
# `conflicts` alone still let a `slack-desktop-wayland` upgrade take the slot.
pkgname=slack-desktop-wayland-jetm
_debname=slack-desktop
-pkgver=4.51.191
+pkgver=4.52.162
pkgrel=1
-pkgdesc='Slack Desktop (Beta) for Linux, launched as a native Wayland client'
+pkgdesc='Slack Desktop (Beta) for Linux, launched as a native Wayland client on the system Electron package'
arch=('x86_64')
url='https://slack.com/downloads'
license=('LicenseRef-Slack')
-# Direct DT_NEEDED of the shipped binary, minus what gtk3 already pulls
-# transitively (cairo, pango, glib2, at-spi2-core, mesa, libcups, dbus, expat,
-# systemd-libs and the libX* stack). libsecret, libnotify and libpipewire carry
-# no NEEDED entry - Electron dlopen()s all three, so they appear only as
-# literal sonames inside the binary.
-#
-# xdg-desktop-portal is what separates this package from plain `slack-desktop`:
-# under Wayland both the screen picker and the file chooser go through it.
-depends=('alsa-lib' 'gtk3' 'libnotify' 'libpipewire' 'libsecret' 'nss'
+# Runs the deb's own app.asar under the system electron<N> package instead of
+# Slack's bundled Electron binary. Slack 4.52.155 bundles Electron 44.0.0,
+# which carries a since-fixed upstream Linux tray/StatusNotifierItem
+# regression (electron/electron#52674, #53213): the SNI object it registers
+# on hide comes back with empty introspection and the D-Bus connection drops
+# outright, so a hidden window has no tray icon to click back - matching
+# KDE Bug 524697 against this exact Slack version. Fixed upstream in Electron
+# 44.1.0 (electron/electron#53214); the `extra` repo's electron44 is 44.4.2 as
+# of this writing, well past it. `slack-electron` in the AUR already proves
+# this swap works (34 votes) - this package folds the same technique into the
+# one already carrying the Wayland fix below, rather than adopting a second
+# package with no Wayland hook to patch against.
+_electronver=44
+
+# Slack's own native code (the *.node modules under app.asar.unpacked) needs
+# these directly, independent of which Electron binary hosts them - dlopen
+# calls carry no DT_NEEDED entry, so they don't show up in the binary's own
+# dependency list. glibc/libstdc++/libx11/libxkbfile match the AUR
+# `slack-electron` package's own vetted set for the same reason: Slack's
+# native modules link them directly, not by way of electron44's dependency
+# graph. xdg-desktop-portal is what separates this package from plain
+# `slack-desktop`: under Wayland both the screen picker and the file chooser
+# go through it.
+depends=("electron${_electronver}" 'glibc' 'libstdc++' 'libx11' 'libxkbfile'
+ 'libnotify' 'libpipewire' 'libsecret'
'xdg-desktop-portal' 'xdg-utils')
-optdepends=('libappindicator-gtk3: system tray icon'
- 'org.freedesktop.secrets: keyring password store'
+optdepends=('org.freedesktop.secrets: keyring password store'
'pipewire: PipeWire daemon, required for screen sharing'
'xdg-desktop-portal-gnome: portal backend for GNOME'
'xdg-desktop-portal-gtk: portal backend for GNOME and GTK'
@@ -38,63 +53,100 @@
conflicts=('slack-desktop' 'slack-desktop-wayland' 'slack-electron')
replaces=('slack-desktop-wayland')
-# Repackaging a prebuilt vendor binary: stripping Slack's bundled Electron and
-# *.node modules can break them and buys nothing here. This also suppresses the
-# debug package on its own - makepkg gates that on `debug` AND `strip`.
+# Slack's own *.node native modules under app.asar.unpacked are prebuilt
+# vendor binaries - stripping them can break them. This package no longer
+# carries a compiled Electron binary of its own to strip (electron44 hosts
+# the app.asar instead), but the *.node modules still need this. Also
+# suppresses the debug package on its own - makepkg gates that on `debug`
+# AND `strip`.
options=('!strip')
source=("https://downloads.slack-edge.com/desktop-releases/linux/x64/${pkgver}/${_debname}-${pkgver}-amd64.deb")
noextract=("${_debname}-${pkgver}-amd64.deb")
-b2sums=('d06a3a0880f776ccf702481bd0009da0ec60d250811ded0c7cc654678b0bcfe97c2d8e75f9e2d54938ff1b4d04d741a7afb4f19714e885de06ed6dbb116d8dcf')
+b2sums=('58be09bb5f84f9d3520d630137d7cf3a1a68180cb72486701c9f9e7dadcc23de524f41615c12ac7689066ebe03c84f81cab859cc9b9b0731147343541055872a')
-package() {
- # Match data.tar.* rather than data.tar.xz: Debian tooling has been moving
- # payloads to zstd, and a hardcoded suffix would turn that into an empty
- # package rather than a build failure. makepkg does not set pipefail, so a
- # failure in the first bsdtar is invisible here too - the native-module check
- # below is what catches both.
+_archive="${_debname}-${pkgver}"
+
+prepare() {
+ # Extracted to a scratch tree rather than straight into $pkgdir: package()
+ # below installs an explicit allowlist (resources/, locales/, the few
+ # top-level files Slack's own code reads at runtime), not "everything minus
+ # a few directories" - the deb also carries Slack's own bundled Electron
+ # binary, its setuid chrome-sandbox helper, and its private copies of
+ # Chromium's *.pak/icudtl.dat/v8 snapshot files, none of which this package
+ # ships once electron44 is what actually runs the app.
+ mkdir -p "${_archive}"
bsdtar -O -xf "${srcdir}/${_debname}-${pkgver}-amd64.deb" 'data.tar.*' |
- bsdtar -C "${pkgdir}" -xf -
+ bsdtar -C "${_archive}" -xf -
+
+ # Refuse to build against a deb whose own Electron major does not match
+ # _electronver: the app.asar was built and tested against exactly one
+ # Electron major, and this package's whole point is running it under a
+ # different point release of that SAME major, not a different one.
+ grep -q "^${_electronver}" "${_archive}/usr/lib/slack/version" || {
+ echo "error: deb's Electron major (usr/lib/slack/version) does not match _electronver=${_electronver}" >&2
+ return 1
+ }
# Refuse to ship a headless package. With the unpacked native modules
# missing, Slack starts, draws no window, registers no tray icon and logs
# nothing - a failure that only surfaces after install.
- local _natmod="${pkgdir}/usr/lib/slack/resources/app.asar.unpacked/node_modules/@tinyspeck/slack-desktop-utils/lib/binding/napi-v8/slackdesktoputils.node"
- if [[ ! -f $_natmod ]]; then
+ local _natmod="${_archive}/usr/lib/slack/resources/app.asar.unpacked/node_modules/@tinyspeck/slack-desktop-utils/lib/binding/napi-v8/slackdesktoputils.node"
+ [[ -f $_natmod ]] || {
echo 'error: native modules missing under app.asar.unpacked after extraction' >&2
return 1
- fi
+ }
# Rewrite the launcher in place instead of carrying a context diff, which
# breaks every time upstream reflows this file. The grep restores the
# fail-loud property a patch would have given, since sed exits 0 when it
# matches nothing.
#
- # --ozone-platform=wayland is the entire reason this package exists. Slack's
- # Electron build ships neither --ozone-platform-hint nor
- # ELECTRON_OZONE_PLATFORM_HINT, so with no switch it lands on XWayland.
+ # --ozone-platform=wayland stays here, not in the /usr/bin/slack wrapper
+ # below - it's the entire reason this package exists. Slack's own Electron
+ # build ships neither --ozone-platform-hint nor
+ # ELECTRON_OZONE_PLATFORM_HINT, so with no switch it lands on XWayland, and
+ # electron44's own bundled Chromium defaults the same way.
#
- # Icon=slack rather than the absolute /usr/share/pixmaps path upstream ships,
- # so an icon theme can override it.
- local _desktop="${pkgdir}/usr/share/applications/slack.desktop"
+ # Icon=slack rather than the absolute /usr/share/pixmaps path upstream
+ # ships, so an icon theme can override it.
+ local _desktop="${_archive}/usr/share/applications/slack.desktop"
local _exec='Exec=/usr/bin/slack --ozone-platform=wayland -s %U'
sed -i -e "s|^Exec=.*|${_exec}|" -e 's|^Icon=.*|Icon=slack|' "$_desktop"
if ! grep -qxF "$_exec" "$_desktop" || ! grep -qxF 'Icon=slack' "$_desktop"; then
echo 'error: slack.desktop rewrite did not apply' >&2
return 1
fi
+}
- # The deb ships some directories 0700.
- find "${pkgdir}" -type d -exec chmod 755 {} +
+package() {
+ install -vdm755 "${pkgdir}/usr/lib/slack/resources/"
+ cp -va -t "${pkgdir}/usr/lib/slack/resources/" "${_archive}"/usr/lib/slack/resources/*
- # /etc holds an apt sources.list.d entry; src/ is Slack's own build tree.
- rm -rf "${pkgdir}/etc" \
- "${pkgdir}/usr/lib/slack/src" \
- "${pkgdir}/usr/share/lintian" \
- "${pkgdir}/usr/share/doc"
+ install -vdm755 "${pkgdir}/usr/lib/slack/locales/"
+ cp -va -t "${pkgdir}/usr/lib/slack/locales/" "${_archive}"/usr/lib/slack/locales/*
+
+ install -vDm644 -t "${pkgdir}/usr/lib/slack" \
+ "${_archive}/usr/lib/slack/LICENSES-linux.json" \
+ "${_archive}/usr/lib/slack/resources.pak" \
+ "${_archive}/usr/lib/slack/version"
+
+ # This package's own launcher, not the deb's: the deb's /usr/bin/slack is a
+ # symlink straight to its bundled Electron binary (usr/lib/slack/slack),
+ # which is intentionally not installed above - electron44 hosts the
+ # app.asar instead. Forwards "$@" untouched so the Wayland flag rewritten
+ # into slack.desktop's Exec above, and any flags a caller passes directly
+ # (e.g. this host's Hyprland keybind), still reach Chromium unchanged.
+ install -vDm755 /dev/stdin "${pkgdir}/usr/bin/slack" <<-EOF
+ #!/bin/sh
+ exec electron${_electronver} /usr/lib/slack/resources/app.asar "\$@"
+ EOF
+
+ install -vDm644 -t "${pkgdir}/usr/share/applications" "${_archive}/usr/share/applications/slack.desktop"
+ install -vDm644 -t "${pkgdir}/usr/share/pixmaps" "${_archive}/usr/share/pixmaps/slack.png"
install -dm755 "${pkgdir}/usr/share/licenses/${pkgname}"
- mv "${pkgdir}/usr/lib/slack/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/"
+ install -vDm644 "${_archive}/usr/lib/slack/LICENSE" "${pkgdir}/usr/share/licenses/${pkgname}/"
ln -s "/usr/share/licenses/${pkgname}/LICENSE" "${pkgdir}/usr/lib/slack/LICENSE"
}

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 00:08:03 Low 2
2026-10-04 00:18:08 Low 2
2026-10-03 00:23:04 Low 2
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 15:12:17 Medium 1
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion