sm64ex-redrawn-60fps-git
Triggered rules
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:26
'https://www.sm64pc.info/forum/download/file.php?id=3' -
PKGBUILD:30
"http://localhost/baserom.$_region.z64"
llm_review
The static rules found a suspicious pattern they could not resolve, so an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed it and judged it HIGH (confidence 85%): The localhost ROM source is intentional and documented — the PKGBUILD explicitly tells users to supply their own legally-obtained SM64 ROM at http://localhost/baserom.us.z64 (with a known-good SHA1 in the comments) and uses SKIP for its checksum, meaning it cannot be verified by makepkg but also cannot be injected by a remote attacker since it must be served locally by the user themselves. This is an unusual but not malicious pattern for distributing packages that require proprietary ROM files the maintainer cannot redistribute. The HD Mario asset is fetched from sm64pc.info (a community forum), which is slightly unofficial but is a static file with a sha512sum. The main supply-chain concern is the piracy angle: sm64ex is a port of a reverse-engineered, copyrighted Nintendo ROM, and the package explicitly packages and installs the compiled game binary derived from that ROM. The license field even says 'reverse-engineered and unlicensed'. This constitutes distribution of software derived from copyrighted material without a license, which is a piracy/IP concern. The localhost ROM trick is low-risk from a security standpoint (no remote attacker can substitute it), but the overall package facilitates running pirated Nintendo IP. Security severity is low (no actual attack vector); piracy flag applies.
PKGBUILD
2 offending line(s) highlighted# Maintainer: mekb https://github.com/mekb-turtle
# Original Maintainer: Kevin MacMartin <prurigro@gmail.com>
# Contributor: Hekuran https://github.com/narukeh
# Contributor: selurvedu
# A legally obtained copy of the Super Mario 64 ROM should be included
# The US version should have a sha1sum of 9bef1128717f958171a4afac3ed78ee2bb4e86ce
_region=us
_pkgname=sm64ex
pkgname=$_pkgname-redrawn-60fps-git
pkgver=r513.58
pkgrel=3
pkgdesc='Super Mario 64 PC port (sm64ex fork) with the 60fps patch, redrawn texture pack and HD Mario'
arch=('i686' 'x86_64' 'armv7h' 'aarch64')
url='https://github.com/sm64pc/sm64ex'
license=('reverse-engineered and unlicensed')
depends=('sdl2')
makedepends=('audiofile' 'git' 'python')
provides=($_pkgname)
conflicts=($_pkgname)
source=(
'git+https://github.com/sm64pc/sm64ex.git'
'git+https://github.com/TechieAndroid/sm64redrawn'
'https://www.sm64pc.info/forum/download/file.php?id=3' # HD Mario
"$_pkgname.desktop"
"$_pkgname.svg"
"$_pkgname.sh"
"http://localhost/baserom.$_region.z64"
)
sha512sums=(
'SKIP'
'SKIP'
'1fbe98f4ea4439b5fb5eff5d985df5815cf4b30333004cb64133b6fb6bb2b6afd8b3154c6df79d73ce07eb573779bcdb3e282ebda3f356f6cc347206da816f7d'
'2e8979c01b314d7acce55f246390ff6667700b97da1831c058b16551e7c506886e4c87397266be5f53848016567eb1743cd4b14ff7d186fa2544e3a76d735755'
'af383cb853eb13376bc9697986756b29c15c3c22f8e7da2fec0516f26e12613e209af6f0470eab483bbcf462778af7f01d412c67f5277691e9823dc5bd885a80'
'7e6cbbac98800a714fc2074027b54aacdbd4bd2ea4f01f09b0fd764b775c2feef6021c1d36ce88703ca1b750cfd381695e7eaafa90d15f5d60b7bfbdfd21fe69'
'SKIP'
)
pkgver() {
cd sm64redrawn
redrawn_version=$(git rev-list --count HEAD)
cd ../$_pkgname
printf "r%s.%s" "$(git rev-list --count HEAD)" "$redrawn_version"
}
prepare() {
find actors -type f -exec cp '{}' $_pkgname/'{}' \; # HD Mario
cd $_pkgname
cp ../baserom.$_region.z64 . # Copy the ROM
}
build() {
cd $_pkgname
patch -p1 < ./enhancements/60fps_ex.patch
make VERSION=$_region BETTERCAMERA=1 NODRAWINGDISTANCE=1 TEXTURE_FIX=1 EXTERNAL_DATA=1 ${MAKEFLAGS:--j$(nproc)}
}
package() {
install -Dm644 $_pkgname.desktop "$pkgdir/usr/share/applications/$_pkgname.desktop"
install -Dm644 $_pkgname.svg "$pkgdir/usr/share/pixmaps/$_pkgname.svg"
install -Dm755 $_pkgname.sh "$pkgdir/usr/bin/$_pkgname"
install -Dm755 $_pkgname/build/${_region}_pc/sm64.${_region}.* "$pkgdir/usr/share/$_pkgname/$_pkgname"
install -Dm644 $_pkgname/build/${_region}_pc/res/base.zip "$pkgdir/usr/share/$_pkgname/res/base.zip"
cp -r --no-preserve=owner sm64redrawn/gfx "$pkgdir/usr/share/$_pkgname/res/" # sm64redrawn
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | HIGH | 2 |
| 2026-08-02 00:16:08 | HIGH | 2 |
| 2026-08-01 00:11:18 | HIGH | 2 |
| 2026-07-31 00:14:10 | HIGH | 2 |
| 2026-07-30 00:17:23 | HIGH | 2 |
| 2026-07-29 00:25:53 | HIGH | 2 |
| 2026-07-28 00:07:28 | HIGH | 2 |
| 2026-07-27 00:24:32 | HIGH | 2 |
| 2026-07-26 00:07:32 | HIGH | 2 |
| 2026-07-25 00:13:44 | HIGH | 2 |
| 2026-07-24 00:02:28 | HIGH | 2 |
| 2026-07-23 00:14:47 | HIGH | 2 |
| 2026-07-22 00:29:32 | HIGH | 2 |
| 2026-07-21 00:24:15 | HIGH | 2 |
| 2026-07-20 00:19:49 | HIGH | 2 |
| 2026-07-19 00:17:08 | HIGH | 2 |
| 2026-07-18 00:14:48 | HIGH | 2 |
| 2026-07-17 00:06:16 | HIGH | 2 |
| 2026-07-16 00:05:41 | HIGH | 2 |
| 2026-07-15 00:09:25 | HIGH | 2 |