sm64ex-redrawn-60fps-git

maintainer orphaned · 1 votes · scanned 2026-08-03 00:08:14.047287
HIGH
piracy
View on AUR ↗
Why flagged The localhost ROM source is intentional and documented — the PKGBUILD explicitly tells users to supply their own legally-obtained SM64 ROM at http://localhost/baserom.us.z64 (with a known-good SHA1 in the comments) and uses SKIP for its checksum, meaning it cannot be verified by makepkg but also cannot be injected by a remote attacker since it must be served locally by the user themselves. This is an unusual but not malicious pattern for distributing packages that require proprietary ROM files the maintainer cannot redistribute. The HD Mario asset is fetched from sm64pc.info (a community forum), which is slightly unofficial but is a static file with a sha512sum. The main supply-chain concern is the piracy angle: sm64ex is a port of a reverse-engineered, copyrighted Nintendo ROM, and the package explicitly packages and installs the compiled game binary derived from that ROM. The license field even says 'reverse-engineered and unlicensed'. This constitutes distribution of software derived from copyrighted material without a license, which is a piracy/IP concern. The localhost ROM trick is low-risk from a security standpoint (no remote attacker can substitute it), but the overall package facilitates running pirated Nintendo IP. Security severity is low (no actual attack vector); piracy flag applies.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:26 'https://www.sm64pc.info/forum/download/file.php?id=3'
  • PKGBUILD:30 "http://localhost/baserom.$_region.z64"
HIGH AI review of an ambiguous pattern llm_review

The static rules found a suspicious pattern they could not resolve, so an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed it and judged it HIGH (confidence 85%): The localhost ROM source is intentional and documented — the PKGBUILD explicitly tells users to supply their own legally-obtained SM64 ROM at http://localhost/baserom.us.z64 (with a known-good SHA1 in the comments) and uses SKIP for its checksum, meaning it cannot be verified by makepkg but also cannot be injected by a remote attacker since it must be served locally by the user themselves. This is an unusual but not malicious pattern for distributing packages that require proprietary ROM files the maintainer cannot redistribute. The HD Mario asset is fetched from sm64pc.info (a community forum), which is slightly unofficial but is a static file with a sha512sum. The main supply-chain concern is the piracy angle: sm64ex is a port of a reverse-engineered, copyrighted Nintendo ROM, and the package explicitly packages and installs the compiled game binary derived from that ROM. The license field even says 'reverse-engineered and unlicensed'. This constitutes distribution of software derived from copyrighted material without a license, which is a piracy/IP concern. The localhost ROM trick is low-risk from a security standpoint (no remote attacker can substitute it), but the overall package facilitates running pirated Nintendo IP. Security severity is low (no actual attack vector); piracy flag applies.

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: mekb https://github.com/mekb-turtle
2# Original Maintainer: Kevin MacMartin <prurigro@gmail.com>
3# Contributor: Hekuran https://github.com/narukeh
4# Contributor: selurvedu
5
6# A legally obtained copy of the Super Mario 64 ROM should be included
7# The US version should have a sha1sum of 9bef1128717f958171a4afac3ed78ee2bb4e86ce
8
9_region=us
10_pkgname=sm64ex
11pkgname=$_pkgname-redrawn-60fps-git
12pkgver=r513.58
13pkgrel=3
14pkgdesc='Super Mario 64 PC port (sm64ex fork) with the 60fps patch, redrawn texture pack and HD Mario'
15arch=('i686' 'x86_64' 'armv7h' 'aarch64')
16url='https://github.com/sm64pc/sm64ex'
17license=('reverse-engineered and unlicensed')
18depends=('sdl2')
19makedepends=('audiofile' 'git' 'python')
20provides=($_pkgname)
21conflicts=($_pkgname)
22
23source=(
24 'git+https://github.com/sm64pc/sm64ex.git'
25 'git+https://github.com/TechieAndroid/sm64redrawn'
26 'https://www.sm64pc.info/forum/download/file.php?id=3' # HD Mario
27 "$_pkgname.desktop"
28 "$_pkgname.svg"
29 "$_pkgname.sh"
30 "http://localhost/baserom.$_region.z64"
31)
32
33sha512sums=(
34 'SKIP'
35 'SKIP'
36 '1fbe98f4ea4439b5fb5eff5d985df5815cf4b30333004cb64133b6fb6bb2b6afd8b3154c6df79d73ce07eb573779bcdb3e282ebda3f356f6cc347206da816f7d'
37 '2e8979c01b314d7acce55f246390ff6667700b97da1831c058b16551e7c506886e4c87397266be5f53848016567eb1743cd4b14ff7d186fa2544e3a76d735755'
38 'af383cb853eb13376bc9697986756b29c15c3c22f8e7da2fec0516f26e12613e209af6f0470eab483bbcf462778af7f01d412c67f5277691e9823dc5bd885a80'
39 '7e6cbbac98800a714fc2074027b54aacdbd4bd2ea4f01f09b0fd764b775c2feef6021c1d36ce88703ca1b750cfd381695e7eaafa90d15f5d60b7bfbdfd21fe69'
40 'SKIP'
41)
42
43pkgver() {
44 cd sm64redrawn
45 redrawn_version=$(git rev-list --count HEAD)
46 cd ../$_pkgname
47 printf "r%s.%s" "$(git rev-list --count HEAD)" "$redrawn_version"
48}
49
50prepare() {
51 find actors -type f -exec cp '{}' $_pkgname/'{}' \; # HD Mario
52 cd $_pkgname
53 cp ../baserom.$_region.z64 . # Copy the ROM
54}
55
56build() {
57 cd $_pkgname
58 patch -p1 < ./enhancements/60fps_ex.patch
59 make VERSION=$_region BETTERCAMERA=1 NODRAWINGDISTANCE=1 TEXTURE_FIX=1 EXTERNAL_DATA=1 ${MAKEFLAGS:--j$(nproc)}
60}
61
62package() {
63 install -Dm644 $_pkgname.desktop "$pkgdir/usr/share/applications/$_pkgname.desktop"
64 install -Dm644 $_pkgname.svg "$pkgdir/usr/share/pixmaps/$_pkgname.svg"
65 install -Dm755 $_pkgname.sh "$pkgdir/usr/bin/$_pkgname"
66 install -Dm755 $_pkgname/build/${_region}_pc/sm64.${_region}.* "$pkgdir/usr/share/$_pkgname/$_pkgname"
67 install -Dm644 $_pkgname/build/${_region}_pc/res/base.zip "$pkgdir/usr/share/$_pkgname/res/base.zip"
68 cp -r --no-preserve=owner sm64redrawn/gfx "$pkgdir/usr/share/$_pkgname/res/" # sm64redrawn
69}
70

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 HIGH 2
2026-08-02 00:16:08 HIGH 2
2026-08-01 00:11:18 HIGH 2
2026-07-31 00:14:10 HIGH 2
2026-07-30 00:17:23 HIGH 2
2026-07-29 00:25:53 HIGH 2
2026-07-28 00:07:28 HIGH 2
2026-07-27 00:24:32 HIGH 2
2026-07-26 00:07:32 HIGH 2
2026-07-25 00:13:44 HIGH 2
2026-07-24 00:02:28 HIGH 2
2026-07-23 00:14:47 HIGH 2
2026-07-22 00:29:32 HIGH 2
2026-07-21 00:24:15 HIGH 2
2026-07-20 00:19:49 HIGH 2
2026-07-19 00:17:08 HIGH 2
2026-07-18 00:14:48 HIGH 2
2026-07-17 00:06:16 HIGH 2
2026-07-16 00:05:41 HIGH 2
2026-07-15 00:09:25 HIGH 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion