wallpaperd-git

LOW
maintainer wenmou 0 votes scanned 2026-10-06 18:07:39.727595
View on AUR
Why flagged

The non-standard host (cef-builds.spotifycdn.com) is Spotify's official CEF distribution CDN used by many projects, the archive has a sha256 checksum, and the package builds from the project's own GitHub source; no obfuscated payloads, exfiltration, or unverifiable prebuilt executables from swappable personal hosts are present.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 75%): The non-standard host (cef-builds.spotifycdn.com) is Spotify's official CEF distribution CDN used by many projects, the archive has a sha256 checksum, and the package builds from the project's own GitHub source; no obfuscated payloads, exfiltration, or unverifiable prebuilt executables from swappable personal hosts are present.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:31 "https://cef-builds.spotifycdn.com/${_cef_archive}.tar.bz2"

PKGBUILD

1 offending line(s) highlighted
1# shellcheck shell=bash
2# shellcheck disable=SC2034,SC2154
3pkgname=wallpaperd-git
4pkgver=0.1.0.r17.gb9c5c01
5pkgrel=1
6pkgdesc='Session wallpaper daemon with image, video, shader and Wallpaper Engine backends'
7arch=('x86_64')
8url='https://github.com/mengdehong/Misari'
9_srcname=misari
10license=('GPL-3.0-or-later' 'BSD-3-Clause' 'LicenseRef-Chromium')
11depends=(
12 'alsa-lib' 'at-spi2-core' 'cairo' 'dbus' 'expat' 'glib2' 'glibc'
13 'libcups' 'libgcc' 'libglvnd' 'libpulse' 'libstdc++' 'libx11' 'libxcb'
14 'libxcomposite' 'libxdamage' 'libxext' 'libxfixes' 'libxkbcommon' 'libxrandr'
15 'mesa' 'mpv' 'nspr' 'nss' 'pango' 'shaderc' 'systemd-libs' 'wayland'
16 'pulse-native-provider' 'ttf-font'
17 # These libraries are loaded at runtime and are absent from ELF NEEDED entries.
18 'libmpv.so=2-64' 'libEGL.so=1-64' 'libGLESv2.so=2-64'
19)
20provides=("wallpaperd=${pkgver%%.r*}")
21conflicts=('wallpaperd')
22makedepends=('git' 'rust>=1.96' 'pkgconf' 'python' 'cmake' 'ninja')
23# Keep the prebuilt CEF libraries intact; Cargo strips the application debug info.
24# Cargo controls Rust LTO; GCC LTO objects cannot be linked by rustc's lld.
25options=('!debug' '!strip' '!lto')
26_cef_archive='cef_binary_154.0.33+ga03e714+chromium-154.0.8037.94_linux64_minimal'
27_cef_sha1='9794ecf85ccd4dfcca42bfaac7a7666004f051e8'
28# Keep this archive in sync with cef-dll-sys in Cargo.lock.
29source=(
30 "misari::git+https://github.com/mengdehong/Misari.git#branch=main"
31 "https://cef-builds.spotifycdn.com/${_cef_archive}.tar.bz2"
32)
33sha256sums=(
34 'SKIP'
35 'cd89e366055d4412942fa25334a9fc98a5b69ff5b0abf6209c94e2d9e38005a2'
36)
37
38pkgver() {
39 cd "$srcdir/$_srcname" || return
40 local version
41 version=$(sed -n 's/^version = "\([^"]*\)"/\1/p' tools/wallpaperd/Cargo.toml | head -n1)
42 printf '%s.r%s.g%s\n' "$version" "$(git rev-list --count HEAD)" "$(git rev-parse --short=7 HEAD)"
43}
44
45prepare() {
46 local cef="$srcdir/$_cef_archive"
47 python - "$srcdir/$_srcname/tools/wallpaperd/Cargo.lock" "$_cef_archive" <<'PY'
48import sys
49import tomllib
50with open(sys.argv[1], "rb") as source:
51 packages = tomllib.load(source)["package"]
52version = next(p["version"] for p in packages if p["name"] == "cef-dll-sys").split("+", 1)[1]
53if not sys.argv[2].startswith(f"cef_binary_{version}+"):
54 sys.exit(f"PKGBUILD CEF archive does not match Cargo.lock ({version}); update archive and checksums")
55PY
56 # Use the layout expected by cef-dll-sys without downloading during compilation.
57 cp -a "$cef/Release/." "$cef/"
58 cp -a "$cef/Resources/." "$cef/"
59 printf '{"name":"%s.tar.bz2","sha1":"%s","type":"minimal"}\n' \
60 "$_cef_archive" "$_cef_sha1" > "$cef/archive.json"
61 cd "$srcdir/$_srcname/tools/wallpaperd" || return
62 cargo fetch --locked --target x86_64-unknown-linux-gnu
63}
64
65build() {
66 export RUSTFLAGS="${RUSTFLAGS} --remap-path-prefix=$srcdir=."
67 export CFLAGS="${CFLAGS} -ffile-prefix-map=$srcdir=."
68 export CXXFLAGS="${CXXFLAGS} -ffile-prefix-map=$srcdir=."
69 cd "$srcdir/$_srcname/tools/wallpaperd" || return
70 CEF_PATH="$srcdir/$_cef_archive" SHADERC_LIB_DIR=/usr/lib \
71 cargo build --frozen --release --features web --bin wallpaperd \
72 --target-dir "$srcdir/target-wallpaperd"
73}
74
75_check_runtime() {
76 python - "$@" <<'PY'
77import ctypes
78import os
79from pathlib import Path
80import subprocess
81import sys
82
83binary, runtime = (Path(arg).resolve() for arg in sys.argv[1:])
84for name in (
85 "libcef.so", "libvk_swiftshader.so", "libvulkan.so.1",
86 "chrome_100_percent.pak", "chrome_200_percent.pak", "resources.pak",
87 "icudtl.dat", "v8_context_snapshot.bin", "vk_swiftshader_icd.json",
88 "chrome-sandbox", "locales/en-US.pak", "LICENSE.txt", "CREDITS.html",
89):
90 if not (runtime / name).is_file():
91 sys.exit(f"missing CEF runtime file: {runtime / name}")
92
93mpv = ctypes.CDLL("libmpv.so.2")
94mpv.mpv_client_api_version.argtypes = []
95mpv.mpv_client_api_version.restype = ctypes.c_ulonglong
96version = mpv.mpv_client_api_version()
97if version >> 16 != 2:
98 sys.exit(f"libmpv client API must be 2.x, found {version >> 16}.{version & 0xffff}")
99for library, symbol in (
100 ("libEGL.so.1", "eglGetProcAddress"),
101 ("libGLESv2.so.2", "glGetString"),
102 ("libpulse.so.0", "pa_get_library_version"),
103 ("libpulse-simple.so.0", "pa_simple_new"),
104):
105 getattr(ctypes.CDLL(library), symbol)
106
107env = os.environ.copy()
108env.pop("LD_LIBRARY_PATH", None)
109env.pop("LD_PRELOAD", None)
110for path in (binary, runtime / "libcef.so"):
111 linked = subprocess.run(
112 ["ldd", str(path)], env=env, check=True, capture_output=True, text=True,
113 ).stdout
114 if "not found" in linked:
115 sys.exit(f"unresolved runtime dependencies for {path}:\n{linked}")
116# CEF is loaded with dlopen on demand, so it has no ELF NEEDED entry.
117# Match the runtime search used by we-web and verify that CEF can load.
118if binary.parent == runtime:
119 located = binary.parent / "libcef.so"
120else:
121 located = binary.parent / "../lib/wallpaperd/web/libcef.so"
122if located.resolve() != runtime / "libcef.so":
123 sys.exit(f"unexpected CEF runtime layout: {located}")
124cef = ctypes.CDLL(str(runtime / "libcef.so"))
125getattr(cef, "cef_execute_process")
126subprocess.run([str(binary), "--help"], env=env, check=True, stdout=subprocess.DEVNULL)
127print(f"wallpaperd runtime OK: libmpv {version >> 16}.{version & 0xffff}, EGL/GLES, PulseAudio, CEF")
128PY
129}
130
131check() {
132 _check_runtime "$srcdir/target-wallpaperd/release/wallpaperd" "$srcdir/target-wallpaperd/release"
133}
134
135package() {
136 local release="$srcdir/target-wallpaperd/release"
137 local runtime="$pkgdir/usr/lib/wallpaperd/web"
138 install -Dm755 "$release/wallpaperd" "$pkgdir/usr/bin/wallpaperd"
139 install -d "$runtime"
140 cp -a "$release"/lib*.so* "$release"/*.pak "$release"/*.bin \
141 "$release"/*.dat "$release"/*.json "$release/locales" \
142 "$release/LICENSE.txt" "$release/CREDITS.html" "$runtime/"
143 install -m755 "$release/chrome-sandbox" "$runtime/chrome-sandbox"
144
145 install -Dm644 "$srcdir/$_srcname/tools/wallpaperd/configs/wallpaperd.service" \
146 "$pkgdir/usr/lib/systemd/user/wallpaperd.service"
147 sed -i 's|^ExecStart=.*|ExecStart=/usr/bin/wallpaperd serve|' \
148 "$pkgdir/usr/lib/systemd/user/wallpaperd.service"
149 install -Dm644 "$srcdir/$_srcname/tools/wallpaperd/README.md" "$pkgdir/usr/share/doc/wallpaperd/README.md"
150 install -Dm644 "$srcdir/$_srcname/niri/LICENSE" "$pkgdir/usr/share/licenses/$pkgname/LICENSE"
151 install -Dm644 "$release/LICENSE.txt" "$pkgdir/usr/share/licenses/$pkgname/CEF-LICENSE.txt"
152 install -Dm644 "$release/CREDITS.html" "$pkgdir/usr/share/licenses/$pkgname/CREDITS.html"
153 # Validate the installed layout, including the relative path used by the CEF loader.
154 _check_runtime "$pkgdir/usr/bin/wallpaperd" "$runtime"
155}
156

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 18:07:39 Low 3
2026-10-06 18:03:40 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion