xlibre-server-bin

maintainer xlibre · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary package (xlibre-xserver) from x11libre.net, which is not an official Arch Linux or upstream X.Org/XLibre infrastructure mirror that is widely recognized or audited. The package is then extracted and installed directly as an X server binary — a highly privileged component that runs as root and interfaces with all display hardware. While XLibre is a real fork of X.Org (started ~2025), x11libre.net is a personal/project-run host with no independent verification chain beyond the SHA256 checksum in the PKGBUILD. The SHA256 sum does provide integrity protection against accidental corruption, but it does not protect against the maintainer of x11libre.net substituting a malicious binary and updating the PKGBUILD simultaneously. Installing a prebuilt X server binary from a non-official, non-audited third-party host represents a genuine supply-chain risk: if the host is compromised or the maintainer is malicious, arbitrary code runs with elevated privileges on the user's system. This is a textbook medium-severity supply-chain concern — not clearly malicious, but a real risk due to the combination of unofficial binary host and highly privileged installed component.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:28 source=(https://x11libre.net/repo/arch_based/x86_64/xlibre-xserver-25.0.0.21-1-x86_64.pkg.tar.zst)
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 72%): This PKGBUILD downloads a prebuilt binary package (xlibre-xserver) from x11libre.net, which is not an official Arch Linux or upstream X.Org/XLibre infrastructure mirror that is widely recognized or audited. The package is then extracted and installed directly as an X server binary — a highly privileged component that runs as root and interfaces with all display hardware. While XLibre is a real fork of X.Org (started ~2025), x11libre.net is a personal/project-run host with no independent verification chain beyond the SHA256 checksum in the PKGBUILD. The SHA256 sum does provide integrity protection against accidental corruption, but it does not protect against the maintainer of x11libre.net substituting a malicious binary and updating the PKGBUILD simultaneously. Installing a prebuilt X server binary from a non-official, non-audited third-party host represents a genuine supply-chain risk: if the host is compromised or the maintainer is malicious, arbitrary code runs with elevated privileges on the user's system. This is a textbook medium-severity supply-chain concern — not clearly malicious, but a real risk due to the combination of unofficial binary host and highly privileged installed component.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: artist for XLibre <artist4xlibre@proton.me>
2
3_pkgname=xlibre-server
4_orgpkgname=xlibre-xserver
5pkgname=$_pkgname-bin
6pkgver=25.0.0.21
7pkgrel=1
8pkgdesc="XLibre Official Easy Install Drop in Replacement fork of X.Org X server (binary release)"
9arch=(x86_64)
10url=https://x11libre.net/repo/arch_based/x86_64
11license=('LicenseRef-Adobe-Display-PostScript'
12 'BSD-3-Clause'
13 'LicenseRef-DEC-3-Clause'
14 'HPND'
15 'LicenseRef-HPND-sell-MIT-disclaimer-xserver'
16 'HPND-sell-variant'
17 'ICU'
18 'ISC'
19 'MIT'
20 'MIT-open-group'
21 'NTP'
22 'SGI-B-2.0'
23 'SMLNJ'
24 'X11'
25 'X11-distribute-modifications-variant')
26groups=('xlibre')
27options=(!strip)
28source=(https://x11libre.net/repo/arch_based/x86_64/xlibre-xserver-25.0.0.21-1-x86_64.pkg.tar.zst)
29noextract=("${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst")
30depends=(xlibre-server-common-bin xlibre-input-libinput-bin libepoxy libxfont2 pixman libunwind
31 dbus libgl nettle libxdmcp sh glibc libxau libtirpc libmd libbsd
32 libpciaccess libdrm libxshmfence libxcvt) # FS#52949
33# see xorg-server-*/hw/xfree86/common/xf86Module.h for ABI versions - we provide major numbers that drivers can depend on
34# and /usr/lib/pkgconfig/xorg-server.pc in xorg-server-devel pkg
35provides=($_pkgname 'xorg-server' 'X-ABI-VIDEODRV_VERSION=28.0' 'X-ABI-XINPUT_VERSION=26.0' 'X-ABI-EXTENSION_VERSION=11.0' 'x-server')
36conflicts=($_pkgname 'xorg-server' 'xorg-server-common<25.0.0.0' 'nvidia-utils<=331.20' 'glamor-egl' 'xf86-video-modesetting')
37replaces=('glamor-egl' 'xf86-video-modesetting')
38install=$pkgname.install
39
40sha256sums=('0b9f04f73f831035444de5b5c6317952bf067e886c371f36b615f1ca21831177')
41
42package() {
43 tar -xf "${_orgpkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst" -C "${pkgdir}" etc usr
44}
45
46

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion