xnviewmp-system-libs
The package downloads a source tarball from the official xnview.com domain, which is the project's legitimate release host; despite the static analyzer flagging it as non-standard, the source is verifiable and the build process is transparent, posing no significant security risk.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads a source tarball from the official xnview.com domain, which is the project's legitimate release host; despite the static analyzer flagging it as non-standard, the source is verifiable and the build process is transparent, posing no significant security risk.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:24
source=("XnViewMP-linux-x64_${pkgver}-rel${srcrel}.tgz::https://download.xnview.com/old_versions/XnView_MP/XnView_MP-${pkgver}-linux-x64.tgz"
PKGBUILD
1 offending line(s) highlighted# Maintainer: Kevin Brodsky <corax26 'at' gmail 'dot' com>
pkgname=xnviewmp-system-libs
_pkgname=xnviewmp
pkgver=1.11.6
srcrel=1 # Incremented when there is a new release for the same version number
pkgrel=1
pkgdesc="An efficient multimedia viewer, browser and converter (using system libraries)."
url="https://www.xnview.com/en/xnviewmp/"
arch=('x86_64')
license=('custom')
depends=(
# Main Qt dependencies
'qt5-location' 'qt5-multimedia' 'qt5-quickcontrols2' 'qt5-svg' 'qt5-x11extras'
# libmdk dependency
'libc++'
# Plugin libs
'libjxl' 'libwebp' 'openjpeg2' 'openexr'
)
optdepends=('glib2: support for moving files to trash')
conflicts=('xnviewmp')
source=("XnViewMP-linux-x64_${pkgver}-rel${srcrel}.tgz::https://download.xnview.com/old_versions/XnView_MP/XnView_MP-${pkgver}-linux-x64.tgz"
'xnview.sh'
'XnView.desktop'
'qt5_std_fun_forwarder.S'
'qt5_std_fun_forwarder.lds')
sha256sums=('3a4a9f80fbf4dcbef0681c78d42cfd52b22eb0129095822e49689452c6287b2c'
'87ec80c5049745dc3018fcdcf4dddf0e877ae3b20706705f2a80715232ad2141'
'f6b3a4aaa0a55b5f21d9b91ab6f3da3d6ee077ba7fdd17e7c4ab1c69ad2a9e3a'
'd4fc1e262f68b7b6b9767ca73870a78f06410035fb97a8bc495f4e1f28416563'
'3d6da484cd55eac8910d5cf87f9057e6eadeac842a249dcbda35e1c6f3fcdc0d')
# There is a lot of useless files in the archive, only install those from that
# list.
installed_files_dirs=(
AddOn
country.txt
language
license.txt
PrintPresets.txt
ResizePresets.txt
UI
WhatsNew.txt
XnView
xnview_2.png
xnview.png
)
executable_files=(
AddOn/exiftool
XnView
)
build() {
# This is massive hack to work around an incompatibility with the system Qt5
# libraries. On 0.93.1, the dynamic linker fails to start XnView, complaining
# that:
# symbol _ZNSt20bad_array_new_lengthD1Ev version Qt_5 not defined in file libQt5Gui.so.5 with link time reference
# (and other functions related to the std::bad_array_new_length class).
#
# It seems that the Qt5 libraries shipped in the archive changed in 0.93.1,
# and they now declare these functions, but our system libs on Arch don't!
# Since these are STL functions, the workaround is to manually define these
# functions in a tiny shared library, and implement them by calling the STL
# functions in libstdc++. This is frankly horrible, but it has worked fine
# since 0.93.1 so fingers crossed it will stay this way!
gcc -fPIC -shared -lstdc++ \
-Wl,--version-script="${srcdir}/qt5_std_fun_forwarder.lds" \
-o "${srcdir}/qt5_std_fun_forwarder.so" \
"${srcdir}/qt5_std_fun_forwarder.S"
}
package() {
cd "${srcdir}/XnView"
local pkg_opt_dir=${pkgdir}/opt/${_pkgname}
install -d -m755 "${pkg_opt_dir}"
# The permissions set in the archive are unreliable and excessive (too many
# executable files). Instead of copying them, we chmod the files that
# actually need to be executable.
cp -r --no-preserve=mode "${installed_files_dirs[@]}" "${pkg_opt_dir}"
for file in "${executable_files[@]}"; do
chmod a+x "${pkg_opt_dir}/${file}"
done
# The plugin libs that XnView packages are included as dependencies, but
# XnView will only look for them in the Plugins directory (regardless of the
# linker paths). Create symlinks as needed.
install -d -m755 "${pkg_opt_dir}/Plugins"
ln -s /usr/lib/libwebp.so "${pkg_opt_dir}/Plugins/libwebp.so"
ln -s /usr/lib/libOpenEXR.so "${pkg_opt_dir}/Plugins/libOpenEXR.so"
ln -s /usr/lib/libopenjp2.so "${pkg_opt_dir}/Plugins/openjp2.so"
# This seems to be a custom library that links against libjxl and is required
# for opening JPEG XL images, use it as-is.
install -D -m644 "Plugins/libJPEGXL.so" -t "${pkg_opt_dir}/Plugins"
# Using the system libraw doesn't seem to work (assertion failure in libc when
# attempting to view a RAW file), use the one provided.
install -D -m644 "lib/liblibraw.so.1" -t "${pkg_opt_dir}/lib"
# There is no package for libmdk, which is anyway distributed as binary, so
# just use the one provided.
install -D -m644 "lib/libmdk.so.0" -t "${pkg_opt_dir}/lib"
# From Adobe XMP Toolkit SDK, apparently not packaged on Arch.
install -D -m644 "lib/libXMPCore.so" -t "${pkg_opt_dir}/lib"
install -D -m644 "lib/libXMPFiles.so" -t "${pkg_opt_dir}/lib"
install -m755 "${srcdir}/xnview.sh" "${pkg_opt_dir}"
# Install our "function forwarder library" (see build()). xnview.sh forces the
# dynamic linker to use it by adding it to LD_PRELOAD.
install -D -m644 "${srcdir}/qt5_std_fun_forwarder.so" -t "${pkg_opt_dir}/lib"
install -d -m755 "${pkgdir}/usr/bin"
ln -s "/opt/${_pkgname}/xnview.sh" "${pkgdir}/usr/bin/${_pkgname}"
install -D -m644 "${srcdir}/XnView.desktop" -t "${pkgdir}/usr/share/applications/"
install -D -m644 "${srcdir}/XnView/license.txt" "${pkgdir}/usr/share/licenses/${_pkgname}/LICENSE"
}
# vim:set ts=2 sw=2 et:
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-05 00:08:03 | Low | 2 |
| 2026-10-04 00:18:08 | Low | 2 |
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |