xtensa-esp32-elf-gcc
The package builds a cross-compiler from official GCC and SourceForge sources, with an additional patch from GitHub; the non-whitelisted host is GitHub's codeload service, which hosts verifiable source code, not executables, and the build process is transparent and standard for AUR.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds a cross-compiler from official GCC and SourceForge sources, with an additional patch from GitHub; the non-whitelisted host is GitHub's codeload service, which hosts verifiable source code, not executables, and the build process is transparent and standard for AUR.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:18
https://libisl.sourceforge.io/isl-$_islver.tar.bz2
PKGBUILD
1 offending line(s) highlighted# Maintainer: Baltazár Radics <baltazar.radics@gmail.com>
_target=xtensa-esp32-elf
pkgname=$_target-gcc
pkgver=12.2.0
_islver=0.25
_overlay_commit=a5ab689
pkgrel=1
pkgdesc='The GNU Compiler Collection - cross compiler for xtensa esp32 (bare-metal) target'
arch=(x86_64)
url='https://gcc.gnu.org/'
license=(GPL LGPL FDL)
depends=($_target-binutils zlib libmpc)
makedepends=(gmp mpfr $_target-newlib)
optdepends=("$_target-newlib: Standard C library optimized for embedded systems")
options=(!emptydirs !strip)
source=(https://ftp.gnu.org/gnu/gcc/gcc-$pkgver/gcc-$pkgver.tar.xz{,.sig}
https://libisl.sourceforge.io/isl-$_islver.tar.bz2
xtensa-overlays-$_overlay_commit.tar.gz::https://codeload.github.com/espressif/xtensa-overlays/tar.gz/$_overlay_commit)
sha256sums=('e549cf9cf3594a00e27b6589d4322d70e0720cdd213f39beb4181e06926230ff'
'SKIP'
'4305c54d4eebc4bf3ce365af85f04984ef5aa97a52e01128445e26da5b1f467a'
'0087aac5e7015d43ff904ef984278df1f99c6757709088c52632b27dc482268f')
validpgpkeys=(33C235A34C46AA3FFB293709A328C3A2C3C45C06 # Jakub Jelinek <jakub@redhat.com>
D3A93CAD751C2AF4F8C7AD516C35B99309B5FA62 # Jakub Jelinek <jakub@redhat.com>
13975A70E63C361C73AE69EF6EEB81F8981C74C7) # Richard Guenther <richard.guenther@gmail.com>
_basedir=gcc-$pkgver
prepare() {
cd $_basedir
# link isl for in-tree builds
ln -sf ../isl-$_islver isl
echo $pkgver > gcc/BASE-VER
# hack! - some configure tests for header files using "$CPP $CPPFLAGS"
sed -i "/ac_cpp=/s/\$CPPFLAGS/\$CPPFLAGS -O2/" {libiberty,gcc}/configure
cp -r ../xtensa-overlays-$_overlay_commit/xtensa_esp32/gcc/* .
mkdir "$srcdir"/build-{gcc,gcc-nano}
}
_build_gcc() {
# espressif's crosstool-ng:
# CC_FOR_BUILD='x86_64-build_pc-linux-gnu-gcc'
# CFLAGS='-O2 -g -pipe -I./.build/xtensa-esp32-elf/buildtools/include '
# CFLAGS_FOR_BUILD='-O2 -g -I./.build/xtensa-esp32-elf/buildtools/include '
# CXXFLAGS='-O2 -g -pipe -I./.build/xtensa-esp32-elf/buildtools/include '
# CXXFLAGS_FOR_BUILD='-O2 -g -I./.build/xtensa-esp32-elf/buildtools/include '
# LDFLAGS='-L./.build/xtensa-esp32-elf/buildtools/lib -lstdc++ -lm'
# CFLAGS_FOR_TARGET=' -mlongcalls'
# CXXFLAGS_FOR_TARGET=' -mlongcalls'
# LDFLAGS_FOR_TARGET=' -static'
# '/usr/bin/bash'
# './.build/xtensa-esp32-elf/src/gcc/configure'
# '--build=x86_64-build_pc-linux-gnu'
# '--host=x86_64-build_pc-linux-gnu'
# '--target=xtensa-esp32-elf'
# '--prefix=./builds/xtensa-esp32-elf'
# '--with-local-prefix=./builds/xtensa-esp32-elf/xtensa-esp32-elf'
# '--with-headers=./builds/xtensa-esp32-elf/xtensa-esp32-elf/include'
# '--with-newlib'
# '--enable-threads=no'
# '--disable-shared'
# '--with-pkgversion=crosstool-NG esp-2020r3-5-gc65c037'
# '--disable-__cxa_atexit'
# '--enable-cxx-flags=-ffunction-sections'
# '--disable-libgomp'
# '--disable-libmudflap'
# '--disable-libmpx'
# '--disable-libssp'
# '--disable-libquadmath'
# '--disable-libquadmath-support'
# '--with-gmp=./.build/xtensa-esp32-elf/buildtools'
# '--with-mpfr=./.build/xtensa-esp32-elf/buildtools'
# '--with-mpc=./.build/xtensa-esp32-elf/buildtools'
# '--with-isl=./.build/xtensa-esp32-elf/buildtools'
# '--enable-lto'
# '--enable-target-optspace'
# '--without-long-double-128'
# '--disable-nls'
# '--enable-multiarch'
# '--enable-languages=c,c++'
# '--disable-libstdcxx-verbose'
# '--enable-threads=posix'
# '--enable-gcov-custom-rtio'
# '--enable-libstdcxx-time=yes'
"$srcdir"/$_basedir/configure \
--libexecdir=/usr/lib \
--prefix=/usr \
--target=$_target \
--with-gmp \
--with-gnu-as \
--with-gnu-ld \
--with-headers=/usr/$_target/include \
--with-host-libstdcxx='-static-libgcc -Wl,-Bstatic,-lstdc++,-Bdynamic -lm' \
--with-isl \
--with-libelf \
--with-mpc \
--with-mpfr \
--with-native-system-header-dir=/include \
--with-newlib \
--with-python-dir=share/gcc-$_target \
--with-sysroot=/usr/$_target \
--with-system-zlib \
--without-libffi \
--disable-__cxa_atexit \
--disable-decimal-float \
--disable-libgomp \
--disable-libmpx \
--disable-libmudflap \
--disable-libquadmath \
--disable-libquadmath-support \
--disable-libssp \
--disable-libstdcxx-pch \
--disable-libstdcxx-verbose \
--disable-nls \
--disable-shared \
--disable-threads \
--disable-tls \
--enable-gnu-indirect-function \
--enable-languages=c,c++ \
--enable-lto \
--enable-target-optspace
make INHIBIT_LIBC_CFLAGS='-DUSE_TM_CLONE_REGISTRY=0'
}
build() {
export CFLAGS="${CFLAGS/-Werror=format-security/}"
export CXXFLAGS="${CXXFLAGS/-Werror=format-security/}"
cd "$srcdir"/build-gcc
export CFLAGS_FOR_TARGET='-g -Os -ffunction-sections -fdata-sections -mlongcalls'
export CXXFLAGS_FOR_TARGET='-g -Os -ffunction-sections -fdata-sections -mlongcalls'
_build_gcc
# Build libstdc++ without exceptions support (the 'nano' variant)
cd "$srcdir"/build-gcc-nano
export CFLAGS_FOR_TARGET='-g -Os -ffunction-sections -fdata-sections -fno-exceptions -mlongcalls'
export CXXFLAGS_FOR_TARGET='-g -Os -ffunction-sections -fdata-sections -fno-exceptions -mlongcalls'
_build_gcc
}
package() {
cd "$srcdir"/build-gcc
make DESTDIR="$pkgdir" install -j1
cd "$srcdir"/build-gcc-nano
make DESTDIR="$pkgdir.nano" install -j1
# we need only libstdc nano files
multilibs=( $("$pkgdir"/usr/bin/$_target-gcc -print-multi-lib 2>/dev/null) )
for multilib in "${multilibs[@]}"; do
dir="${multilib%%;*}"
from_dir="$pkgdir".nano/usr/$_target/lib/"$dir"
to_dir="$pkgdir"/usr/$_target/lib/"$dir"
cp -f "$from_dir"/libstdc++.a "$to_dir"/libstdc++_nano.a
cp -f "$from_dir"/libsupc++.a "$to_dir"/libsupc++_nano.a
done
# strip target binaries
find "$pkgdir"/usr/lib/gcc/$_target/$pkgver "$pkgdir"/usr/$_target/lib -type f -and \( -name \*.a -or -name \*.o \) -exec $_target-objcopy -R .comment -R .note -R .debug_info -R .debug_aranges -R .debug_pubnames -R .debug_pubtypes -R .debug_abbrev -R .debug_line -R .debug_str -R .debug_ranges -R .debug_loc '{}' \;
# strip host binaries
find "$pkgdir"/usr/bin/ "$pkgdir"/usr/lib/gcc/$_target/$pkgver -type f -and \( -executable \) -exec strip '{}' \;
# Remove files that conflict with host gcc package
rm -r "$pkgdir"/usr/share/man/man7
rm -r "$pkgdir"/usr/share/info
rm "$pkgdir"/usr/lib/libcc1.*
}
# vim: ts=2 sw=0 noet
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |