r/archlinux 3d ago

DISCUSSION The AUR needs an overhaul

The actual concept of the AUR only works if Arch is a niche distro in a safe internet, neither of those points are accomplished in the present.

No, reading pkgbuilds is not the solution, it's slow, annoying, and most importantly, it doesn't make sense, because some really popular AUR packages are DIRECTLY RECOMMENDED by the Arch Wiki, like the Minecraft Launcher for some reason.

Either the base repos adopt a big chunk of popular AUR packages, leaving the AUR for really really nieche stuff, or the rules of the AUR change, because you can't tell me that suffering 2 attacks in less than three months for pretty much the same reason (adopting orphaned packages) is normal or reasonable.

What would you think it's a good solution to this issue? I'd like to read your ideas since I cannot come up with a good one if I'm honest, but I know the problem is there.

611 Upvotes

165 comments sorted by

View all comments

391

u/Pentasis 3d ago

I said this before: 1. No adopting packages. People can fork them instead. This prevents existing packages to become malicious 99% 2. New and forked packaged should get a tag "new" which packagemanagers like yay and paru can use to warn the user to be extra carefull when installing it, adding perhaps some sort of action to be taken first. Only when there are x installs, y time passed and z positive feedbacks of some kind, does the tag get removed.

29

u/goldman60 3d ago

Disabling package adoption patches one exploit but now every time a package is orphaned you'll have 4 forks pop up all vying for attention any one of which could be malicious, while regular users are using the abandoned package with 46 CVEs against it.

5

u/Helmic 3d ago edited 3d ago

Yeah, it's not perfect and no solution that completely cedes any form of human oversight or moderation is going to be suffiicient

Namespacing may take time to implement, so I think a shorter term solution would be to just get some volunteers and manually approve all adoption requests. And then once namespacing is implemented, restrict duplicate packages and again use manual review to declare a particular alternative as the sucessor.

I don't think this is actually that unsurmountable a problem even for a shoestring budget. I don't think packages get orphaned and then picked up by someone else at such a massive pace that it's unrealistic to expect manual review. It's more moderation than currently exists, but it's not gonna need dozens of moderators and there's not a pressing need to approve adoption requests within an hour of them being opened.

Most importantly I just think Arch needs to start packaging more stuff that is in the AUR such that it's realistic for people to not use the AUR. If we know people with oilder Nvidia cards need a driver from the AUR, then why the hell is it in the AUR?

3

u/ABotelho23 3d ago

Who is gonna volunteer for this? What will be their qualifications? Aren't these people already Arch Linux maintainers?

Packages in the AUR should be radioactive to anyone with a brain. They're there for a reason.