Arch Linux disables AUR package adoption

(lwn.net)

50 points | by database64128 3 hours ago

8 comments

  • WD-42 26 minutes ago
    I’ve been using arch for nearly 2 decades at this point. It’s amazing that the AUR went this long without any serious attacks.

    It’s a different world now. I can’t help but feel there used to be honor among hackers. You didn’t go after your own. What kind of jerk would attack Arch Linux?

    • sp0rk 15 minutes ago
      > I can’t help but feel there used to be honor among hackers. You didn’t go after your own. What kind of jerk would attack Arch Linux?

      This has absolutely not ever been the case.

    • jolmg 8 minutes ago
      Arch is simply getting popular enough to be targeted.
    • charcircuit 24 minutes ago
      Desktop Linux has always been a house of cards in regards to security. I agree it's amazing that it went on for so long, but this was inevitable.
      • zahlman 0 minutes ago
        More so than, say, Windows? Really?

        And no, "people using one Linux distro can opt in to possibly getting pwned by each other by making use of a third-party software depot" does not reflect upon the entirety of the Linux world.

      • tempfile 4 minutes ago
        I disagree. Maintainers for the major distributions take their roles very seriously, and do a very good job generally of filtering out malicious packages. The AUR is an outlier, being essentially an unmaintained wild west.
  • uticus 5 minutes ago
    WRT package vulns, I'm surprised there's not more technical theory out there. We have plenty of theory around algorithm design, but so far I haven't heard much about inspecting and improving control of dependencies in source - apart from conflict and version management.

    Seems like instead of big-O notation, we could have a "reach index" - how far does the top-level code need to reach, to be effective? Top-level -> Userland lib 1 -> Userland lib 2 -> Kernel, would be a reach level "4" - not the simplest, but much simpler to inspect and securely build than reach level "20".

  • dandersch 18 minutes ago
    I think Arch has to rethink what the AUR really is for in the age of AI.

    If users aren't supposed to trust anything from the AUR, then they will start to use LLMs to scan PKGBUILDs for them. But at that point, why not let the LLM loose directly on the upstream repo and build+install the package from source?

  • uticus 10 minutes ago
    From the actual announcement:

    > ...package adoption is currently disabled while we are handling the situation.

    Sounds much more like the temporary pause, than the much less temporary-sounding "has been disabled" from the OP.

  • tim-projects 12 minutes ago
    I added a git repo to AUR last year. It was super easy with basically no checks of any kind. Once these reports came out recently, I went through and deleted every AUR package that I could.
  • delecti 56 minutes ago
    That title had me worried, but the reality seems quite reasonable.

    I assumed the goal was to reduce usage of AUR, they've actually remove the ability to adopt (take ownership of) orphaned packages. I'm sure there are legitimate uses of that functionality, but it also seems like a pretty big avenue for abuse.

    • OJFord 45 minutes ago
      I've used it (not for abuse). It's simply volunteering to maintain the package after previous maintainer(s) have explicitly disowned it, knowing they no longer have time for it or don't care because they stopped using it, etc.
      • gchamonlive 31 minutes ago
        Problem is that there is no KYC process before someone can adopt any orphaned package
    • ameliaquining 42 minutes ago
      Yeah, the security problems with unilateral adoption of orphaned packages by unprivileged users are fundamental and unfixable; the only remedy is to remove the feature. Whether it has legitimate use cases (which it sounds like it does) is irrelevant. I'm not sure why it took them so long to realize this and act accordingly, but I'm glad they now have.
  • Sleaker 41 minutes ago
    I don't think any form of automated adoption of orphaned packages will ever work, it's just too easy to introduce malicious code into an otherwise functional but no longer maintained source.
  • charcircuit 26 minutes ago
    AUR should be scanning new uploads for malware before allowing them to be published.
    • tempfile 2 minutes ago
      What does "scanning for malware" mean? As far as I know this is a totally open question, and the only credible answers (install in a sandbox) are too inconvenient for widespread adoption.