在 Sat, Aug 01, 2026 at 07:34:46PM +0200,Ralf Mardorf 写道:
> Hi,
> 
> On Sat, 2026-08-01 at 21:43 +0530, Amal krishna wrote:
> > Hi team,
> > Does the list also include malware?
> >
> > On Sat, 1 Aug, 2026, 8:47 pm firstpick1992 wrote:
> >> 27 more infected AUR packages contain malware executed via sudo during 
> >> builds:
>    
> ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
> 
> although the package list contained malware, the mailing list does not.
> 
> By the way, maybe we should consider using an alias for "makepkg":
> 
>   sudo -k && makepkg
> 
> At the very least, this ensures that, if we run a command with "sudo"
> before running "makepkg" as a user, "sudo" cannot run automatically
> during the build process. Or am I missing something here?

I do have an alias for makepkg (alongside with npm etc), and it is a little 
complex:

_makepkg_prefix=(
  bwrap --unshare-all --share-net --die-with-parent
  --ro-bind /usr /usr --ro-bind /opt /opt --ro-bind /etc /etc --proc /proc 
--dev /dev --tmpfs /tmp
  --symlink usr/bin /bin --symlink usr/bin /sbin --symlink usr/lib /lib 
--symlink usr/lib /lib64
  --ro-bind /var/lib/pacman /var/lib/pacman --bind ~/.cache ~/.cache
  --bind ~/.makepkg/gnupg ~/.gnupg
  # work around 
https://github.com/containers/bubblewrap/issues/395#issuecomment-771159189
  --setenv FAKEROOTDONTTRYCHOWN 1
)
_makepkg_setup () {
  mkdir -m 700 -p ~/.makepkg/gnupg
  ${_makepkg_prefix[@]} --bind $PWD /build --chdir /build "$@"
}
makepkg () {
  _makepkg_setup /usr/bin/makepkg "$@"
}
compdef makepkg=makepkg
updpkgsums () {
  _makepkg_setup /usr/bin/updpkgsums
}

This is zsh btw.

-- 
Best regards,
lilydjwg

Reply via email to