Request #87172 has been Rejected by Auerhuhn [1]: Hi Emiliano,
thanks for your request and taking your time to address this issue. Like many other users who have posted on aur-general lately, you seem to care about trust and that AUR users are safe. I find that commendable. So, thank you for being a good upstream maintainer and AUR citizen. However, I regret to say that I have decided to close your deletion request. I’m personally convinced that trust chains are a helpful instrument. The AUR’s trust model, however, doesn’t involve the kind of chain of trust you seem to be aiming for. We’ve had an incident last week where an upstream maintainer was also the PKGBUILD author, and their upstream project source included malicious code. We were extremely lucky to have AUR users flag the PKGBUILD quickly, so not much damage was done. But the plot twist that came up during the post mortem when another user looked at the IOCs [0] is that the upstream maintainer was most likely **completely benign** though reckless, and they got their dev machine infected by a known nasty worm which had sneakily amended upstream Git commits with a dropper that allowed the worm to spread, and snuck it onto upstream via force push. Their security hygiene was poor but that’s not the point. The point is that from an AUR user’s point of view, there’s no difference in whether a third party packager owns a PKGBUILD or the upstream author itself. The AUR user may trust any of them, or both, but it’s ultimately not helpful, they have to audit what they’re installing. One chain of trust that *may* actually emerge specifically in the case of Trustsight is that once a user has bootstrapped Trustsight, they’re always free to use it to audit its own successor. So the problem you’re proposing (“disrupting the trust chain”) is actually just a one-time concern. I think you’ll agree that this fact weakens your case somewhat. There are two things you can do that I’d like you to be aware of: 1. you’re free to contact the PKGBUILD owner and ask them to add you as a co-maintainer; 2. regardless of whether they’ll accept your request, you can subscribe to the PKGBUILD, which sends you emails about future uploads, and you’re free to have that email notification trigger your tool to re-assess the PKGBUILD safety/security if you want, and in case it finds the PKGBUILD has gone rogue, flag it on the list and we’ll act (hopefully) within minutes. Even though I think it’s cool that you seem to care deeply about AUR safety, the AUR deliberately allows third parties to own a PKGBUILD, even if the upstream author objects to that, or if they object to the fact that the PKGBUILD is on the AUR in the first place. I trust that to a degree, you’ll understand that I’m going to close your request. Thanks again for your work and for continuing to be a vigilant AUR citizen. Regards Claudia [0]: https://lists.archlinux.org/archives/list/aur- [email protected]/message/ST4RIYSBS5IAIZ4PVNGW2LQEGBUL7I2L/ [1] https://aur.archlinux.org/account/Auerhuhn/
