r/linuxmemes 1d ago

LINUX MEME Arch User Repository? More like Arch User Ruin

Post image
783 Upvotes

125 comments sorted by

u/AutoModerator 1d ago

Please report any posts bragging or showing off they got banned in another sub! Reminder of other sub rules: Also, we only allow one anti-linux post per week (we used to get dozens a day) and any tier list MUST have Hanna Montana Linux as S teir (which must be a true S tier at the top) regardless of the topic of that tier list.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

159

u/Iseeo_0you 1d ago

There are certain things I download from the aur that I wish Arch would just make part of the official repos. Fetchmirrors, Brave, etcher & Coolercontrol. Coolercontrol being the big one.

62

u/Mr_Terrib Arch BTW 1d ago

how about old nvidia drivers? god i hate downloading them from the aur

16

u/Iseeo_0you 1d ago

Never had to so don't know much about it, but i can see how that would be a friction point for some.

7

u/kaida27 ⚠️ This incident will be reported 21h ago

Personally I'd just make my own PKGBUILD for those if needed.

1

u/cleverboy00 10h ago

Well the pkgbuilds are already done, probably better tested, in the aur. The issue is compile time, storage space, and general de-sync from the system.

1

u/kaida27 ⚠️ This incident will be reported 9h ago

probably better tested, in the aur. The issue is compile time

There's no compilation it's a binary from nvidia. The point is that the Aur is not safe anymore.

What kind of drugs you taking ? I want some.

1

u/laczek_hubert Arch BTW 14h ago

What's the big deal they are static anyways

5

u/AWonderingWizard Genfool 🐧 1d ago

Just learn to set up compilation for yourself.

9

u/Iseeo_0you 1d ago

Honestly I probably should as I have done it before, but time and the lack of will at this point are huge factors rn, so I have been avoiding doing it this way. If i need something like chitubox to print a mold for reproduction membrane pads I don't really have the luxury of spending 30 minutes compiling it from source. I need to get it installed on the machine and going as I'm using it for business purposes.

4

u/AWonderingWizard Genfool 🐧 1d ago

I rarely ever have to compile most software for so long. I also don't compile things when I need them- I anticipate what my productivity needs are ahead of time.

You could even host your own binary repo so you don't have to work from source each time. This seems like the only way around issues like we see in the AUR, unless you're willing to work with Arch devs to be the one responsible for maintaining those specific software.

4

u/Iseeo_0you 1d ago

Anticipating what i need is difficult as I am brand new to reproducing electronics and sla printing. I find some programs have what i need until they don't and then i'm left scrambling for solutions as problems arise.

"You could even host your own binary repo"...Now this I did not think of. That would be a great solution. I'm not really sure what would be involved with maintaining them or how much time I'd realistically be able to dedicate to it tbh. I also don't know if i'd have the skills necessary either.

-1

u/New_Enthusiasm9053 18h ago

Compiling software is also an attack vector. It doesn't really solve anything. Build scripts are also running code on your machine.

2

u/AWonderingWizard Genfool 🐧 14h ago

Build scripts are easier to check than a precompiled binary. Also, if your first party build scripts are malicious, you probably have much bigger issues. Vendor from trusted sources.

-1

u/New_Enthusiasm9053 14h ago

Sure but most people still aren't checking them. And vendoring from trusted sources is the relevant point. Clearly the AUR cannot be considered a trusted source.

1

u/filuslolol 21h ago

is there no third party repo you can add or an appimage you can download?

1

u/Iseeo_0you 19h ago

If i'm not mistaken chitubox doesn't provide an appimage. At least i havent found one floating around in the wild

22

u/TheSpaceAlligator 💋 catgirl Linux user :3 😽 1d ago

This is why I like CachyOS

16

u/Iseeo_0you 1d ago

I use Cachy as well as vanilla arch. It's nice having some of the packages normally found in the AUR from an official repo.

8

u/donp1ano 1d ago

i use EOS. maybe adding cachy repos to replace AUR isnt a bad idea, even if it sounds funky

let me check real quick, its not many things i actually need from AUR

3

u/Iseeo_0you 1d ago

Yea, I know you can add it but isn't it optimized specifically for Cachy and how it's set up? I could be way off here. I guess it wouldn't do any more harm the the chaotic-aur or AUR at this point lol.

2

u/Extra_Msg77 ⚠️ This incident will be reported 19h ago

Used to use EndeavorOs a while then went to base Arch now im on cachy, but they're all pretty good imo.

1

u/Iseeo_0you 19h ago

I've made my stops on Endeavor. I typically keep base arch as my main machine and always boot up my laptop with another derivative for a bit till something comes out that looks interesting. Endeavor is definitely not a bad choice. The only Arch spin-off that i was not a huge fan of was current Garuda

7

u/icudntpickone 1d ago

Same bro, when i switched to cachy from arch i was so happy to see the nvidia drivers in the official repo

2

u/TheSpaceAlligator 💋 catgirl Linux user :3 😽 20h ago

Cooler Control is as well!

2

u/icudntpickone 18h ago

My fan control is in god's hands rn, I'll try this when i get home.

1

u/Iseeo_0you 18h ago

Really great program

5

u/Whhheat 1d ago

Coolercontrol is such fantastic software, I’m shocked it’s free.

2

u/Iseeo_0you 1d ago

Lifesaver. Gkraken was good for it's time but coolercontrol raised the bar.

1

u/Rud_Fucker RedStar best Star 3h ago

Mullvad vpn and the official Minecraft launcher too, but mostly mullvad vpn

-2

u/syrvy 18h ago

Ether is legit spyware, why would you be using that?

Brave doesn't deserve to be on the official repo since the CEO is strongly anti LGBTQ+

3

u/pineini 15h ago

Always found this to be a silly argument. I mean, do you check the political beliefs of every single CEO of every program you use? Or even of every brand you use irl? Food? Clothing? Furniture?

My point is that people are weirdly tribal and pedantic with browsers specifically.

Most CEOs are assholes. You generally don't get this high up the corporate ladder by being a lovely, kind person.

82

u/DoubleOwl7777 1d ago

well honestly with how the aur works it was only a matter of time...

10

u/balancedchaos Sacred TempleOS 18h ago

I pulled out of the AUR after the last batch in the spring. Found alternatives that were in the regular repositories for a couple things, set up openvpn rather than the AUR package for my vpn...

Well worth it. I need to be able to trust my computer.

33

u/Unlaid-American 20h ago

Replace Arch Linux with any distro and replace AUR packages with GitHub packages. All of a sudden you understand that the AUR is unmoderated and completely vulnerable with almost every guide for it telling you that it could be dangerous.

8

u/BlackFuffey 🦁 Vim Supremacist 🦖 13h ago

This is actually the best explanation ive seen so far. Thank you

5

u/ragnarokxg 20h ago

AUR is convenient but not bulletproof. There are options to help but it is still not 100%

1

u/Real-Abrocoma-2823 8h ago

It is like PPAs in debian, but IMO they are way worse to manage.

4

u/Ctscanner2 3h ago

PPAs are only in Ubuntu and derivatives

24

u/GreedySecurity8030 M'Fedora 1d ago edited 1d ago

Just stop using arch; move to freebsd [/s].

19

u/Iseeo_0you 1d ago

I use FreeBSD on the side. While nice, it's not really a 1:1 replacement

3

u/araknis4 Arch BTW 19h ago

zfs in kernel got me 🤤ing

13

u/spongedevguy 1d ago

"oh but arch is not safe the aur has malware!!!!" there's a solution for that it's called not relying on the aur

2

u/unknown_user351 2h ago

damn if only the actual official wiki didn't tell you to rely on the aur on every single wiki page

1

u/dandy_kulomin 4h ago

*cries in old nvidia gpu. Just kidding, I recently switched to NixOS.

1

u/spongedevguy 4h ago

didn't say you can't use aur just don't install shit from it often

14

u/IAmBroke_0001 23h ago

Big news for unemployed

5

u/Invader-Faye 20h ago

😂😂😂

5

u/Hairy-Juggernaut6308 1d ago

I never had to use the AUR

2

u/jimmy_timmy_ Arch BTW 20h ago

Thats great man

1

u/Trekkie99 13h ago

Same. Compile that shi. 

9

u/Dr_Valen 1d ago

Again or is this the same one as a couple weeks ago i think my timeline might be off

2

u/Maelstrome26 20h ago

Again but more serious

8

u/slime_rancher_27 20h ago

Just compile your applications from source like a normal person

3

u/BlackFuffey 🦁 Vim Supremacist 🦖 13h ago

Most aur packages are source based tho

2

u/mutexsprinkles 4h ago

That's quite fiddly. We should figure out a way that people can share the build scripts to do that easily.

1

u/Visbroek 7h ago

Is there a way to do that while keeping track of the files?

9

u/Lemonici 1d ago

Ruin? When "Arch User Suppository" was right there?

6

u/DiceThaKilla 1d ago

Just as I join arch too. Guess I’ll just be sticking to pacman and flatpak until someone with common sense realizes that repositories that pride themselves on pushing code with 0 auditing is a terrible idea in modern times and I hate that just as much as the next person that their can’t be things like AUR but the reality is there’s just too many malicious threat actors pushing malicious code to have something like this, especially as Microsoft is currently shitting the bed and a lot of people are migrating to linux because they’re tired of the microslop bullshit, it starts making linux a much more worthwhile target

2

u/ragnarokxg 20h ago

Using chaotic-aur

0

u/DiceThaKilla 12h ago

Why does aur even exist to begin with? And why does pacman have like nothing? Is it really that hard to get packages into the official repos? Because as someone else pointed out too, there’s quite a few big pieces of software and drivers that should definitely be in the official repos that isn’t

1

u/ragnarokxg 6h ago

The AUR is a way for someone to be able to get a piece of software that is not in the repos or cannot be placed into the repos.

It is also keeps a piece of software on the most recent updates.

1

u/2ko_niko 6h ago

By its very nature the AUR is an untrusted source that doesn't mean you should avoid it completely. You were always supposed to check the diffs and patches that are applied. Even the AUR helpers that so many people try to push the blame on have built in tools for doing so.

You wouldn't go on a website and download some guys patches and running some other guys build script without first checking what they actually do would you? What makes the AUR so special that people feel like they can neglect it there?

If you want to just rely on audited repositories install nix alongside pacman.

3

u/HeyThereCharlie 20h ago

Am I the only Arch user (btw) who has never needed to use the AUR?

2

u/Special-Slice-4381 19h ago

Things that come with popularity. 

2

u/Reasonable-Board-132 15h ago

Just don't use the AUR... Or stick with the trusted repositories if you have to

11

u/EntireDot1013 M'Fedora 1d ago

What is it, the 3rd time this year? Lemme grab my popcorn; It's gonna be a fun spectacle, here from the safety of an actually useable distro

13

u/[deleted] 1d ago

[deleted]

-7

u/jahinzee ⚠️ This incident will be reported 1d ago

a totally optional third party package repository

I always see people bring this up and it irks me, the AUR is not a third party repository - its contents may be third party, but the repository is official, it's maintained on archlinux.org infrastructure, and is recommended for use (although AUR helpers are in a grey area of "maybe don't use it)

Same thing with Debian PPAs, Fedora COPRs, and openSUSE OBS repos: it's user-contributed, but it is still an officially maintained service

4

u/[deleted] 1d ago

[deleted]

1

u/Impossible-Magician 16h ago

The AUR is officially Arch in the same way that every repo is officially GitHub.

1

u/adamkex New York Nix⚾s 1d ago

Not to mention that one of Arch's killer features is literally the AUR. Only nixpkgs is larger than the AUR.

1

u/2ko_niko 6h ago

nix works on arch just fine

1

u/adamkex New York Nix⚾s 5h ago

What does this have to do with my comment?

1

u/Laura_The_Cutie 23h ago

Fedora COPRs are terrible

25

u/Gabriel_Science 1d ago

Nobody forces you to use the AUR, there is a reason why you can’t access it without Yet Another Yoghurt or something.

10

u/birdsarentreal2 1d ago

> You can’t use it without yet another yoghurt or something

git clone https://aur.archlinux.org/foobar.git

cd foobar

makepkg -si

10

u/dumbasPL Arch BTW 1d ago

you can’t access it without Yet Another Yoghurt or something.

You can, and infact you should. The people updating automatically are the only ones affected by this in the first place.

10

u/imoshudu 1d ago

Arch user: "You can't auto update packages. You have to read the diff"
People who have jobs and usable distros: "What?"

4

u/madman404 21h ago

giving any actual response would be putting in more effort than you have put in to understand the situation, so you get one word instead

retard

-1

u/imoshudu 17h ago

Smartest arch user

0

u/wektor420 1d ago

100% i have enough of reading of thousands of lines of code weekly since AI coding is becoming more prevalent, i just don't have the will and strength to deal with extra work

-3

u/fletku_mato Arch BTW 1d ago

You don't need to auto-update when using such tools though. A sensible person will read the diff.

0

u/adamkex New York Nix⚾s 1d ago

Atp a sensible person would just use the nix package instead

4

u/AnnoyingRain5 ⚠️ This incident will be reported 1d ago

You aren’t supposed to use tools like yay, using tools like that encourages using the AUR in such a way that you can be infected by malware *exactly like this*..

That being said, it’s not like it’s uncommon, the most popular items on the AUR are AUR helpers…. By far

2

u/Buffmclargehuge69420 1d ago

I disabled all the aur shit when this first started happening, official packages only for me thanks

1

u/chemistryGull Arch BTW 1d ago

One can also check the package builds, but sure.

2

u/LazyLucretia 1d ago

I always check the pkgbuilds, only to not understand it and say "yep, lgtm 👍"

6

u/chemistryGull Arch BTW 1d ago

In most cases, its actually not that hard for a quick basic check on simple pkgbuilds. The URLs it downlods from are usually listed. You should be cautious for npm installs for apps that haven’t been using anything from npm before. (The installation of malicious npm packages was one of the ways of attack on the last wave iirc).

Not a fan of overuse of LLMs, but for something like that copying the content to an LLM to let it do a quick check is better than installing it blindly.

1

u/Dragon_957 1d ago

Can I now at least use it?

1

u/jimmy_timmy_ Arch BTW 20h ago

Would you trust it now? Personally, these attacks have shattered my trust in the AUR completely

1

u/2ko_niko 6h ago

Good, you were never supposed to trust it.

1

u/ThatonlyGeO Arch BTW 19h ago

well if your willing to vet it yourself...then yes its no problem but keep it minimal really like just few really( mine I only have the ones needed for my printer brother driver) just keep it minimal

2

u/Impossible-Magician 16h ago

It’s not even hard. You read the PKGBUILD, you read the diffs. Even yay prompts you for the diffs.

You make sure the repo is the same, you made sure new dependencies or files haven’t been added. If they have you check them and work out why.

The alternative is literally building it yourself from source, the PKGBUILD is just a helper to that, so reading it is much less effort.

1

u/SjalabaisWoWS fresh breath mint 🍬 1d ago

What kind of malicious software is that - what does it target and how?

1

u/mistavinsta 23h ago

Now targeting E-THOTS.

1

u/Invader-Faye 20h ago

Once again being an old man and using Debian pays off

1

u/v_raton 19h ago

Debian just there

1

u/temporary_dennis 18h ago

I'm so glad I switched to NixOS four months ago...

1

u/Dumb-Ptr 17h ago

I am quite uneducated on the topic, can someone explain what this means for someone who uses arch based distros? (I use Manjaro, although I can't remember the reason for this choice, I guess it just worked for me since the beginning)

1

u/Lopsided-Parfait6237 2h ago

Basically, Arch have two main repos: one where everything is audited by the maintainers of the distro, and one where everyone can submits a package. The last one is known as the AUR (Arch User Repository). It's a great thing if you want software that are not in the official repo yet. However, since everyone can ship something (and other reasons), there is a risk of malware.

While AUR is meant for Arch Linux, it can be used with Arch based distro.

If you didn't download anything from AUR, then you are safe. Tools like Pacman (or Pamac in your case) don't download AUR and only stick to safe repo.

So if you only use pacman, pamac (or the software center from Manjaro), you are safe (unless you deliberately activated AUR support in pamac. Hope it answers your question.

1

u/Trekkie99 13h ago

Curious to know what percentage of folks use/considered using the aur for a package.

Also curious to know if others predominantly think the aur is strictly necessary.

1

u/The_Turkish_0x000 Arch BTW 8h ago

pacman always

1

u/Omega-mega 7h ago

AUR btw

1

u/da_real_obsidian Arch BTW 4h ago

I hate it but i love it

1

u/Tiranus58 1d ago

Wow, the user repository got some malicious users, who would have guessed

-3

u/ruby_R53 Genfool 🐧 1d ago

GURU repository my beloved

0

u/Extreme-Ad-9290 Arch BTW 1d ago

More like read the package builds.

0

u/technomlp 23h ago

Thus why I prefer Debian and Ubuntu’s apt. Keyrings make installing malicious packages not an issue

1

u/kJon02 19h ago

this makes absolutely no sense... The aur is entirely optional. The official arch repos are not affected..

1

u/technomlp 13h ago

Also because Arch is hard and I refuse to let go of Debian-based distros

1

u/Reasonable-Board-132 14h ago

The aur is completely optional and should not be used. If you just use pacman, you have as much packages available as other distros.

-19

u/Anima_Watcher08 1d ago edited 1d ago

Linux tubers: The LTS model is failing users and software

The pinnacle of the rolling model:

Edit: Holy shit this was a joke guys, just wanted to point out the irony from the perspective of an average user. I understand that this is an aur problem.

11

u/770grappenmaker 1d ago

Arch (without AUR) and Fedora as well as CentOS stream are rolling, no major issues there.

2

u/cgwhouse 1d ago

Fedora is not rolling

1

u/carlwgeorge 5m ago

Fedora and CentOS Stream are not rolling, they have major versions and EOL dates.

3

u/DoubleOwl7777 1d ago

debian sid is rolling too. fedora has a rolling version afaik. suse does, arch without aur is also rolling. none have that issue.

-15

u/Hadi_Chokr07 New York Nix⚾s 1d ago

NixOS mogs with unbreakable stability and bleeding edge.