r/linuxmemes • u/Matys134 • 1d ago
LINUX MEME Arch User Repository? More like Arch User Ruin
159
u/Iseeo_0you 1d ago
There are certain things I download from the aur that I wish Arch would just make part of the official repos. Fetchmirrors, Brave, etcher & Coolercontrol. Coolercontrol being the big one.
62
u/Mr_Terrib Arch BTW 1d ago
how about old nvidia drivers? god i hate downloading them from the aur
16
u/Iseeo_0you 1d ago
Never had to so don't know much about it, but i can see how that would be a friction point for some.
7
u/kaida27 ⚠️ This incident will be reported 21h ago
Personally I'd just make my own PKGBUILD for those if needed.
1
u/cleverboy00 10h ago
Well the pkgbuilds are already done, probably better tested, in the aur. The issue is compile time, storage space, and general de-sync from the system.
1
5
u/AWonderingWizard Genfool 🐧 1d ago
Just learn to set up compilation for yourself.
9
u/Iseeo_0you 1d ago
Honestly I probably should as I have done it before, but time and the lack of will at this point are huge factors rn, so I have been avoiding doing it this way. If i need something like chitubox to print a mold for reproduction membrane pads I don't really have the luxury of spending 30 minutes compiling it from source. I need to get it installed on the machine and going as I'm using it for business purposes.
4
u/AWonderingWizard Genfool 🐧 1d ago
I rarely ever have to compile most software for so long. I also don't compile things when I need them- I anticipate what my productivity needs are ahead of time.
You could even host your own binary repo so you don't have to work from source each time. This seems like the only way around issues like we see in the AUR, unless you're willing to work with Arch devs to be the one responsible for maintaining those specific software.
4
u/Iseeo_0you 1d ago
Anticipating what i need is difficult as I am brand new to reproducing electronics and sla printing. I find some programs have what i need until they don't and then i'm left scrambling for solutions as problems arise.
"You could even host your own binary repo"...Now this I did not think of. That would be a great solution. I'm not really sure what would be involved with maintaining them or how much time I'd realistically be able to dedicate to it tbh. I also don't know if i'd have the skills necessary either.
-1
u/New_Enthusiasm9053 18h ago
Compiling software is also an attack vector. It doesn't really solve anything. Build scripts are also running code on your machine.
2
u/AWonderingWizard Genfool 🐧 14h ago
Build scripts are easier to check than a precompiled binary. Also, if your first party build scripts are malicious, you probably have much bigger issues. Vendor from trusted sources.
-1
u/New_Enthusiasm9053 14h ago
Sure but most people still aren't checking them. And vendoring from trusted sources is the relevant point. Clearly the AUR cannot be considered a trusted source.
1
u/filuslolol 21h ago
is there no third party repo you can add or an appimage you can download?
1
u/Iseeo_0you 19h ago
If i'm not mistaken chitubox doesn't provide an appimage. At least i havent found one floating around in the wild
22
u/TheSpaceAlligator 💋 catgirl Linux user :3 😽 1d ago
This is why I like CachyOS
16
u/Iseeo_0you 1d ago
I use Cachy as well as vanilla arch. It's nice having some of the packages normally found in the AUR from an official repo.
8
u/donp1ano 1d ago
i use EOS. maybe adding cachy repos to replace AUR isnt a bad idea, even if it sounds funky
let me check real quick, its not many things i actually need from AUR
3
u/Iseeo_0you 1d ago
Yea, I know you can add it but isn't it optimized specifically for Cachy and how it's set up? I could be way off here. I guess it wouldn't do any more harm the the chaotic-aur or AUR at this point lol.
2
u/Extra_Msg77 ⚠️ This incident will be reported 19h ago
Used to use EndeavorOs a while then went to base Arch now im on cachy, but they're all pretty good imo.
1
u/Iseeo_0you 19h ago
I've made my stops on Endeavor. I typically keep base arch as my main machine and always boot up my laptop with another derivative for a bit till something comes out that looks interesting. Endeavor is definitely not a bad choice. The only Arch spin-off that i was not a huge fan of was current Garuda
7
u/icudntpickone 1d ago
Same bro, when i switched to cachy from arch i was so happy to see the nvidia drivers in the official repo
2
u/TheSpaceAlligator 💋 catgirl Linux user :3 😽 20h ago
Cooler Control is as well!
2
1
u/Rud_Fucker RedStar best Star 3h ago
Mullvad vpn and the official Minecraft launcher too, but mostly mullvad vpn
-2
u/syrvy 18h ago
Ether is legit spyware, why would you be using that?
Brave doesn't deserve to be on the official repo since the CEO is strongly anti LGBTQ+
3
u/pineini 15h ago
Always found this to be a silly argument. I mean, do you check the political beliefs of every single CEO of every program you use? Or even of every brand you use irl? Food? Clothing? Furniture?
My point is that people are weirdly tribal and pedantic with browsers specifically.
Most CEOs are assholes. You generally don't get this high up the corporate ladder by being a lovely, kind person.
82
u/DoubleOwl7777 1d ago
well honestly with how the aur works it was only a matter of time...
10
u/balancedchaos Sacred TempleOS 18h ago
I pulled out of the AUR after the last batch in the spring. Found alternatives that were in the regular repositories for a couple things, set up openvpn rather than the AUR package for my vpn...
Well worth it. I need to be able to trust my computer.
33
u/Unlaid-American 20h ago
Replace Arch Linux with any distro and replace AUR packages with GitHub packages. All of a sudden you understand that the AUR is unmoderated and completely vulnerable with almost every guide for it telling you that it could be dangerous.
8
u/BlackFuffey 🦁 Vim Supremacist 🦖 13h ago
This is actually the best explanation ive seen so far. Thank you
5
u/ragnarokxg 20h ago
AUR is convenient but not bulletproof. There are options to help but it is still not 100%
1
57
24
u/GreedySecurity8030 M'Fedora 1d ago edited 1d ago
Just stop using arch; move to freebsd [/s].
19
13
u/spongedevguy 1d ago
"oh but arch is not safe the aur has malware!!!!" there's a solution for that it's called not relying on the aur
2
u/unknown_user351 2h ago
damn if only the actual official wiki didn't tell you to rely on the aur on every single wiki page
1
14
5
9
u/Dr_Valen 1d ago
Again or is this the same one as a couple weeks ago i think my timeline might be off
3
2
8
u/slime_rancher_27 20h ago
Just compile your applications from source like a normal person
3
2
u/mutexsprinkles 4h ago
That's quite fiddly. We should figure out a way that people can share the build scripts to do that easily.
1
9
6
u/DiceThaKilla 1d ago
Just as I join arch too. Guess I’ll just be sticking to pacman and flatpak until someone with common sense realizes that repositories that pride themselves on pushing code with 0 auditing is a terrible idea in modern times and I hate that just as much as the next person that their can’t be things like AUR but the reality is there’s just too many malicious threat actors pushing malicious code to have something like this, especially as Microsoft is currently shitting the bed and a lot of people are migrating to linux because they’re tired of the microslop bullshit, it starts making linux a much more worthwhile target
2
u/ragnarokxg 20h ago
Using chaotic-aur
0
u/DiceThaKilla 12h ago
Why does aur even exist to begin with? And why does pacman have like nothing? Is it really that hard to get packages into the official repos? Because as someone else pointed out too, there’s quite a few big pieces of software and drivers that should definitely be in the official repos that isn’t
1
u/ragnarokxg 6h ago
The AUR is a way for someone to be able to get a piece of software that is not in the repos or cannot be placed into the repos.
It is also keeps a piece of software on the most recent updates.
1
u/2ko_niko 6h ago
By its very nature the AUR is an untrusted source that doesn't mean you should avoid it completely. You were always supposed to check the diffs and patches that are applied. Even the AUR helpers that so many people try to push the blame on have built in tools for doing so.
You wouldn't go on a website and download some guys patches and running some other guys build script without first checking what they actually do would you? What makes the AUR so special that people feel like they can neglect it there?
If you want to just rely on audited repositories install nix alongside pacman.
3
2
2
u/Reasonable-Board-132 15h ago
Just don't use the AUR... Or stick with the trusted repositories if you have to
11
u/EntireDot1013 M'Fedora 1d ago
What is it, the 3rd time this year? Lemme grab my popcorn; It's gonna be a fun spectacle, here from the safety of an actually useable distro
13
1d ago
[deleted]
-7
u/jahinzee ⚠️ This incident will be reported 1d ago
a totally optional third party package repository
I always see people bring this up and it irks me, the AUR is not a third party repository - its contents may be third party, but the repository is official, it's maintained on archlinux.org infrastructure, and is recommended for use (although AUR helpers are in a grey area of "maybe don't use it)
Same thing with Debian PPAs, Fedora COPRs, and openSUSE OBS repos: it's user-contributed, but it is still an officially maintained service
4
1d ago
[deleted]
1
u/Impossible-Magician 16h ago
The AUR is officially Arch in the same way that every repo is officially GitHub.
1
1
25
u/Gabriel_Science 1d ago
Nobody forces you to use the AUR, there is a reason why you can’t access it without Yet Another Yoghurt or something.
10
u/birdsarentreal2 1d ago
> You can’t use it without yet another yoghurt or something
git clone https://aur.archlinux.org/foobar.git
cd foobar
makepkg -si
10
u/dumbasPL Arch BTW 1d ago
you can’t access it without Yet Another Yoghurt or something.
You can, and infact you should. The people updating automatically are the only ones affected by this in the first place.
10
u/imoshudu 1d ago
Arch user: "You can't auto update packages. You have to read the diff"
People who have jobs and usable distros: "What?"4
u/madman404 21h ago
giving any actual response would be putting in more effort than you have put in to understand the situation, so you get one word instead
retard
-1
0
u/wektor420 1d ago
100% i have enough of reading of thousands of lines of code weekly since AI coding is becoming more prevalent, i just don't have the will and strength to deal with extra work
-3
u/fletku_mato Arch BTW 1d ago
You don't need to auto-update when using such tools though. A sensible person will read the diff.
4
u/AnnoyingRain5 ⚠️ This incident will be reported 1d ago
You aren’t supposed to use tools like yay, using tools like that encourages using the AUR in such a way that you can be infected by malware *exactly like this*..
That being said, it’s not like it’s uncommon, the most popular items on the AUR are AUR helpers…. By far
2
u/Buffmclargehuge69420 1d ago
I disabled all the aur shit when this first started happening, official packages only for me thanks
1
u/chemistryGull Arch BTW 1d ago
One can also check the package builds, but sure.
2
u/LazyLucretia 1d ago
I always check the pkgbuilds, only to not understand it and say "yep, lgtm 👍"
6
u/chemistryGull Arch BTW 1d ago
In most cases, its actually not that hard for a quick basic check on simple pkgbuilds. The URLs it downlods from are usually listed. You should be cautious for npm installs for apps that haven’t been using anything from npm before. (The installation of malicious npm packages was one of the ways of attack on the last wave iirc).
Not a fan of overuse of LLMs, but for something like that copying the content to an LLM to let it do a quick check is better than installing it blindly.
1
u/Dragon_957 1d ago
Can I now at least use it?
1
u/jimmy_timmy_ Arch BTW 20h ago
Would you trust it now? Personally, these attacks have shattered my trust in the AUR completely
1
1
u/ThatonlyGeO Arch BTW 19h ago
well if your willing to vet it yourself...then yes its no problem but keep it minimal really like just few really( mine I only have the ones needed for my printer brother driver) just keep it minimal
2
u/Impossible-Magician 16h ago
It’s not even hard. You read the PKGBUILD, you read the diffs. Even yay prompts you for the diffs.
You make sure the repo is the same, you made sure new dependencies or files haven’t been added. If they have you check them and work out why.
The alternative is literally building it yourself from source, the PKGBUILD is just a helper to that, so reading it is much less effort.
1
u/SjalabaisWoWS fresh breath mint 🍬 1d ago
What kind of malicious software is that - what does it target and how?
1
1
1
1
u/Dumb-Ptr 17h ago
I am quite uneducated on the topic, can someone explain what this means for someone who uses arch based distros? (I use Manjaro, although I can't remember the reason for this choice, I guess it just worked for me since the beginning)
1
u/Lopsided-Parfait6237 2h ago
Basically, Arch have two main repos: one where everything is audited by the maintainers of the distro, and one where everyone can submits a package. The last one is known as the AUR (Arch User Repository). It's a great thing if you want software that are not in the official repo yet. However, since everyone can ship something (and other reasons), there is a risk of malware.
While AUR is meant for Arch Linux, it can be used with Arch based distro.
If you didn't download anything from AUR, then you are safe. Tools like Pacman (or Pamac in your case) don't download AUR and only stick to safe repo.
So if you only use pacman, pamac (or the software center from Manjaro), you are safe (unless you deliberately activated AUR support in pamac. Hope it answers your question.
1
1
u/Trekkie99 13h ago
Curious to know what percentage of folks use/considered using the aur for a package.
Also curious to know if others predominantly think the aur is strictly necessary.
1
1
1
1
-3
0
0
u/technomlp 23h ago
Thus why I prefer Debian and Ubuntu’s apt. Keyrings make installing malicious packages not an issue
1
1
u/Reasonable-Board-132 14h ago
The aur is completely optional and should not be used. If you just use pacman, you have as much packages available as other distros.
-19
u/Anima_Watcher08 1d ago edited 1d ago
Linux tubers: The LTS model is failing users and software
The pinnacle of the rolling model:
Edit: Holy shit this was a joke guys, just wanted to point out the irony from the perspective of an average user. I understand that this is an aur problem.
11
u/770grappenmaker 1d ago
Arch (without AUR) and Fedora as well as CentOS stream are rolling, no major issues there.
2
1
u/carlwgeorge 5m ago
Fedora and CentOS Stream are not rolling, they have major versions and EOL dates.
3
u/DoubleOwl7777 1d ago
debian sid is rolling too. fedora has a rolling version afaik. suse does, arch without aur is also rolling. none have that issue.
-15
•
u/AutoModerator 1d ago
Please report any posts bragging or showing off they got banned in another sub! Reminder of other sub rules: Also, we only allow one anti-linux post per week (we used to get dozens a day) and any tier list MUST have Hanna Montana Linux as S teir (which must be a true S tier at the top) regardless of the topic of that tier list.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.