still failling on a regular brave-bin package #7
Labels
No labels
Agent/Autonomous OK
Agent/Demeter
Agent/Hermes
Agent/Human
Agent/Needs Review
Area/API
Area/Auth
Area/CLI
Area/Data
Area/Docs
Area/Infra
Area/UI
CI/Failing
CI/Flaky
CI/Green
CI/Needs Runner
CI/Needs Workflow
Compat/Backward Compatible
Compat/Breaking
Compat/Migration
Deploy/Ansible
Deploy/Blocked
Deploy/Homelab
Deploy/Needs Config
Deploy/Needs Secret
Deploy/Ready
Deploy/Rollback
Kind/Bug
Kind/Chore
Kind/Design
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Refactor
Kind/Security
Kind/Spike
Kind/Testing
Ops/Backup
Ops/Incident
Ops/Maintenance
Ops/Monitoring
Ops/Upgrade
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Priority
Someday
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Risk
Critical
Risk
High
Risk
Low
Risk
Medium
Security/Auth
Security/Disclosure
Security/Hardening
Security/Secret
Size
L
Size
M
Size
S
Size
XL
Size
XS
Stack/Ansible
Stack/Docker
Stack/Forgejo
Stack/Hermes
Stack/Node
Stack/Postgres
Stack/Python
Stack/Systemd
Status
Abandoned
Status
Blocked
Status
In Progress
Status
In Review
Status
Need More Info
Status
Ready
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
2027a/paru-llm-audit#7
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
:: Looking for PKGBUILD upgrades...
:: Recherche des mises à jour pour les paquets de l'AUR...
:: Recherche de mises à jour pour les paquets devel...
:: Résolution des dépendances...
:: Calcul des conflits...
:: Calcul des conflits internes...
Aur (5) Ancienne Version Nouvelle Version Make Only
aur/brave-bin 1:1.93.138-1 1:1.94.117-1 Non
aur/netbird-ui-bin 0.77.0-1 0.77.1-1 Non
aur/pandoc-bin 3.10.2-1 3.11-1 Non
aur/t3code-bin 0.0.33-1 0.0.36-1 Non
aur/teams-for-linux-bin 2.17.0-1 2.17.1-1 Non
:: Procéder à la relecture ? [O/n]
:: Téléchargement des PKGBUILDs...
PKGBUILDs à jour
[paru-llm-audit] package=brave-bin version=1:1.94.117-1
[paru-llm-audit] LLM model=gpt-5.6-luna risk=MEDIUM verdict=REVIEW confidence=0.96
[paru-llm-audit] LLM summary: The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available.
[paru-llm-audit] HIGH static PKGBUILD:52: Setuid or file capabilities configured — chmod 475
[paru-llm-audit] HIGH llm PKGBUILD:52: Setuid sandbox executable installed — PKGBUILD package() runs
chmod 4755 "$pkgdir/opt/brave-bin/chrome-sandbox"(static finding identifieschmod 475at line 52). This grants setuid-root behavior to the browser sandbox binary.[paru-llm-audit] INFO llm PKGBUILD:30: Official remote binary sources with checksums — PKGBUILD downloads versioned x86_64 and aarch64 archives from
https://github.com/brave/brave-browser/releases/download/v${pkgver}/...and supplies architecture-specific SHA-256 checksums.[paru-llm-audit] INFO llm: No evident obfuscation or persistence — The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present.
diffis empty andbaseline_commitis null, so meaningful changes cannot be compared.[paru-llm-audit] FINAL risk=HIGH decision=BLOCK exit=30
PARU_LLM_AUDIT_RESULT={"schema_version":1,"pkgbase":"brave-bin","version":"1:1.94.117-1","aggregate_risk":"high","decision":"block","exit_code":30,"accepted_interactively":false,"llm":{"model":"gpt-5.6-luna","risk":"medium","verdict":"review","confidence":0.96,"summary":"The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available.","findings":[{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runs
chmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\"(static finding identifieschmod 475at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives fromhttps://github.com/brave/brave-browser/releases/download/v${pkgver}/...and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present.diffis empty andbaseline_commitis null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}]},"findings":[{"severity":"high","title":"Setuid or file capabilities configured","evidence":"chmod 475","file":"PKGBUILD","line":52,"source":"static"},{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runschmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\"(static finding identifieschmod 475at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives fromhttps://github.com/brave/brave-browser/releases/download/v${pkgver}/...and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present.diffis empty andbaseline_commitis null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}],"report_path":"/home/mathieu/.local/state/paru-llm-audit/reports/20260829T122928Z-brave-bin-168120.json","error":null}erreur : échec du lancement : sh -c /usr/bin/paru-llm-audit audit .:
zsh: exit 1 paru
Looking for updates…
Nothing to update.
Pris en charge par la boucle de maintenance (tâche Kanban
t_b86c7a5b, branche prévuefix/issue-7-still-failling-on-a-regular-brave-bin-package). Une PR ou une demande de clarification sera liée ici après analyse.Correctif proposé dans la PR #8 : #8
Cause confirmée : la correction ciblée de
brave-binavait bien été fusionnée dans la PR #6, mais le paquet installable restait épinglé sur v0.1.2, donc l'ancien blocage setuid continuait de s'exécuter. La PR #8 publie cette correction en v0.1.3, synchronise la recette AUR et son checksum, et ajoute un test anti-régression de version.Vérifications : 36 tests passent, syntaxe PKGBUILD et compilation Python validées,
namcappropre, archive v0.1.3 téléchargée et checksum vérifié. Le cas exact du sandbox Brave reste une revue medium avec confirmation humaine; les autres opérations setuid/setgid/setcap restent high et bloquantes.