still failling on a regular brave-bin package #7

Closed
opened 2026-08-29 12:30:56 +00:00 by mathieu · 2 comments
Owner

:: Looking for PKGBUILD upgrades...
:: Recherche des mises à jour pour les paquets de l'AUR...
:: Recherche de mises à jour pour les paquets devel...
:: Résolution des dépendances...
:: Calcul des conflits...
:: Calcul des conflits internes...

Aur (5) Ancienne Version Nouvelle Version Make Only
aur/brave-bin 1:1.93.138-1 1:1.94.117-1 Non
aur/netbird-ui-bin 0.77.0-1 0.77.1-1 Non
aur/pandoc-bin 3.10.2-1 3.11-1 Non
aur/t3code-bin 0.0.33-1 0.0.36-1 Non
aur/teams-for-linux-bin 2.17.0-1 2.17.1-1 Non

:: Procéder à la relecture ? [O/n]

:: Téléchargement des PKGBUILDs...
PKGBUILDs à jour
[paru-llm-audit] package=brave-bin version=1:1.94.117-1
[paru-llm-audit] LLM model=gpt-5.6-luna risk=MEDIUM verdict=REVIEW confidence=0.96
[paru-llm-audit] LLM summary: The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available.
[paru-llm-audit] HIGH static PKGBUILD:52: Setuid or file capabilities configured — chmod 475
[paru-llm-audit] HIGH llm PKGBUILD:52: Setuid sandbox executable installed — PKGBUILD package() runs chmod 4755 "$pkgdir/opt/brave-bin/chrome-sandbox" (static finding identifies chmod 475 at line 52). This grants setuid-root behavior to the browser sandbox binary.
[paru-llm-audit] INFO llm PKGBUILD:30: Official remote binary sources with checksums — PKGBUILD downloads versioned x86_64 and aarch64 archives from https://github.com/brave/brave-browser/releases/download/v${pkgver}/... and supplies architecture-specific SHA-256 checksums.
[paru-llm-audit] INFO llm: No evident obfuscation or persistence — The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. diff is empty and baseline_commit is null, so meaningful changes cannot be compared.
[paru-llm-audit] FINAL risk=HIGH decision=BLOCK exit=30
PARU_LLM_AUDIT_RESULT={"schema_version":1,"pkgbase":"brave-bin","version":"1:1.94.117-1","aggregate_risk":"high","decision":"block","exit_code":30,"accepted_interactively":false,"llm":{"model":"gpt-5.6-luna","risk":"medium","verdict":"review","confidence":0.96,"summary":"The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available.","findings":[{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runs chmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\" (static finding identifies chmod 475 at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives from https://github.com/brave/brave-browser/releases/download/v${pkgver}/... and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. diff is empty and baseline_commit is null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}]},"findings":[{"severity":"high","title":"Setuid or file capabilities configured","evidence":"chmod 475","file":"PKGBUILD","line":52,"source":"static"},{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runs chmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\" (static finding identifies chmod 475 at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives from https://github.com/brave/brave-browser/releases/download/v${pkgver}/... and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. diff is empty and baseline_commit is null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}],"report_path":"/home/mathieu/.local/state/paru-llm-audit/reports/20260829T122928Z-brave-bin-168120.json","error":null}
erreur : échec du lancement : sh -c /usr/bin/paru-llm-audit audit .:
zsh: exit 1 paru
Looking for updates…

Nothing to update.

:: Looking for PKGBUILD upgrades... :: Recherche des mises à jour pour les paquets de l'AUR... :: Recherche de mises à jour pour les paquets devel... :: Résolution des dépendances... :: Calcul des conflits... :: Calcul des conflits internes... Aur (5) Ancienne Version Nouvelle Version Make Only aur/brave-bin 1:1.93.138-1 1:1.94.117-1 Non aur/netbird-ui-bin 0.77.0-1 0.77.1-1 Non aur/pandoc-bin 3.10.2-1 3.11-1 Non aur/t3code-bin 0.0.33-1 0.0.36-1 Non aur/teams-for-linux-bin 2.17.0-1 2.17.1-1 Non :: Procéder à la relecture ? [O/n] :: Téléchargement des PKGBUILDs... PKGBUILDs à jour [paru-llm-audit] package=brave-bin version=1:1.94.117-1 [paru-llm-audit] LLM model=gpt-5.6-luna risk=MEDIUM verdict=REVIEW confidence=0.96 [paru-llm-audit] LLM summary: The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available. [paru-llm-audit] HIGH static PKGBUILD:52: Setuid or file capabilities configured — chmod 475 [paru-llm-audit] HIGH llm PKGBUILD:52: Setuid sandbox executable installed — PKGBUILD package() runs `chmod 4755 "$pkgdir/opt/brave-bin/chrome-sandbox"` (static finding identifies `chmod 475` at line 52). This grants setuid-root behavior to the browser sandbox binary. [paru-llm-audit] INFO llm PKGBUILD:30: Official remote binary sources with checksums — PKGBUILD downloads versioned x86_64 and aarch64 archives from `https://github.com/brave/brave-browser/releases/download/v${pkgver}/...` and supplies architecture-specific SHA-256 checksums. [paru-llm-audit] INFO llm: No evident obfuscation or persistence — The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. `diff` is empty and `baseline_commit` is null, so meaningful changes cannot be compared. [paru-llm-audit] FINAL risk=HIGH decision=BLOCK exit=30 PARU_LLM_AUDIT_RESULT={"schema_version":1,"pkgbase":"brave-bin","version":"1:1.94.117-1","aggregate_risk":"high","decision":"block","exit_code":30,"accepted_interactively":false,"llm":{"model":"gpt-5.6-luna","risk":"medium","verdict":"review","confidence":0.96,"summary":"The package is largely conventional and references official Brave GitHub release archives with SHA-256 checksums. Review is warranted because installation explicitly sets the Chromium sandbox executable setuid-root (mode 4755), creating a privilege-sensitive component; no baseline diff is available.","findings":[{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runs `chmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\"` (static finding identifies `chmod 475` at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives from `https://github.com/brave/brave-browser/releases/download/v${pkgver}/...` and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. `diff` is empty and `baseline_commit` is null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}]},"findings":[{"severity":"high","title":"Setuid or file capabilities configured","evidence":"chmod 475","file":"PKGBUILD","line":52,"source":"static"},{"severity":"high","title":"Setuid sandbox executable installed","evidence":"PKGBUILD package() runs `chmod 4755 \"$pkgdir/opt/brave-bin/chrome-sandbox\"` (static finding identifies `chmod 475` at line 52). This grants setuid-root behavior to the browser sandbox binary.","file":"PKGBUILD","line":52,"source":"llm"},{"severity":"info","title":"Official remote binary sources with checksums","evidence":"PKGBUILD downloads versioned x86_64 and aarch64 archives from `https://github.com/brave/brave-browser/releases/download/v${pkgver}/...` and supplies architecture-specific SHA-256 checksums.","file":"PKGBUILD","line":30,"source":"llm"},{"severity":"info","title":"No evident obfuscation or persistence","evidence":"The supplied PKGBUILD and wrapper contain straightforward shell logic; no install hooks, credential access, startup persistence, or unrelated network commands are present. `diff` is empty and `baseline_commit` is null, so meaningful changes cannot be compared.","file":null,"line":null,"source":"llm"}],"report_path":"/home/mathieu/.local/state/paru-llm-audit/reports/20260829T122928Z-brave-bin-168120.json","error":null} erreur : échec du lancement : sh -c /usr/bin/paru-llm-audit audit .: zsh: exit 1 paru Looking for updates… Nothing to update.
Owner

Pris en charge par la boucle de maintenance (tâche Kanban t_b86c7a5b, branche prévue fix/issue-7-still-failling-on-a-regular-brave-bin-package). Une PR ou une demande de clarification sera liée ici après analyse.

Pris en charge par la boucle de maintenance (tâche Kanban `t_b86c7a5b`, branche prévue `fix/issue-7-still-failling-on-a-regular-brave-bin-package`). Une PR ou une demande de clarification sera liée ici après analyse. <!-- paru-llm-audit-loop:task:t_b86c7a5b -->
Owner

Correctif proposé dans la PR #8 : #8

Cause confirmée : la correction ciblée de brave-bin avait bien été fusionnée dans la PR #6, mais le paquet installable restait épinglé sur v0.1.2, donc l'ancien blocage setuid continuait de s'exécuter. La PR #8 publie cette correction en v0.1.3, synchronise la recette AUR et son checksum, et ajoute un test anti-régression de version.

Vérifications : 36 tests passent, syntaxe PKGBUILD et compilation Python validées, namcap propre, archive v0.1.3 téléchargée et checksum vérifié. Le cas exact du sandbox Brave reste une revue medium avec confirmation humaine; les autres opérations setuid/setgid/setcap restent high et bloquantes.

Correctif proposé dans la PR #8 : https://git.2027a.net/2027a/paru-llm-audit/pulls/8 Cause confirmée : la correction ciblée de `brave-bin` avait bien été fusionnée dans la PR #6, mais le paquet installable restait épinglé sur v0.1.2, donc l'ancien blocage setuid continuait de s'exécuter. La PR #8 publie cette correction en v0.1.3, synchronise la recette AUR et son checksum, et ajoute un test anti-régression de version. Vérifications : 36 tests passent, syntaxe PKGBUILD et compilation Python validées, `namcap` propre, archive v0.1.3 téléchargée et checksum vérifié. Le cas exact du sandbox Brave reste une revue medium avec confirmation humaine; les autres opérations setuid/setgid/setcap restent high et bloquantes.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
2027a/paru-llm-audit#7
No description provided.