this post was submitted on 31 Jul 2026
137 points (98.6% liked)

Linux

66746 readers
1155 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 7 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] thingsiplay@lemmy.ml 33 points 2 days ago (3 children)

Adoption of unmaintained packages to maintain them is not a mistake. The problem is the current implementation, not the idea behind it. It's like saying the AUR is a mistake, because some people do malicious stuff.

They should find a better solution, like adoption shouldn't be granted to everyone without question, especially new accounts who didn't maintain anything before. Mass adoption shouldn't be granted automatically (limit rate), in example 1 package adoption per day and if someone wants more, admins or moderators need to approve. And updates of newly adopted packages should wait a day.

Also the AUR helpers should do a better job. Always ask if a new adopted package should be updated and give a warning the maintainer changed.

[–] Dirk@lemmy.ml 9 points 2 days ago (1 children)

The problem is the current implementation

Yes, exactly this! I am not surprised it happens. I’m surprised it didn’t happen before.

especially new accounts

Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

Also the AUR helpers should do a better job.

Even experienced people will just update as if nothing could happen. Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

[–] thingsiplay@lemmy.ml 4 points 2 days ago* (last edited 2 days ago) (1 children)

Weren’t there “sleeper accounts” registered years ago that became active in the current wave?

Which does not invalidate my point about new accounts, but yes. Its important for new accounts, so once a sleeper account is banned, its not that easy to just create thousands of new accounts while everyone is focusing on the current active ones. And if, as I suggested, mass adoption per account is not possible, then the attacker has less to attack.

Edit: They need to make sure that sudden editing many packages in short time, with probably the same or similar lines should be automatically reported. They need some automated checks in place, at the very least. This would be a very suspicious behavior if many accounts are not active, and then suddenly all of them do something.

Even experienced people will just update as if nothing could happen.

Then you can't fault the system, if you are this reckless.

Adopted packages should have to use a different name and the current name being blocked so it WILL get attention when some tries to update their system.

This would break all dependencies of this package. The point of adoption is to keep it working and stable. I'm highly against force changing the name, that is not a solution (at least not one I am happy about).

[–] Dirk@lemmy.ml 4 points 2 days ago (1 children)

[Changing a package’s name] would break all dependencies of this package.

Yes, that is correct. But that should not be a big deal for packages that are actively maintained. The maintainer can simply change the dependency to the new name after making sure the new package is legit.

[–] thingsiplay@lemmy.ml 4 points 2 days ago* (last edited 2 days ago)

OK, that's a good point. It would prevent auto updating. However any package that is NOT updated, should stay with same name in my opinion. So that everything (with the old secure code) stays intact and working. The name change should be part of the the update process. So it only breaks if you want to update, which would ensure compatibility if you choose not to (as it is safe). Something along the likes like this. I agree with your suggestion now, because that seems to be sensible idea.

[–] trevor@lemmy.blahaj.zone 3 points 2 days ago

Enforced commit signing and making it obvious when the signature changes would help make adoption much safer. I really hope they implement it.

[–] lemmyvore@feddit.nl -1 points 1 day ago (1 children)

They should find a better solution

Who's "they"? Because it's not Arch. Arch doesn't want to have anything to do with AUR, and neither does any of the Arch-derived distros. They're all perfectly happy taking advantage of it, of course, but not the responsibility.

[–] thingsiplay@lemmy.ml 7 points 1 day ago (1 children)

Who’s “they”? Because it’s not Arch. Arch doesn’t want to have anything to do with AUR, and neither does any of the Arch-derived distros. They’re all perfectly happy taking advantage of it, of course, but not the responsibility.

Where did you got this nonsense from? What do you mean "they are not Arch"? The AUR is managed and operated by the Archlinux team. As the packages are community-driven content, they cannot guarantee and give support, because it is not their package. But they are still managing and supporting the AUR itself.

https://archlinux.org/news/active-aur-malicious-packages-incident/ from 2026-06-12 is an official message on the main Archlinux website (there is no new post about the current situation).

Are what could I find quickly. The point is, the AUR is officially developer, maintained and supported by the Archlinux team. They refer to them. What they cannot do is, support community-driven packages. It's like expecting from Microsoft to support every single repository on Github. That's not how it works and what "support" of AUR means.

[–] lemmyvore@feddit.nl -5 points 1 day ago (1 children)

And you're gonna see the Arch team wash their hands of the whole thing, like they did in the past whenever the AUR was in trouble.

That's not real ownership.

[–] thingsiplay@lemmy.ml 7 points 1 day ago (1 children)

Do you have any sources, links or evidence for your statements?

[–] lemmyvore@feddit.nl -3 points 1 day ago* (last edited 1 day ago) (1 children)

Is the current state of the AUR, despite the previous waves of attacks, and its troubled history, not evidence enough? The Arch team has never made the AUR a priority and I don't see why they would start now.

The way I see it there are three possibilities:

  • They do nothing.
  • They shut it down.
  • They give it up for adoption.

What is not going to happen is the Arch team putting time and effort into overhauling the AUR.

[–] thingsiplay@lemmy.ml 3 points 1 day ago