AUR AI Reviewer

Review Results

Version #1796 of icecat · commit ade5acba0892 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #593

Comment

The change is a routine metadata refresh for a new IceCat/Firefox ESR release: pkgver/pkgrel bump, updated upstream source tarball URL, and a new pinned gnuzilla commit. The source remains HTTPS and commit-pinned, and there are no new install scripts, binaries, privilege changes, or build-time network fetches introduced by this .SRCINFO-only diff. The dependency list and patch set are adjusted to match the new upstream release, which is expected for a version update. No obvious supply-chain or persistence red flags are present in the reviewed hunk.

@@ -1,7 +1,7 @@
 pkgbase = icecat
 	pkgdesc = GNU version of the Firefox ESR browser
-	pkgver = 140.12.0
-	pkgrel = 2
+	pkgver = 140.13.0
+	pkgrel = 1
 	url = https://gitweb.git.savannah.gnu.org/gitweb/?p=gnuzilla.git
 	arch = x86_64
 	license = MPL-2.0
Risk 1/5 · Low .SRCINFO
Result #594

Comment

Risk is low. The .SRCINFO update tracks a routine upstream version bump from 140.12.0 to 140.13.0 and refreshes the pinned gnuzilla commit and Firefox source tarball URL/checksum accordingly. The dependency list changes are consistent with the PKGBUILD’s conditional system-libs block (adding libffi.so, libpixman-1.so, libwebpdemux.so, libz.so and removing the older zlib/libevent/libpulse entries from the generated metadata), and there are no signs of new network fetches, install-script behavior, privilege escalation, or other persistence mechanisms in this diff. The only noteworthy issue is that the source URL still uses the odd `https://https.git.savannah.gnu.org/...` form, but that pre-existed and is not introduced by this change.

@@ -38,31 +38,32 @@ pkgbase = icecat
 	depends = dbus
 	depends = ffmpeg
 	depends = gtk3
-	depends = libevent
-	depends = libjpeg.so
-	depends = libpulse
-	depends = libvpx.so
-	depends = libwebp.so
 	depends = libxss
 	depends = libxt
 	depends = mime-types
+	depends = ttf-font
+	depends = libffi.so
+	depends = libjpeg.so
+	depends = libpixman-1.so
+	depends = libvpx.so
+	depends = libwebp.so
+	depends = libwebpdemux.so
+	depends = libz.so
 	depends = nspr
 	depends = nss
-	depends = ttf-font
-	depends = zlib
 	optdepends = hunspell-dictionary: Spell checking
 	optdepends = libnotify: Notification integration
 	optdepends = networkmanager: Location detection via available WiFi networks
 	optdepends = speech-dispatcher: Text-to-Speech
 	optdepends = xdg-desktop-portal: Screensharing with Wayland
-	noextract = firefox-esr-140.12.0-1-source.tar.xz
+	noextract = firefox-esr-140.13.0-1-source.tar.xz
 	options = !debug
 	options = !emptydirs
 	options = !lto
 	options = !makeflags
 	options = !strip
-	source = gnuzilla::git+https://https.git.savannah.gnu.org/git/gnuzilla.git#commit=7cf09cb6107e888c93d85a7e575b4e7c8a2dc917
-	source = firefox-esr-140.12.0-1-source.tar.xz::https://ftp.mozilla.org/pub/firefox/candidates/140.12.0esr-candidates/build1/source/firefox-140.12.0esr.source.tar.xz
+	source = gnuzilla::git+https://https.git.savannah.gnu.org/git/gnuzilla.git#commit=715ab58c4226572511cad0496908b64124f6729d
+	source = firefox-esr-140.13.0-1-source.tar.xz::https://ftp.mozilla.org/pub/firefox/candidates/140.13.0esr-candidates/build1/source/firefox-140.13.0esr.source.tar.xz
 	source = 0000-parallelize-makeicecat.diff
 	source = 5fcff175718cd308bc6d6f2996de14eb8a93e2a2.patch
 	source = 23efd75219786d71acff0b4e7c1b0de297b84c4e.patch
Risk 1/5 · Low .SRCINFO
Result #595

Comment

Risk is low. This .SRCINFO update is a routine version bump from 140.12.0 to 140.13.0 with corresponding source URL/checksum and a removed patch entry. The remaining source URLs are HTTPS and pinned to a specific gnuzilla commit, and there are no new build-time downloads, scripts, or privilege-related changes in this diff. The only notable change is dropping 0006-cbindgen-0_29_4.patch, but without the patch contents or any evidence of malicious behavior, this looks like a normal upstream compatibility update rather than a security issue.

@@ -74,9 +75,8 @@ pkgbase = icecat
 	source = 0003-Use-wasm32-wasip1-target.patch
 	source = 0004-update-rust-bindgen-to-fix-clang22-build.patch.xz
 	source = 0005-skia-m142-update.patch.xz
-	source = 0006-cbindgen-0_29_4.patch
 	sha256sums = SKIP
-	sha256sums = 85dfb9f6021152b4302b8968ef485d958c8c471cb02415a19853daaad5acce62
+	sha256sums = f53b9dc6942abda1185aa7d79048f59fc075020da36b4dd6b31f668b88714d01
 	sha256sums = 1f1b71fcc22fe5e12bd57e7dcc544599e99071eb17b843b261c77fb86f943288
 	sha256sums = 10e928127276c934a51c053d3f7ceb247344afd2e82186e12c4f188dd743bc49
 	sha256sums = 6479aa1df3fda931d0e261edaffdcac2d162c0166c5cfd6adf6f45ccf632b852
Risk 0/5 · Safe .SRCINFO
Result #596

Comment

The change only removes one sha256 checksum entry from .SRCINFO. By itself this does not introduce new sources, code execution, privilege escalation, or packaging behavior; it merely makes the metadata inconsistent with the PKGBUILD/source array until regenerated. I see no direct security impact in the reviewed hunk.

@@ -88,6 +88,5 @@ pkgbase = icecat
 	sha256sums = 28b086f5492d8e6731fe0dfe34a2e4c6d4d502a9eefa15a31e44b5788cf4df89
 	sha256sums = 8f9b7458760b37766a73d4d2c0e93dc810e59d3844495b9d52b3b61dde59c05d
 	sha256sums = e11aba9839824096f07ca5dc17c9fd5bfa09209f8261ab09f7e473f350a82760
-	sha256sums = 198a797558d58d8cb68870fc1ff30dead271f5f1a3be0bce9a627d728a37da9f
 
 pkgname = icecat
Risk 1/5 · Low PKGBUILD
Result #597

Comment

Risk score 1/5. The change is mostly a version bump plus packaging cleanup. I did not find any new execution paths, network fetches outside the declared sources, privilege escalation, or suspicious install-time behavior. The only notable changes are dependency and build-flag adjustments (moving some libraries behind the _build_system_libs toggle, adding system ffi/pixman/gbm/drm options, and changing the cached source tarball name), which affect build behavior but do not introduce an obvious supply-chain or persistence risk. The removed cbindgen patch and the reordered build directory change are not inherently malicious based on the diff shown.

@@ -25,15 +25,15 @@
 : ${_build_limit_cores:=true} # detect usable cores for parallelism, limited by RAM
 
 ## update
-_icver="140.12.0-1"
-_commit="7cf09cb6107e888c93d85a7e575b4e7c8a2dc917"
-_ffsum="85dfb9f6021152b4302b8968ef485d958c8c471cb02415a19853daaad5acce62"
+_icver="140.13.0-1"
+_commit="715ab58c4226572511cad0496908b64124f6729d"
+_ffsum="f53b9dc6942abda1185aa7d79048f59fc075020da36b4dd6b31f668b88714d01"
 
 ## package
 _pkgname="icecat"
 pkgname="$_pkgname"
 pkgver="${_icver%%-*}"
-pkgrel=2
+pkgrel=1
 pkgdesc="GNU version of the Firefox ESR browser"
 url="https://gitweb.git.savannah.gnu.org/gitweb/?p=gnuzilla.git"
 license=('MPL-2.0')
Risk 0/5 · Safe PKGBUILD
Result #598

Comment

The change is low risk overall. It removes several hard-coded runtime dependencies from `depends` and conditionally re-adds them only when `_build_system_libs` is enabled, which is a packaging/feature toggle rather than a security-sensitive behavior. The rest of the diff is build-system housekeeping: updating the IceCat upstream version/commit, dropping an obsolete patch, adjusting mozconfig system-library flags, and changing how parallelism is computed. I do not see any new network fetches, privilege escalation, persistence, or suspicious execution paths introduced by this hunk. One minor concern is that the dependency gating could make the package metadata less accurate if the build flags are changed, but that is a correctness issue, not a security issue.

@@ -43,18 +43,10 @@ depends=(
   dbus
   ffmpeg
   gtk3
-  libevent
-  libjpeg.so # libjpeg-turbo
-  libpulse
-  libvpx.so  # libvpx
-  libwebp.so # libwebp
   libxss
   libxt
   mime-types
-  nspr
-  nss
   ttf-font
-  zlib
 )
 makedepends=(
   cargo
Risk 0/5 · Safe PKGBUILD
Result #599

Comment

The change is low risk. It mainly updates IceCat to a newer upstream commit, adjusts the system-libs toggle to add the corresponding shared-library dependencies and mozconfig flags, and removes an obsolete cbindgen patch. I don’t see any new network fetches, privilege escalation, persistence hooks, or suspicious install-time behavior. The only notable packaging change is the conditional switch to system libraries, but it is gated by an existing build option and only affects dependency declarations/build flags, not runtime behavior. No high-confidence security issue is evident from this diff alone.

@@ -97,6 +89,20 @@ optdepends=(
   'xdg-desktop-portal: Screensharing with Wayland'
 )
 
+if [[ "${_build_system_libs::1}" == "t" ]]; then
+  depends+=(
+    libffi.so       # libffi
+    libjpeg.so      # libjpeg-turbo
+    libpixman-1.so  # pixman
+    libvpx.so       # libvpx
+    libwebp.so      # libwebp
+    libwebpdemux.so # libwebp
+    libz.so         # zlib
+    nspr
+    nss
+  )
+fi
+
 if [[ "${_build_pgo::1}" == "t" ]]; then
   if [[ "${_build_pgo_xvfb::1}" == "t" ]]; then
     makedepends+=(
Risk 0/5 · Safe PKGBUILD
Result #600

Comment

Risk score 0. The change only removes an obsolete patch from the source array and its checksum entry, and updates the package version/commit metadata plus some build-time dependency handling. There are no new network fetches, no added execution paths, no privilege changes, and no suspicious install/persistence behavior. The removed patch appears to be a build fix, so its deletion may affect build success but does not introduce a security issue in the reviewed hunk.

@@ -149,9 +155,6 @@ source=(
   0003-Use-wasm32-wasip1-target.patch
   0004-update-rust-bindgen-to-fix-clang22-build.patch.xz
   0005-skia-m142-update.patch.xz
-
-  # Fix for cbindgen 0.29.4
-  0006-cbindgen-0_29_4.patch
 )
 sha256sums=(
   'SKIP'
Risk 0/5 · Safe PKGBUILD
Result #601

Comment

The change is low risk. It updates IceCat to a new upstream Firefox ESR base, adjusts optional system-library handling, and removes an obsolete patch/checksum entry. The only notable behavior change is switching the cached source restore check from a hardcoded tarball name to the existing $_archive_icecat variable, which appears to be a correctness fix rather than a security issue. I did not see any new network fetches, privilege escalation, suspicious install scripts, or packaging actions outside $pkgdir in this diff.

@@ -167,12 +170,11 @@ sha256sums=(
   '28b086f5492d8e6731fe0dfe34a2e4c6d4d502a9eefa15a31e44b5788cf4df89'
   '8f9b7458760b37766a73d4d2c0e93dc810e59d3844495b9d52b3b61dde59c05d'
   'e11aba9839824096f07ca5dc17c9fd5bfa09209f8261ab09f7e473f350a82760'
-  '198a797558d58d8cb68870fc1ff30dead271f5f1a3be0bce9a627d728a37da9f'
 )
 
 _make_icecat() (
   # restore icecat tarball, if exists
-  if [ "${_build_repatch::1}" != "t" ] && [ -e "$SRCDEST/$_pkgsrc.tar.zst" ]; then
+  if [ "${_build_repatch::1}" != "t" ] && [ -e "$SRCDEST/$_archive_icecat" ]; then
     echo "Restoring previously patched sources..."
     rm -rf "$srcdir/$_pkgsrc"
     bsdtar -xf "$SRCDEST/$_archive_icecat"
Risk 0/5 · Safe PKGBUILD
Result #602

Comment

The change is low risk. It only adjusts which system libraries IceCat is built against, adds the corresponding runtime dependencies, and removes an obsolete patch from the source list. The new mozconfig entries are commented/standard build flags and there is no added network access, privilege escalation, install-script behavior, or suspicious packaging logic. One minor concern is that enabling more system libraries slightly increases reliance on distro-provided components, but that is a normal packaging choice rather than a security issue.

@@ -336,11 +338,19 @@ END
 
   if [[ "${_build_system_libs::1}" == "t" ]]; then
     cat >> ../mozconfig << END
+# ac_add_options --with-system-av1
+# ac_add_options --with-system-icu
+# ac_add_options --with-system-libevent
+# ac_add_options --with-system-pipewire
+# ac_add_options --with-system-png
+ac_add_options --with-system-ffi
+ac_add_options --with-system-gbm
 ac_add_options --with-system-jpeg
-ac_add_options --with-system-libevent
+ac_add_options --with-system-libdrm
 ac_add_options --with-system-libvpx
 ac_add_options --with-system-nspr
 ac_add_options --with-system-nss
+ac_add_options --with-system-pixman
 ac_add_options --with-system-webp
 ac_add_options --with-system-zlib
 END
Risk 0/5 · Safe PKGBUILD
Result #603

Comment

The change is low risk overall. It only adjusts build-time PKGBUILD logic: updates IceCat version/commit, changes optional system-library linkage, removes an old patch, and refactors parallel build detection. I did not see any new network fetches, privilege escalation, persistence mechanisms, or suspicious install scripts/units. The only notable security-relevant change is the new conditional `depends+=()` for system libraries and the removal of the cbindgen patch, but both are ordinary packaging maintenance and do not introduce obvious attack surface in the PKGBUILD itself. The build-parallelism refactor reads `/proc/meminfo` and `nproc` locally and writes mozconfig; it does not execute external commands beyond standard build tooling. No high-confidence security issue is evident in this diff.

@@ -352,21 +362,30 @@ ac_add_options --enable-lto=cross,full
 END
   fi
 
+  # build paralleism
+  local _mem _nproc _cores
+  _mem=$(grep -Pom1 '^MemFree.*\b\K[0-9]+' /proc/meminfo)
+  _nproc=$(nproc)
+
   if [[ "${_build_limit_cores::1}" == "t" ]]; then
-    # calculate core availability
-    local _mem _nproc _cores
-    _mem=$(cat /proc/meminfo | grep MemFree | grep -Eom1 '[0-9]+')
-    _nproc=$(nproc)
+    # calculate core availability based on free RAM and CPU count
     _cores=$((_mem / (1024 * 1024) < _nproc ? _mem / (1024 * 1024) : _nproc))
     _cores=$((_cores < 1 ? 1 : _cores))
+  elif ((${_build_limit_cores:-0} > 0)); then
+    # user-specified, capped by CPU count
+    _cores=$((_build_limit_cores > _nproc ? _nproc : _build_limit_cores))
+  fi
 
+  if [ -n "${_cores:-}" ]; then
     printf '\nFree RAM: %s\nCores: %s\nUsing: %s\n\n' "$((_mem / (1024 * 1024)))" "$_nproc" "$_cores"
-
     cat >> ../mozconfig << END
-mk_add_options MOZ_PARALLEL_BUILD=${_cores:-4}
+mk_add_options MOZ_PARALLEL_BUILD=${_cores}
 END
+  else
+    printf '\nFree RAM: %s\nCores: %s\nUsing: auto\n\n' "$((_mem / (1024 * 1024)))" "$_nproc"
   fi
 
+  # apply patches
   local src
   for src in "${source[@]}"; do
     src="${src%%::*}"
Risk 0/5 · Safe PKGBUILD
Result #604

Comment

The only functional change in the reviewed hunk is moving `cd "$ _pkgsrc"` from the start of `build()` to later, after `ulimit -n 4096`. This does not introduce new network access, privilege changes, persistence, or packaging writes outside `$pkgdir`; it only changes the working directory timing within the same build function. I did not see any malicious behavior in the surrounding PKGBUILD diff relevant to this hunk. Risk is therefore very low.

@@ -383,8 +402,6 @@ END
 build() (
   _prepare_icecat
 
-  cd "$_pkgsrc"
-
   export RUSTUP_TOOLCHAIN=stable
 
   export XDG_RUNTIME_DIR="${XDG_RUNTIME_DIR:-$srcdir/xdg-runtime}"
Risk 0/5 · Safe PKGBUILD
Result #605

Comment

Low risk change. The diff mainly updates IceCat to a newer upstream commit, adjusts optional system-library dependencies/configuration, and moves the build directory change later in build(). I do not see any added network fetches, privilege escalation, persistence mechanisms, or suspicious install-time behavior. The only notable packaging change is removal of a local cbindgen patch and some dependency toggles, but nothing in this hunk suggests malicious behavior or integrity compromise.

@@ -406,6 +423,8 @@ build() (
   # LTO/PGO needs more open files
   ulimit -n 4096
 
+  cd "$_pkgsrc"
+
   # Do 3-tier PGO
   if [[ "${_build_pgo::1}" == "t" ]]; then
     # find previous profile file...