AUR AI Reviewer

Review Results

Version #2332 of wechat-universal-bwrap · commit cca34f388761 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #2897

Comment

The change only bumps pkgver in .SRCINFO from 4.1.1.8 to 4.1.13.9. No sources, checksums, build steps, install scripts, or packaging logic are modified in the reviewed diff, so there is no new security-relevant behavior to assess from this change alone. The risk is therefore minimal.

@@ -1,6 +1,6 @@
 pkgbase = wechat-universal-bwrap
 	pkgdesc = WeChat (Universal) with bwrap sandbox
-	pkgver = 4.1.1.8
+	pkgver = 4.1.13.9
 	pkgrel = 1
 	url = https://linux.weixin.qq.com/
 	install = wechat-universal.install
Risk 0/5 · Safe .SRCINFO
Result #2898

Comment

The change is a straightforward version bump in .SRCINFO: updated pkgver, noextract filenames, and source checksums for the official Tencent download URLs. There are no new sources, no protocol changes, no build-script or install-script logic, and no signs of added execution, persistence, or privilege escalation. Based on the diff provided, this is low risk and appears to be routine metadata refresh only.

@@ -31,9 +31,9 @@ pkgbase = wechat-universal-bwrap
 	conflicts = wechat-universal
 	replaces = wechat-beta
 	replaces = wechat-beta-bwrap
-	noextract = wechat-universal-4.1.1.8-x86_64.deb
-	noextract = wechat-universal-4.1.1.8-aarch64.deb
-	noextract = wechat-universal-4.1.1.8-loong64.deb
+	noextract = wechat-universal-4.1.13.9-x86_64.deb
+	noextract = wechat-universal-4.1.13.9-aarch64.deb
+	noextract = wechat-universal-4.1.13.9-loong64.deb
 	options = !strip
 	options = !debug
 	options = emptydirs
Risk 0/5 · Safe .SRCINFO
Result #2899

Comment

The change only updates .SRCINFO checksums and bumps the referenced upstream WeChat .deb versions from 4.1.1.8 to 4.1.13.9 for the three architecture-specific binary sources. The sources remain HTTPS from the same official QQ domain, and there are no new build-time commands, scripts, or packaging behaviors introduced in this diff. Since this is just metadata reflecting a version refresh, I do not see a security issue in the reviewed hunk.

@@ -42,16 +42,16 @@ pkgbase = wechat-universal-bwrap
 	source = libuosdevicea.c
 	source = libuosdevicea.Makefile
 	source = wechat-license
-	sha256sums = 7ef002c45bf89d3f5dd02045c327a802b57cb2b57b65406f17f68baab967e407
+	sha256sums = a71158393c04658e89d3cdc12186bcdde70dc96321db2c8e86648a1487fbbe1c
 	sha256sums = 0563472cf2c74710d1fe999d397155f560d3ed817e04fd9c35077ccb648e1880
 	sha256sums = fc3ce9eb8dee3ee149233ebdb844d3733b2b2a8664422d068cf39b7fb08138f8
 	sha256sums = f05f6f907898740dab9833c1762e56dbc521db3c612dd86d2e2cd4b81eb257bf
 	sha256sums = 898ebc397583d111db9a337e9d09aaee2f795fcd720e65cab5ce0e92efcd8f10
-	source_x86_64 = wechat-universal-4.1.1.8-x86_64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.deb
-	sha256sums_x86_64 = c9765e87ee5133bf4bb50d585c1814fafd995e3fb0da62c5ed07259b43dada7b
-	source_aarch64 = wechat-universal-4.1.1.8-aarch64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.deb
-	sha256sums_aarch64 = c3ed1a481247e6a1b166e87a66cccdee898c3ae0b76613b39bb6e9795e50929f
-	source_loong64 = wechat-universal-4.1.1.8-loong64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_LoongArch.deb
-	sha256sums_loong64 = a5fa706d7936dcf55cff2ae4a59c11ccd0e0095210d602c3233ca7f14c291b94
+	source_x86_64 = wechat-universal-4.1.13.9-x86_64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.deb
+	sha256sums_x86_64 = 096865e050ba0d3c1a23887227e2400bf343037b1d7d658c84c88ff26bfdc17f
+	source_aarch64 = wechat-universal-4.1.13.9-aarch64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.deb
+	sha256sums_aarch64 = a6d115d24dfe3ed1b7e7de16cf6cc02acef8df5668150f702ac8d8c5256405fa
+	source_loong64 = wechat-universal-4.1.13.9-loong64.deb::https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_LoongArch.deb
+	sha256sums_loong64 = 2d13aad578bb6e2d66ef3d71cfcfc0ad59fc34fc6e6e8f1eb3091f063cd12ece
 
 pkgname = wechat-universal-bwrap
Risk 0/5 · Safe PKGBUILD
Result #2900

Comment

The change only bumps pkgver and updates the corresponding SHA256 checksums for the upstream .deb sources. I do not see any new code execution, additional sources, privilege changes, or packaging logic changes in the reviewed hunk. This is a routine version/hash refresh with no obvious security regression in the diff provided.

@@ -4,7 +4,7 @@
 
 _pkgname=wechat-universal
 pkgname=${_pkgname}-bwrap
-pkgver=4.1.1.8
+pkgver=4.1.13.9
 pkgrel=1
 pkgdesc="WeChat (Universal) with bwrap sandbox"
 arch=('x86_64' 'aarch64' 'loong64')
Risk 0/5 · Safe PKGBUILD
Result #2901

Comment

The change only updates PKGBUILD versioned source checksums to match a new upstream release (pkgver bump plus corresponding SHA256 updates for the downloaded .deb artifacts). I do not see any new build steps, network fetches outside source=(), privilege escalation, or packaging logic changes. The package still relies on upstream binary .debs, but that was already the case; this diff does not introduce additional risk beyond the normal trust in the new upstream release artifacts.

@@ -62,7 +62,7 @@ source_loong64=("${_deb_prefix}loong64.deb::${_deb_url_common}LoongArch.deb")
 noextract=("${_deb_prefix}"{x86_64,aarch64,loong64}.deb )
 
 sha256sums=(
-	'7ef002c45bf89d3f5dd02045c327a802b57cb2b57b65406f17f68baab967e407'
+    'a71158393c04658e89d3cdc12186bcdde70dc96321db2c8e86648a1487fbbe1c'
     '0563472cf2c74710d1fe999d397155f560d3ed817e04fd9c35077ccb648e1880'
     'fc3ce9eb8dee3ee149233ebdb844d3733b2b2a8664422d068cf39b7fb08138f8'
     'f05f6f907898740dab9833c1762e56dbc521db3c612dd86d2e2cd4b81eb257bf'
Risk 0/5 · Safe PKGBUILD
Result #2902

Comment

The change only updates pkgver and the corresponding SHA-256 checksums for the upstream .deb sources on each architecture. I do not see any new code execution, network behavior, privilege changes, or packaging logic changes in the diff. The integrity pins are still present and the sources remain the same official upstream download URLs, so this looks like a routine version bump with refreshed checksums.

@@ -70,13 +70,13 @@ sha256sums=(
 )
 
 sha256sums_x86_64=(
-    'c9765e87ee5133bf4bb50d585c1814fafd995e3fb0da62c5ed07259b43dada7b'
+    '096865e050ba0d3c1a23887227e2400bf343037b1d7d658c84c88ff26bfdc17f'
 )
 sha256sums_aarch64=(
-    'c3ed1a481247e6a1b166e87a66cccdee898c3ae0b76613b39bb6e9795e50929f'
+    'a6d115d24dfe3ed1b7e7de16cf6cc02acef8df5668150f702ac8d8c5256405fa'
 )
 sha256sums_loong64=(
-    'a5fa706d7936dcf55cff2ae4a59c11ccd0e0095210d602c3233ca7f14c291b94'
+    '2d13aad578bb6e2d66ef3d71cfcfc0ad59fc34fc6e6e8f1eb3091f063cd12ece'
 )
 
 prepare() {
Risk 0/5 · Safe wechat-universal.sh
Result #2903

Comment

The change removes the previous conditional bwrap setup and now always appends `--unshare-user-try --unshare-pid --unshare-uts --unshare-cgroup-try`, while dropping `--share-net`. This is a packaging/runtime behavior change, but it does not introduce obvious supply-chain, persistence, privilege-escalation, or code-execution red flags. The new sandboxing is actually stricter in some respects (no shared network, PID namespace isolation), and there are no added downloads, scripts, or privileged operations in the reviewed hunk. Main risk is functional breakage for multi-instance behavior or networking, not a security issue.

@@ -151,22 +151,11 @@ try_start() {
     mkdir -p "${WECHAT_FILES_DIR}" "${WECHAT_HOME_DIR}"
     ln -snf "${WECHAT_FILES_DIR}" "${WECHAT_HOME_DIR}/xwechat_files"
 
-    if [[ "${WECHAT_MULTIPLE_INSTANCE}" ]];then
-        BWRAP_ARGS=(
-            --unshare-user-try
-            --unshare-ipc
-            --unshare-uts
-            --unshare-cgroup-try
-        )
-    else
-        BWRAP_ARGS=(
-            # Drop privileges
-            --unshare-all
-        )
-    fi
-
     BWRAP_ARGS+=(
-        --share-net
+        --unshare-user-try
+        --unshare-pid
+        --unshare-uts
+        --unshare-cgroup-try
         --cap-drop ALL
         --die-with-parent