AUR AI Reviewer

Review Results

Version #2429 of nvidia-utils-beta · commit b04d019a58a4 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #3318

Comment

The .SRCINFO update is a routine version bump for NVIDIA beta utilities: it switches the source URL to the new upstream release, updates checksums, and adjusts provided package versions and the companion config filename. The source remains HTTPS from NVIDIA’s official download host, and there are no new build-time execution paths, external mirrors, or suspicious metadata changes in this diff. The license identifier change is cosmetic/metadata-only and does not introduce an integrity or privilege risk by itself. Overall this looks like a normal package refresh with low security concern.

@@ -1,14 +1,14 @@
 pkgbase = nvidia-utils-beta
 	pkgdesc = NVIDIA drivers utilities (beta version)
-	pkgver = 610.57.04
+	pkgver = 615.71.09
 	pkgrel = 1
 	url = https://www.nvidia.com/
 	arch = x86_64
-	license = LicenseRef-custom
+	license = LicenseRef-NVIDIA-Driver-License-Agreement
 	options = !strip
-	source = https://us.download.nvidia.com/XFree86/Linux-x86_64/610.57.04/NVIDIA-Linux-x86_64-610.57.04.run
+	source = https://us.download.nvidia.com/XFree86/Linux-x86_64/615.71.09/NVIDIA-Linux-x86_64-615.71.09.run
 	source = nvidia-drm-outputclass.conf
-	source = nvidia-sleep.conf
+	source = nvidia-utils.conf
 	source = nvidia-utils.sysusers
 	source = nvidia.rules
 	source = systemd-homed-override.conf
Risk 0/5 · Safe .SRCINFO
Result #3319

Comment

The change is a routine version bump in .SRCINFO for NVIDIA beta utilities, updating the upstream download URL, package provides/dependency versions, license string, and checksums. The source remains an HTTPS URL on NVIDIA's official domain, and there are no new build-time commands, scripts, or privilege-related artifacts introduced by this diff. No obvious supply-chain or persistence red flags are present in the reviewed hunk.

@@ -16,11 +16,11 @@ pkgbase = nvidia-utils-beta
 	source = 10-gsk.conf
 	source = gsk-renderer.sh
 	source = 120-nvidia-settings-change-desktop-paths.patch
-	sha256sums = b2e935c66b83bb00c0c857bc8e0ee0fd52de9286b40c9cc1eec29a7ce7eb116d
+	sha256sums = cdceed22bbeb61248d1a6deabc2596673e3a6501698ee71ac8d2fdc28f3b70fe
 	sha256sums = be99ff3def641bb900c2486cce96530394c5dc60548fc4642f19d3a4c784134d
-	sha256sums = 19800e91ab96a8be828af1383cbbadeda9f65f709e52f1217b54d5f3f1282318
+	sha256sums = 8ed91802c2a2d5b46c0692c624caf01dcde62a885dc617dda6694f4666de4c8e
 	sha256sums = f77a5247a3ba63e9fad3a3b2822d0fcfa51e0f79b5a90bd79bf08ea34b64ab07
-	sha256sums = 0e54249a7754b668b436f0f7aa7e95fff68edbb12a93dbee4660e09a8c695f84
+	sha256sums = e30714f9b473d810c28763d067e0b85c75f86f23618d968b49b9d1fced9a1dd6
 	sha256sums = c5aa7b8abe69e72bfdc6b9ee8afbfd350bcc557e894558f2e6e4087fa9aa0dd8
 	sha256sums = 1d053c5078387021338cfc3a732bed61be1a20a549775573788e9134775c8149
 	sha256sums = 05af96f86b7b3b40b93160fdcb702572401579f8756c0831b5de5f8e9afebeba
Risk 0/5 · Safe .SRCINFO
Result #3320

Comment

The change only updates .SRCINFO virtual package version metadata from 610.57.04 to 615.71.09 for provides entries. This does not introduce executable code, network access, privilege changes, or packaging behavior changes by itself. It is consistent with a version bump for the beta NVIDIA utilities package and has no obvious security impact in the reviewed hunk.

@@ -44,11 +44,11 @@ pkgname = nvidia-utils-beta
 	optdepends = opencl-nvidia-beta: for OpenCL support
 	optdepends = xorg-server: for Xorg support
 	optdepends = xorg-server-devel: for nvidia-xconfig
-	provides = nvidia-utils=610.57.04
+	provides = nvidia-utils=615.71.09
 	provides = vulkan-driver
 	provides = opengl-driver
-	provides = nvidia-libgl=610.57.04
-	provides = nvidia-libgl-beta=610.57.04
+	provides = nvidia-libgl=615.71.09
+	provides = nvidia-libgl-beta=615.71.09
 	conflicts = nvidia-utils
 	conflicts = nvidia-libgl
 	replaces = nvidia-libgl
Risk 0/5 · Safe .SRCINFO
Result #3321

Comment

The change is limited to .SRCINFO metadata and updates the provided virtual package version from 610.57.04 to 615.71.09 for opencl-nvidia-beta. This does not introduce code execution, network access, privilege escalation, or packaging behavior changes by itself. It appears to be a routine version bump to keep provides() in sync with the package version, with no security-relevant red flags in the diff shown.

@@ -57,7 +57,7 @@ pkgname = opencl-nvidia-beta
 	pkgdesc = OpenCL implemention for NVIDIA (beta version)
 	depends = glibc
 	optdepends = opencl-headers: headers necessary for OpenCL development
-	provides = opencl-nvidia=610.57.04
+	provides = opencl-nvidia=615.71.09
 	provides = opencl-driver
 	conflicts = opencl-nvidia
 
Risk 0/5 · Safe .SRCINFO
Result #3322

Comment

The change only bumps versioned dependency/provides metadata in .SRCINFO for nvidia-settings-beta from 610.57.04 to 615.71.09. There are no new sources, scripts, install hooks, permissions changes, or build-time execution paths introduced here. This is a routine package metadata update and does not by itself create a security concern.

@@ -72,9 +72,9 @@ pkgname = nvidia-settings-beta
 	depends = hicolor-icon-theme
 	depends = libx11
 	depends = libxext
-	depends = nvidia-utils-beta>=610.57.04
+	depends = nvidia-utils-beta>=615.71.09
 	depends = pango
 	depends = wayland
-	provides = nvidia-settings=610.57.04
-	provides = nvidia-settings-beta=610.57.04
+	provides = nvidia-settings=615.71.09
+	provides = nvidia-settings-beta=615.71.09
 	conflicts = nvidia-settings
Risk 0/5 · Safe PKGBUILD
Result #3323

Comment

The change is low risk. It updates the package to a newer NVIDIA beta release, refreshes checksums, and swaps in a renamed modprobe config file. The new nvidia-utils.conf content is straightforward: it blacklists nouveau/nova, sets module softdeps, and enables two NVIDIA module options. The added libraries (libnvidia-fmdrv.so and libnvidia-imex.so) are installed from the vendor .run payload like the rest of the package, with no new build-time network access, privilege escalation, or suspicious post-install behavior introduced by this diff. The only notable packaging change is the license identifier rename, which is metadata-only.

@@ -5,17 +5,17 @@
 
 pkgbase=nvidia-utils-beta
 pkgname=('nvidia-utils-beta' 'opencl-nvidia-beta' 'nvidia-settings-beta')
-pkgver=610.57.04
+pkgver=615.71.09
 pkgrel=1
 pkgdesc='NVIDIA drivers utilities (beta version)'
 arch=('x86_64')
 url='https://www.nvidia.com/'
-license=('LicenseRef-custom')
+license=('LicenseRef-NVIDIA-Driver-License-Agreement')
 options=('!strip')
 _pkg="NVIDIA-Linux-${CARCH}-${pkgver}"
 source=("https://us.download.nvidia.com/XFree86/Linux-${CARCH}/${pkgver}/${_pkg}.run"
         'nvidia-drm-outputclass.conf'
-        'nvidia-sleep.conf'
+        'nvidia-utils.conf'
         'nvidia-utils.sysusers'
         'nvidia.rules'
         'systemd-homed-override.conf'
Risk 0/5 · Safe PKGBUILD
Result #3324

Comment

The change is low risk. It updates the package to a new NVIDIA beta release, refreshes checksums, renames the modprobe config source from nvidia-sleep.conf to nvidia-utils.conf, and adds two newly shipped NVIDIA libraries (libnvidia-fmdrv.so and libnvidia-imex.so) to the package payload. I did not find any new network fetches, privilege escalation, persistence mechanisms, or suspicious build-time execution. The only notable packaging change is that the modprobe config now comes from a differently named local file, but its contents are still limited to module blacklisting and NVIDIA options, which is expected for this package.

@@ -23,11 +23,11 @@ source=("https://us.download.nvidia.com/XFree86/Linux-${CARCH}/${pkgver}/${_pkg}
         '10-gsk.conf'
         'gsk-renderer.sh'
         '120-nvidia-settings-change-desktop-paths.patch')
-sha256sums=('b2e935c66b83bb00c0c857bc8e0ee0fd52de9286b40c9cc1eec29a7ce7eb116d'
+sha256sums=('cdceed22bbeb61248d1a6deabc2596673e3a6501698ee71ac8d2fdc28f3b70fe'
             'be99ff3def641bb900c2486cce96530394c5dc60548fc4642f19d3a4c784134d'
-            '19800e91ab96a8be828af1383cbbadeda9f65f709e52f1217b54d5f3f1282318'
+            '8ed91802c2a2d5b46c0692c624caf01dcde62a885dc617dda6694f4666de4c8e'
             'f77a5247a3ba63e9fad3a3b2822d0fcfa51e0f79b5a90bd79bf08ea34b64ab07'
-            '0e54249a7754b668b436f0f7aa7e95fff68edbb12a93dbee4660e09a8c695f84'
+            'e30714f9b473d810c28763d067e0b85c75f86f23618d968b49b9d1fced9a1dd6'
             'c5aa7b8abe69e72bfdc6b9ee8afbfd350bcc557e894558f2e6e4087fa9aa0dd8'
             '1d053c5078387021338cfc3a732bed61be1a20a549775573788e9134775c8149'
             '05af96f86b7b3b40b93160fdcb702572401579f8756c0831b5de5f8e9afebeba'
Risk 1/5 · Low PKGBUILD
Result #3325

Comment

The change only adds installation of two additional NVIDIA shared libraries from the already-vendored upstream .run payload. There is no new network fetch, privilege escalation, script execution, or write outside $pkgdir. The package still sources the official NVIDIA download over HTTPS with a pinned version and checksum, and the added files appear to be part of the upstream driver bundle rather than arbitrary artifacts. Low risk, though this remains a proprietary binary package with limited auditability.

@@ -172,6 +172,8 @@ package_nvidia-utils-beta() {
     install -D -m755 "libnvidia-encode.so.${pkgver}"    -t "${pkgdir}/usr/lib"
     install -D -m755 "libnvidia-cfg.so.${pkgver}"       -t "${pkgdir}/usr/lib"
     install -D -m755 "libnvidia-ml.so.${pkgver}"        -t "${pkgdir}/usr/lib"
+    install -D -m755 "libnvidia-fmdrv.so.${pkgver}"     -t "${pkgdir}/usr/lib"
+    install -D -m755 "libnvidia-imex.so.${pkgver}"      -t "${pkgdir}/usr/lib"
     install -D -m755 "libnvidia-glvkspirv.so.${pkgver}" -t "${pkgdir}/usr/lib"
     install -D -m755 "libnvidia-allocator.so.${pkgver}" -t "${pkgdir}/usr/lib"
     install -D -m755 "libnvidia-gpucomp.so.${pkgver}"   -t "${pkgdir}/usr/lib"
Risk 0/5 · Safe PKGBUILD
Result #3326

Comment

The change is low risk. It renames the modprobe config source from nvidia-sleep.conf to nvidia-utils.conf and, based on the file contents, the new file still only contains the expected NVIDIA module blacklist/softdep/options settings. The removed inline blacklist generation is functionally equivalent to the new shipped config file, and the added libraries are standard NVIDIA userland components from the upstream .run payload. No suspicious network access, privilege escalation, or persistence mechanism is introduced by this diff.

@@ -283,11 +285,10 @@ package_nvidia-utils-beta() {
     install -D -m644 "${srcdir}/nvidia-utils.sysusers" "${pkgdir}/usr/lib/sysusers.d/${pkgname}.conf"
     install -D -m644 "${srcdir}/nvidia.rules" "${pkgdir}/usr/lib/udev/rules.d/60-nvidia.rules"
     
-    install -D -m644 <(printf '%s\n%s\n%s\n' 'blacklist nouveau' 'blacklist nova_core' 'blacklist nova_drm') "${pkgdir}/usr/lib/modprobe.d/${pkgname}.conf"
     install -D -m644 <(printf '%s\n' 'nvidia-uvm') "${pkgdir}/usr/lib/modules-load.d/${pkgname}.conf"
     
     # enable NVreg_UseKernelSuspendNotifiers and TemporaryFilePath
-    install -D -m644 "${srcdir}/nvidia-sleep.conf" -t "${pkgdir}/usr/lib/modprobe.d"
+    install -D -m644 "${srcdir}/nvidia-utils.conf" -t "${pkgdir}/usr/lib/modprobe.d"
     
     # Vulkan GTK renderer crash fix
     # https://forums.developer.nvidia.com/t/580-65-06-gtk-4-apps-hang-when-attempting-to-exit-close/341308/5?u=ptr1337
Risk 0/5 · Safe nvidia-utils.conf
Result #3327

Comment

The change adds a modprobe configuration snippet that blacklists nouveau/nova, sets a soft dependency for NVIDIA modules, and enables two NVIDIA driver options. This is a local system configuration change only; it does not introduce code execution, network access, privilege escalation, persistence, or packaging integrity issues. The only notable effect is that it alters kernel module loading behavior and temporary file location for the NVIDIA driver, which is expected for a driver package and not inherently suspicious.

@@ -0,0 +1,15 @@
+# Blacklist nouveau and nova
+blacklist nouveau
+blacklist nova_core
+blacklist nova_drm
+
+# Make sure that all modules are loaded after the main one.
+softdep nvidia post: nvidia-uvm nvidia-drm
+
+# https://download.nvidia.com/XFree86/Linux-x86_64/595.45.04/README/powermanagement.html
+# Enable Suspend Notifiers for faster and more modern suspend
+options nvidia NVreg_UseKernelSuspendNotifiers=1
+#
+# The destination should not be using tmpfs, so we prefer
+# /var/tmp instead of /tmp
+options nvidia NVreg_TemporaryFilePath=/var/tmp
Risk 0/5 · Safe nvidia.rules
Result #3328

Comment

The change narrows the udev trigger from any NVIDIA GPU bind event to only the nvidia_drm kernel module being added, and removes the unconditional nvidia-modprobe invocation for GPU device events. This is a behavior change, but it does not introduce new execution paths, network access, privilege escalation, or persistence mechanisms. The remaining RUN action still invokes the expected local helper with a fixed argument set, and the rule still only fires when /dev/nvidia-uvm is absent. No obvious security regression is present in the diff itself.

@@ -3,7 +3,5 @@
 # nvidia-modprobe in the udev rules to cover the Wayland/EGLStream and compute
 # case without a started display. In the case where vfio-pci is used
 # nvidia-modprobe should not be invoked.
-ACTION=="add|bind", ATTR{vendor}=="0x10de", ATTR{class}=="0x03[0-9]*", \
-    DRIVER=="nvidia", TEST!="/dev/nvidia-uvm", \
-    RUN+="/usr/bin/nvidia-modprobe", \
+ACTION=="add", SUBSYSTEM=="module", KERNEL=="nvidia_drm", TEST!="/dev/nvidia-uvm", \
     RUN+="/usr/bin/nvidia-modprobe -c0 -u"