AUR AI Reviewer

Review Results

Version #2695 of opencl-amd · commit 2772cc685043 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4511

Comment

The change only bumps .SRCINFO metadata from 10.0.0 to 10.1.0 and updates the corresponding AMD HTTPS source URLs and SHA-256 checksums. The sources remain pinned to specific .deb artifacts from AMD's official repository, with no new build-time code execution, no added scripts, and no packaging logic changes in this diff. The main risk is the inherent trust in prebuilt vendor binaries, but that was already present and is not introduced by this metadata-only update.

@@ -1,6 +1,6 @@
 pkgbase = opencl-amd
 	pkgdesc = ROCm components repackaged from AMD's Ubuntu releases (ROCr runtime, OpenCL runtime, HIP runtime) - This package is intended to work along with the free amdgpu stack.
-	pkgver = 10.0.0
+	pkgver = 10.1.0
 	pkgrel = 1
 	epoch = 1
 	url = https://www.amd.com
Risk 0/5 · Safe .SRCINFO
Result #4512

Comment

The change only updates the package metadata to point at newer AMD ROCm .deb artifacts and corresponding SHA256 checksums. The sources remain HTTPS on AMD's official repository, and there is no evidence in this diff of added build-time execution, network fetches outside source=(), privilege escalation, or packaging logic changes. Risk is limited to the usual trust in upstream binary blobs, which was already present before this change.

@@ -42,15 +42,15 @@ pkgbase = opencl-amd
 	conflicts = hsa-amd-aqlprofile
 	conflicts = rocm-cmake
 	conflicts = rocm-smi-lib
-	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-sysdeps10.0_10.0.0-4_amd64.deb
-	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-llvm10.0_10.0.0-4_amd64.deb
-	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-runtime10.0_10.0.0-4_amd64.deb
-	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-base10.0_10.0.0-4_amd64.deb
-	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-opencl10.0_10.0.0-4_amd64.deb
-	sha256sums = 6e99e9d4a9bce350d86624b723586e5e81153aab00ebe989b2ef0e0758c23189
-	sha256sums = 24a33e37d845f1e6809c34f2eebfe4686a4bd76befaf1e1b23605e3978f224ef
-	sha256sums = 531aa7b229a6e42f2048fa4b539e15623a9df679db4cdd0b4bf7e582be0e276d
-	sha256sums = 9f179ac2d9298b07bd7153f780f5cf210e0558281835e2b34753d32e3e3a6e1e
-	sha256sums = 06983f91cd417015411013044a32608784d340cb6104ba1e8b8dbf0fdbd394fa
+	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-sysdeps10.1_10.1.0-3_amd64.deb
+	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-llvm10.1_10.1.0-3_amd64.deb
+	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-runtime10.1_10.1.0-3_amd64.deb
+	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-base10.1_10.1.0-3_amd64.deb
+	source = https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-opencl10.1_10.1.0-3_amd64.deb
+	sha256sums = a2493d98144a586df49489c4b4b7a7449c9eb123597515929699b1b5fccfd916
+	sha256sums = 6a4727102d830f6c97b911351192b15623189278afad9b4558514a6fe51ca58a
+	sha256sums = 2cf4fa3b82f9b37be9fc18ca6886e1791585c1b8041758ccba9e3c5dadb7c6b1
+	sha256sums = a3d48032edee53c51016b28884a1fe81e2d2f84e087c2546dd20753402ad53c9
+	sha256sums = d4c195a9c99bd61f9269fb61a9c396bfdbbe1db5ebea21cc3bc5657f75ca1304
 
 pkgname = opencl-amd
Risk 0/5 · Safe PKGBUILD
Result #4513

Comment

The change is a straightforward version bump in PKGBUILD from ROCm 10.0.0 to 10.1.0, updating the AMD-hosted .deb source URLs, checksums, and the installed directory rename from core-10.0 to core-10.1. The sources remain HTTPS on AMD domains, there is no added build-time code execution, no new install script, and no packaging behavior change beyond selecting a newer upstream release. I did not find evidence of typosquatting, privilege escalation, persistence, or integrity regressions in this diff.

@@ -5,7 +5,7 @@ _rocm_repo='https://repo.amd.com/rocm/packages-multi-arch/ubuntu2604'
 
 pkgname=opencl-amd
 pkgdesc="ROCm components repackaged from AMD's Ubuntu releases (ROCr runtime, OpenCL runtime, HIP runtime) - This package is intended to work along with the free amdgpu stack."
-pkgver=10.0.0
+pkgver=10.1.0
 pkgrel=1
 epoch=1
 arch=('x86_64')
Risk 0/5 · Safe PKGBUILD
Result #4514

Comment

The change is a straightforward version bump of five AMD ROCm runtime .deb sources from 10.0.0-4 to 10.1.0-3, with corresponding SHA-256 updates. The URLs remain HTTPS and point to AMD's official repository, and there are no new build-time commands, scripts, or packaging logic introduced in the shown hunk. I don't see evidence of supply-chain red flags in this diff alone beyond the usual trust in vendor-hosted binary blobs, which was already present before the change.

@@ -19,20 +19,20 @@ optdepends=('clinfo')
 
 source=(
 #runtime
-"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-sysdeps10.0_10.0.0-4_amd64.deb"
-"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-llvm10.0_10.0.0-4_amd64.deb"
-"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-runtime10.0_10.0.0-4_amd64.deb"
-"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-base10.0_10.0.0-4_amd64.deb"
-"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-opencl10.0_10.0.0-4_amd64.deb"
+"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-sysdeps10.1_10.1.0-3_amd64.deb"
+"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-llvm10.1_10.1.0-3_amd64.deb"
+"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-runtime10.1_10.1.0-3_amd64.deb"
+"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-base10.1_10.1.0-3_amd64.deb"
+"https://stable.repo.amd.com/rocm/core/packages/ubuntu2604/pool/main/amdrocm-opencl10.1_10.1.0-3_amd64.deb"
 #dev - todo
 )
 
 sha256sums=(
-"6e99e9d4a9bce350d86624b723586e5e81153aab00ebe989b2ef0e0758c23189"
-"24a33e37d845f1e6809c34f2eebfe4686a4bd76befaf1e1b23605e3978f224ef"
-"531aa7b229a6e42f2048fa4b539e15623a9df679db4cdd0b4bf7e582be0e276d"
-"9f179ac2d9298b07bd7153f780f5cf210e0558281835e2b34753d32e3e3a6e1e"
-"06983f91cd417015411013044a32608784d340cb6104ba1e8b8dbf0fdbd394fa"
+"a2493d98144a586df49489c4b4b7a7449c9eb123597515929699b1b5fccfd916"
+"6a4727102d830f6c97b911351192b15623189278afad9b4558514a6fe51ca58a"
+"2cf4fa3b82f9b37be9fc18ca6886e1791585c1b8041758ccba9e3c5dadb7c6b1"
+"a3d48032edee53c51016b28884a1fe81e2d2f84e087c2546dd20753402ad53c9"
+"d4c195a9c99bd61f9269fb61a9c396bfdbbe1db5ebea21cc3bc5657f75ca1304"
 )
 
 package() {
Risk 0/5 · Safe PKGBUILD
Result #4515

Comment

The change is a simple path update in package() from renaming /opt/rocm/core-10.0 to /opt/rocm/core-10.1. It does not introduce new sources, network access, privilege escalation, or post-install behavior. The only security-relevant question is whether the renamed directory exists in the packaged payload; that is a packaging correctness issue, not a security concern. No malicious patterns are present in this hunk.

@@ -50,7 +50,7 @@ package() {
     done
 
     mv "${srcdir}/opt/" "${pkgdir}/"
-    mv "${pkgdir}/opt/rocm/core-10.0" "${pkgdir}/opt/rocm/core"
+    mv "${pkgdir}/opt/rocm/core-10.1" "${pkgdir}/opt/rocm/core"
 
     mkdir -p "${pkgdir}/opt/amdgpu/share/libdrm"
     cd "${pkgdir}/opt/amdgpu/share/libdrm"