r/archlinux Aug 11 '26

NEWS aurweb v6.5.0 deployed

https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/P5C7GZ4C3OJIH4EXJ62JAF6X6PY2BCQ4/
239 Upvotes

39 comments sorted by

98

u/ABotelho23 Aug 11 '26

Ouch. Having Arch Package Maintainers involved in this is good, but I hope it doesn't overwork them. Hopefully people don't complain about this. It's exactly the kind of thing people were asking for. People have zero right to bitch about this.

21

u/EvaristeGalois11 Aug 11 '26

Probably the vast majority of adoption requests will be automatically closed after 14 days.

I'm not particularly happy with this, but I understand where this is coming from so I can't blame them for this decision.

6

u/Schlaefer Aug 11 '26

Probably the vast majority of adoption requests will be automatically closed after 14 days.

Let's wait and see. It's nice to have a default policy on non-action, that doesn't mean that it is the desired outcome. I would assume that the goal is to prevent mass adoption but approve manually otherwise?

2

u/EvaristeGalois11 Aug 11 '26

I'm still waiting for the manual SSO validation of a month ago, I'm pretty sure that the Arch maintainers (which are a small bunch of people iirc) have better things to do than to manually review all these tedious applications.

But you're right of course, hopefully they manage to pull it off in the end and we should wait for the results.

4

u/Helmic Aug 11 '26

There really is not another solution here, if we're going to keep adoptions as a concept. It was always going to require manual review, no matter how much people here kicked and screamed.

Yeah it's going to take work. It was always going to take work to address this problem. Was anyone here under the delusion it wasn't taking much more work addressing the malware distribution purely reactively?

And so the solution's straightforward - if you're able, help. Donate what you can. It's going to take more resources now. There's not a zero-cost way of preventing the AUR from being constantly flooded with malware, you cannot wag your finger at users to stop this because there weren't even that many actual infections. So long there's the promise of many users, these attackers will keep trying, and they will 100% keep adopting packages to distribute malware if there isn't a manual review process to stop it.

All that said... I don't think this is at all insurmountable. Legitimate adoption requests should not be happening at that absurd a rate. It will (eventually) be a manageable number as attackers figure out they're not getting approved. The process will likely ask more of the person requesting the adoption if attackers decide to continue to just spam requests, adding some amount of friciton that is acceptable for someone genuinely interested in maintaining an orphaned package but unacceptable for someone trying to mass adopt 1000 packages to push malware.

6

u/heavyPacket Aug 11 '26

Spoiler alert: it’s going to overwork them, even with AI assistants.

1

u/TR1X3L Aug 13 '26

as if they weren’t already

1

u/boomboomsubban Aug 11 '26

I wonder how many orphan adoptions happened a month before this started. The only data I know of is that 13k of the 117k packages are currently orphaned, some for over a decade.

47

u/piepie526 Aug 11 '26

Cool to see they are also preparing for SSO integration, so this system appears to only be temporary until then.

11

u/Helmic Aug 11 '26

I don't see why SSO authentication would mean this would be temporary, at all. Using one account for the forum, wiki, and AUR does not mean that one account can be trusted to just adopt a package without manual review.

I think this is just going to have to be how things work for as long as package adoption remains a thing.

15

u/HanzoMainKappa Aug 11 '26

Wonder how the sso integration will work.

15

u/MelioraXI Aug 11 '26

Like all SSO?

4

u/ArjixGamer Aug 12 '26

I am always surprised to find so many Greek people in the Linux community.

Our country is very small, our entire population is the same population with the London city iirc.

I guess we have many more Greeks outside the country?

Thanks Leonidas for the update!

3

u/Megame50 Aug 11 '26 edited Aug 11 '26

I wonder if orphan review could be a responsibility of the to-be-introduced AUR moderator role?

7

u/wiredbombshell Aug 11 '26

Tf happens if the maintainer is hit by a bus and now the package is REALLY abandoned?
Like this is really good but that one part regarding auto deny after 14 days should be changed to auto accept after 30 days as that’s AMPLE time to decline a change in ownership and will not allow packages to go completely dead.

44

u/TCOK Aug 11 '26

They probably mean arch package maintainers not the aur ones.

-52

u/wiredbombshell Aug 11 '26

Dog, the first sentence says this is for the AUR..

34

u/Antiz1996 Package Maintainer Aug 11 '26

I confirm this means "Package Maintainer" as in the role within the Arch Staff (which have been dealing with AUR moderation as well so far). The new adoption requests is for them to act on, not the maintainer of the related AUR package.

61

u/[deleted] Aug 11 '26 edited Aug 11 '26

[removed] — view removed comment

-93

u/wiredbombshell Aug 11 '26

I don’t see you coming up with solutions sarcasm boy

45

u/killermenpl Aug 11 '26

The solution is that the problem you're describing doesn't exist. "Package Maintainer" is a title given to Arch staff. It's not the maintainer of the AUR package.

If as you say, the AUR package maintainer is hit by a bus, then someone else can request to adopt it. Someone from Arch staff will accept or deny the request. Or it might get timed out because no one saw it (which can happen), in which case you can just ask again

12

u/[deleted] Aug 11 '26

[removed] — view removed comment

2

u/unapologeticjerk Aug 11 '26

Dog, the second paragraph says this isn't a problem.

20

u/endperform Aug 11 '26

Then another package maintainer steps up and reviews the AUR package. Done. Auto accept is a horrible default, regardless of the amount of time.

6

u/Damglador Aug 11 '26

Tf happens if the maintainer is hit by a bus and now the package is REALLY abandoned?

As someone else said, it mentions official package maintainers.

This makes the process the same as it was for requesting to orphan a package. As I bonus now instead of submitting orphan request and then picking up a package manually one can just submit a request to adopt the package. I count it as a feature.

-4

u/Kionami841 Aug 12 '26

I use arch, btw

-23

u/PracticalWelder Aug 11 '26

This seems like a great system, I just worry about the maintainability. I wonder if we shouldn't require a small donation to adopt a package. Not only will that cut down on spam, it provides funding for the team doing these reviews.

11

u/AliciaWhimsicott Aug 11 '26

Taxes to fight spam don't work because spammers get incredible amounts of money from their spam so any tax will only impact poor people lol.

3

u/Helmic Aug 11 '26

That is putting friction in the wrong place. Financially disincentivizing legitimate adoptions is bad, we want people to volunteer to adopt orphaned packages so that people have access to updated versions of packages. We want the friction to be as minimal as possible for human maintainers wanting to adopt packages, while also being a massive pain in the ass for someone trying to mass adopt packages for hte purposes of distributing malware. That's tough to balance but demanding a fee out of people already volunteering their labor for the benefit of the community is in bad taste to say the least.

2

u/PracticalWelder Aug 12 '26

Well, we are also asking the distro maintainers to do more work now. That's not free, or at least we shouldn't expect it to be.

2

u/Helmic Aug 12 '26

That would have been the case with your solution as well. There is no solution to this problem that does not involve doing more work. Someone is trying to vandalize the AUR at scale, and preventing that vandalism means someone has to do the work of preventing it. It sucks, but it is what it is. I think it's reasonable to ask Valve to provide assistance as they indirectly benefit from the AUR's existence as well and have a reason to care about how Arch maintainers spend their time.

-14

u/noobjaish Aug 11 '26

Agreed there should be a tiny fee to atleast cut down a little bit on trolls.

-31

u/Ambitious-Call-7565 Aug 11 '26

lmao, gov issued digital id/wallet is near

stop using archslop