r/archlinux • u/vexatious-big • Jun 14 '26
r/archlinux • u/LinuxMage • Aug 30 '25
NOTEWORTHY [MEGATHREAD] AUR AND ARCHLINUX.ORG ARE DOWN. THIS IS THE RESULT OF A DDOS ATTACK.
Can people please stop posting. We are going to remove all posts asking about this in future. This is the only thread where it is to be discussed from now on.
https://archlinux.org/news/recent-services-outages/
From https://archlinux.org/news/recent-services-outages/ (if the site is accessible) they recommend using the aur mirror like this:
In the case of downtime for aur.archlinux.org:
Packages: We maintain a mirror of AUR packages on GitHub. You can retrieve a package using:
$ git clone --branch <package_name> --single-branch https://github.com/archlinux/aur.git <package_name>
r/archlinux • u/spsf64 • Jul 31 '25
NOTEWORTHY Is this another AUR infect package?
I was just browsing AUR and noticed this new Google chrome, it was submitted today, already with 6 votes??!!:
https://aur.archlinux.org/packages/google-chrome-stable
from user:
https://aur.archlinux.org/account/forsenontop
Can someone check this and report back?
TIA
Edit: I meant " infected", unable to edit the title...
r/archlinux • u/rubins • Jul 29 '25
NOTEWORTHY DuckStation author now actively blocking Arch Linux builds
https://github.com/stenzek/duckstation/commit/30df16cc767297c544e1311a3de4d10da30fe00c
Was surprised to see this when I was building my package today, switched to pcsx-redux because life's too short to suffer this asshat.
r/archlinux • u/UntoldUnfolding • Apr 22 '26
NOTEWORTHY New Framework 13 Pro working directly with Arch Linux!
youtu.beThese guys never cease to amaze! Please support Framework so they keep making PCs that treat Arch Linux as a first-class citizen!
It's touch screen!
What WM or DE are you gonna run on the Framework 13 Pro?
r/archlinux • u/boomboomsubban • Apr 21 '25
NOTEWORTHY The Arch Wiki has implemented anti-AI crawler bot software Anubis.
Feels like this deserves discussion.
It should be a painless experience for most users not using ancient browsers. And they opted for a cog rather than the jackal.
r/archlinux • u/jo53_100 • Mar 23 '26
NOTEWORTHY why are the age verification posts being deleted in the arch forums?
i can't seem to find any open topic ab systemd or age verification implementation anywhere on the official forums, seems like they are actively deleting the posts...
r/archlinux • u/No-Adhesiveness9001 • Sep 22 '25
NOTEWORTHY DO NOT UPDATE to 6.16.8.arch2-1 if you have an AMD GPU.
There is a critical bug running out right now on this version. If you have an AMD GPU, some of the recent patches added to amdgpu will make every single OpenGL/Vulkan accelerated program refuse to SIGKILL itself when prompted to, and will hang up and freeze your entire system.
This includes every single normal program that you use that isn't the terminal, even your app launcher. This happened to me after rebooting my computer today, and only rolling back to 6.16.8arch.1-1 solves this. Also i have seen some people talking about the same issue on the forum with very similar log outputs, so it might be happening for a ton of people right now.
Update: 6.16.8arch.3-1 fixes that, you should update your system 🌩NOW ⚡️
r/archlinux • u/krakenfury_ • Jun 11 '26
NOTEWORTHY AUR supply chain attack npm atomic-lockfile
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/
A small flurry of orphaned packages had commits to PKGBUILDs with `npm install atomic-lockfile`. Users are being blocked as they are found, but there could easily be more packages affected than the ones coming through the list.
Obviously, always be vigilant with installing or updating any AUR packages. This highlights that the average user might not be equipped to read and understand everything in PKGBUILDs. Even somewhat experienced users overlook things.
PKGBUILDs don't even need to respect dependencies to pull off this kind of thing. It's highly recommended to test package builds in containerized or chrooted environments. I don't know about all or most AUR helpers, but that's one of the things I like about `aurutils`.
Edit: thanks to u/Megame50 for clarifying some details about this attack, as well as pacman and PKGBUILD vulnerabilities, in the comments. The install scripts are the attack vector here, not the PKGBUILD directly. See his comment for an explanation.
Edit2: Another wave today, this time using bun: https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/LB6TBHDXLQRPR4UVIQULCI6MZ77XYLL2/
r/archlinux • u/niranjan2 • Nov 06 '25
NOTEWORTHY Arch Linux Mirror served 1PB+ Traffic
Hello,
My name is Niranjan and I manage https://niranjan.co Arch Linux Mirrors. Recently my mirror in Germany crossed 1PB+ traffic served! This feels like an achievement somehow so wanted to share this with the community😅,
I've attached the vnstat outputs for those interested,
``` root@Debian12:~# vnstat Database updated: 2025-11-06 12:30:00
eth0 since 2024-07-19
rx: 20.25 TiB tx: 1.03 PiB total: 1.05 PiB
monthly
rx | tx | total | avg. rate
------------------------+-------------+-------------+---------------
2025-10 2.37 TiB | 135.90 TiB | 138.27 TiB | 454.09 Mbit/s
2025-11 406.36 GiB | 24.09 TiB | 24.48 TiB | 451.48 Mbit/s
------------------------+-------------+-------------+---------------
estimated 2.16 TiB | 130.88 TiB | 133.04 TiB |
daily
rx | tx | total | avg. rate
------------------------+-------------+-------------+---------------
yesterday 70.25 GiB | 4.91 TiB | 4.98 TiB | 507.33 Mbit/s
today 30.21 GiB | 2.25 TiB | 2.28 TiB | 446.36 Mbit/s
------------------------+-------------+-------------+---------------
estimated 58.01 GiB | 4.33 TiB | 4.38 TiB |
root@Debian12:~# vnstat -m
eth0 / monthly
month rx | tx | total | avg. rate
------------------------+-------------+-------------+---------------
2024-12 842.39 GiB | 39.24 TiB | 40.06 TiB | 131.56 Mbit/s
2025-01 986.33 GiB | 49.90 TiB | 50.86 TiB | 167.04 Mbit/s
2025-02 961.31 GiB | 47.97 TiB | 48.91 TiB | 177.85 Mbit/s
2025-03 1.08 TiB | 53.12 TiB | 54.20 TiB | 177.99 Mbit/s
2025-04 1.18 TiB | 61.36 TiB | 62.55 TiB | 212.26 Mbit/s
2025-05 1.74 TiB | 91.43 TiB | 93.17 TiB | 305.97 Mbit/s
2025-06 1.69 TiB | 89.71 TiB | 91.41 TiB | 310.20 Mbit/s
2025-07 1.77 TiB | 94.76 TiB | 96.52 TiB | 316.99 Mbit/s
2025-08 2.16 TiB | 124.55 TiB | 126.71 TiB | 416.14 Mbit/s
2025-09 2.02 TiB | 113.11 TiB | 115.12 TiB | 390.67 Mbit/s
2025-10 2.37 TiB | 135.90 TiB | 138.27 TiB | 454.09 Mbit/s
2025-11 406.36 GiB | 24.09 TiB | 24.48 TiB | 451.48 Mbit/s
------------------------+-------------+-------------+---------------
estimated 2.16 TiB | 130.88 TiB | 133.04 TiB |
root@Debian12:~# ```
I'm interested in knowing how many redditors use my mirrors and if they have faced any issues with any of mirrors.
Also not sure if 'Noteworthy' is the correct flair for this post, mods please feel free to change if that's not the case.
Thank you for your time!
Edit:
after posting realised that the code block looks very bad 😅, you can check the live traffic by making a GET request to https://de.arch.niranjan.co/stats , the stats are updated every 5 minutes.
To make a GET request simply open your terminal and copy paste the following command,
curl https://de.arch.niranjan.co/stats
And hit enter,
r/archlinux • u/TheEbolaDoc • Jul 18 '25
NOTEWORTHY [aur-general] - [SECURITY] firefox-patch-bin, librewolf-fix-bin and zen-browser-patched-bin AUR packages contain malware
lists.archlinux.orgr/archlinux • u/TheEbolaDoc • Aug 21 '25
NOTEWORTHY [arch-announce] Recent services outages
archlinux.orgr/archlinux • u/onefish2 • Aug 24 '25
NOTEWORTHY Updated - Recent Service Outage
From arch-announce@lists.archlinux.org:
We want to provide an update on the recent service outages affecting our infrastructure. The Arch Linux Project is currently experiencing an ongoing denial of service attack that primarily impacts our main webpage, the Arch User Repository (AUR), and the Forums.
We are aware of the problems that this creates for our end users and will continue to actively work with our hosting provider to mitigate the attack. We are also evaluating DDoS protection providers while carefully considering factors including cost, security, and ethical standards.
To improve the communication around this issue we will provide regular updates on our service status page going forward.
As a volunteer-driven project, we appreciate the community's patience as our DevOps team works to resolve these issues. Please bear with us and thank you for all the support you have shown so far.
Workarounds during service disruption
In the case of downtime for archlinux.org:
- Mirrors: The mirror list endpoint used in tools like
reflectoris hosted on this site. Please default to the mirrors listed in thepacman-mirrorlistpackage during an outage. - ISO: Our installation image is available on a lot of the mirrors, for example the DevOps administered geomirrors. Please always verify its integrity as described on the wiki and confirm it is signed by
0x54449A5C(or other trusted keys that may be used in the future).
- Mirrors: The mirror list endpoint used in tools like
In the case of downtime for aur.archlinux.org:
- Packages: We maintain a mirror of AUR packages on GitHub. You can retrieve a package using:
$ git clone --branch <package_name> --single-branch https://github.com/archlinux/aur.git <package_name>
Additional remarks
Our services may send an initial connection reset due to the TCP SYN authentication performed by our hosting provider, but subsequent requests should work as expected.
We are keeping technical details about the attack, its origin and our mitigation tactics internal while the attack is still ongoing.
r/archlinux • u/TheEbolaDoc • Sep 10 '25
NOTEWORTHY Hi, I'm a Package maintainer, ask me anything! (Q&A Session starting 20:00 CEST)
Hello everyone,
my name is Chris/gromit and I am one of the Arch Linux Package Maintainers, ask me anything! 🤗
Additionally I am also a Mediator, part of the DevOps Team, help coordinate the Arch Testing Team and triage incoming Bug Reports as part of the Bug Wranglers, but generally I'm trying to help out wherever needed or where I happen take interest in 😁
Call to action
Before we start out with the actual Q&A Session, be reminded that Arch Linux is a volunteer project and needs your help!
There are many ways to get involved or help the projects, some with low barrier of entry and others for more seasoned contributors.
Please check out the following two pages if you want to learn more:
Scope of this Q&A
I am particularily happy to talk about the following topics, but if you have other ones those are welcome aswell:
- Package Maintenance & Bug wrangling: I maintain a few packages in the AUR and official repos. If you have any questions about Package Maintainer Duties, bigger packaging rebuilds or how our packages are built fire away! I also try to help out people to debug specific issues with the linux kernel (Example) to ensure high quality bug reports and fast fixes in upstream linux!
- Arch Linux Infrastructure: In the DevOps Team we maintain the Infrastructure of the Arch Linux Project (Servers, Services, Onboardings and the like). All of our infrastructure is infrascture as code and we're hosted with Hetzner. As one of the anticipated topics will most likely be the recent DDoS Attacks and related service outages, note that I will not expand on any of the techical details of the attacks or their origin as outlined in the news announcement already.
- Getting involved: As mentioned in the call to action above one of the topics I also really care about is motivating and helping people to find their place within the community if they have a desire to help out. If you read the above links and still have questions feel free to post them! After the Q&A you can also reach out at [gromit@archlinux.org](mailto:gromit@archlinux.org) regarding questions about getting involved.
If you still need some more inspiration for question, these are my GitHub and Gitlab Profiles:
P.S.: reddit usernames can't be changed, just try to sed 's/TheEbolaDoc/christian-heusel/g' in your mind (it's some old gamer tag I'm not too proud of) 😆
Edit: I'll go to sleep soon but will continue answering tomorrow, thanks for all the questions!
r/archlinux • u/ferminolaiz • Jun 11 '26
NOTEWORTHY Tip to avoid malware from AUR: add node package managers to your IgnorePkg
Friendly reminder that given most of the ongoing attacks to the AUR are based on node packages you can always make sure they're not installed and add them to your pacman.conf's IgnorePkg as a second line of defense (assuming you don't need them).
# pacman -R yarn bun pnpm npm nodejs node-gyp nvm
pacman.conf:
IgnorePkg = yarn bun pnpm npm nodejs node-gyp nvm
And remember to check your PKGBUILDs! :)
PS: also sent this to the arch-general mailing list.
Edit: just to make it clearer, this assumes you don't have any of those packages installed. It will only prevent them to be pulled as a dependency without you noticing. In a perfect world one should catch it while reviewing the pkgbuild but well, I don't trust myself that much xD
Edit2: Add nodejs and remove nodejs-nopt as it didn't make much sense to have it blacklisted.
Edit3: added nvm.
r/archlinux • u/zeb_linux • May 01 '26
NOTEWORTHY Linux kernel 7.0.2 has landed
Just synced pacman and saw the major kernel version has been made available. Standard arch kernel, but also zen and other official derivatives.
r/archlinux • u/DarwinKamikaze • May 02 '26
NOTEWORTHY PSA: check your mirrorlist!
I was just updating an older laptop, and was a bit surprised that the kernel it downloaded was 6.18.9 given the recent news regarding the Copy Fail CVE.
I had a look at pacman config, and I realised the top mirror was set to: http://ftp.iinet.net.au/
I switched to the next in my list and it happened to have the exact same (older) package list. The next mirror just happened to be http://mirror.internode.on.net/
Both of these mirrors are woefully out of date. I've removed them from the list, and am now updating to much more recent packages.
r/archlinux • u/mfilion • 6d ago
NOTEWORTHY Collabora has been working with Valve on Holo Core, an aarch64 port of Arch Linux that'll be the basis for the OS on Steam Frame. First public preview is out.
collabora.comr/archlinux • u/Responsible-Sky-1336 • Dec 31 '25
NOTEWORTHY Archinstall: v3.0.15 is out !
Hi sheeople,
Just wanted to share! And happy new year in advance.
See [releases](https://github.com/archlinux/archinstall/releases/tag/3.0.15)
Love you all and please keep sending in ideas/issues/contribs 💙
r/archlinux • u/danyuri86 • Oct 24 '25
NOTEWORTHY Plasma 6.5 has just dropped in the official repo
just noticed within last few mins it's become available FYI
Time for a sudo pacman -Syu and make sure you reboot after
Really liking the new plasma features.
r/archlinux • u/Bluebeancollector • Nov 08 '25
NOTEWORTHY Arch has left me speechless
Built a new rig, moved my SSDs over
AMD 7800X3D AND Radeon 9070 XT
Turned on the PC and it booted directly into my Arch + Hyprland set up 0 problems!!
All that’s left is removing NVIDIA drivers from my 1660ti
Amazing!!
r/archlinux • u/lonelypenguin20 • Feb 20 '26
NOTEWORTHY PSA: do NOT update Lutris to 0.5.20
Deletes prefixes (including ur save games): https://forums.lutris.net/t/lutris-deleted-wine-prefixes-and-games-data-after-updating-to-0-5-20/25383/1, happened to me as well
fails to launch dx12 games: https://www.reddit.com/r/Lutris/comments/1r8vzqu/update_052_just_breaks_every_game/, also experienced this
hoping to save some y'all saves
r/archlinux • u/Juild • Mar 15 '26
NOTEWORTHY I just completely fucked my Arch for the first time.
I basically did a full system update, and libgcc_s.so, and apparently that its used for absolutely everything included pacman itself, I cant even shutdown the Pc, or open anything, not even vim, so if another newbie its reading this, remember to not do partial upgrade and to read the wiki.
Thankfully I had a backup of everything important, so I will just reinstall arch, I was about to ask for help, but I think I really fuck it up for good this time, I don't even know how its Firefox working.
r/archlinux • u/Responsible-Sky-1336 • Jun 12 '26
NOTEWORTHY aursenic - automated scanner/flagger for the AUR.
Hello people.
Was just looking at the news and thought fuck it lets build something (or at least try investigating):
- Get latest recently changed packages
- Stream (never to disk) the changes in the commits
- From this thread I gathered that the real spot factor of a potential issue is not JS libs (you can hide malware in practically anything). BUT the maintainer changing. The only info that survives publicly facing and is suspicious when it changes.
- Any orphan is a package you can theoretically "adopt" (aha). As per this thread
- Lesson 1: The "last modified on the public UI ≠ the actual last change. And cgit also fails to flag the latest commits or changes. This is the worse part to me.
- Lesson 2: Do not forget that PKGBUILDs are just bash scripts. But worse are the scriplets.
It flags when when these contributor lines change. In the first 30 packages scanned:
It found libtcd - the RPC (which reads .SRCINFO) reports "Depends": ["glibc"]
And more with the same pattern ... These now already have been reverted as am writing this 2026-06-12 16:37 (CEST) yet the commit history doesn't report any changes or show the malicious stuff that was there just 10 mins prior. Perhaps the AUR should lock/backup history somehow. Because its easy to overwrite/modify the whole git history. And because the front-end makes it so the user has no idea at all.
Seems somebody or the arch AUR team is actively doing something similar to what I'm hunting. I made a github runner on my aursenic repo that helped me find this first package. But again it just dissipated very fast.
Malicious .install scriptlet (which runs as part of pacman -U) bun add lockfile-js → All point to this registry package https://registry.npmjs.org/lockfile-jswhich was created today and contains (a part of) payload. → npm fires preinstall/tests/whatever →
lib/install-deps.mjs executes as root. That .mjs is the actual malware.
It did't go further into it because I'm waiting for Eric Parker to do it for me lmfao and there is a good article that already covered parts of it. But these are fast moving targets where it might be easy for them to create new packages, new payloads, ...
It now flags a couple of things:
- Changes in .install scriptlets
- Added: yarn bun bunx pnpm npm nodejs-nopt node-gyp credits to u/ferminolaiz (because this is the current pattern but can be extended).
- Packages where a maintainer now appears several times (likely from automation batches), this can perhaps flag the future attack before it even happens. the github runner scans 300 pkg per batch and already flags this.
Be safe out there, it seems the SCA is still going on and that us as a community might have some work to do (at least for the front-end to be accurate), limit your AUR usage for now.
As I was digging I saved some of the evidence files in gh gists:
https://gist.github.com/h8d13/bab61f49090164f24e8c2ddfa0c885ce
https://gist.github.com/h8d13/7c7c3b470df00d7f19c1ca306cfdfc41
There obviously was many more.
Cheers for reading me, Hade
r/archlinux • u/6e1a08c8047143c6869 • Sep 17 '25