Aura-Emerge
AuraEmerge
GitHub Install

Documentation

Full reference for world, make.conf, mask, sandbox, scanner, and everyday usage — the README in page form.

Installation

AUR helper

paru -S aura-emerge
# or
yay -S aura-emerge

Makepkg

git clone https://aur.archlinux.org/aura-emerge.git
cd aura-emerge
makepkg -si

Dependencies

  • Required: git
  • Optional: devtools (--abs), gnupg (--autopgp), bubblewrap (sandbox; without it builds fall back to plain makepkg)
Binary name
The installed binary is emerge (with a portageq symlink). Completions and the man page are generated from the same CLI definition.

World & sets

Path: /etc/portage/world. Every explicitly installed package is added automatically and removed on unmerge. You can edit it by hand: one package per line, optional repo prefix.

cachyos-extra-v3/rust-analyzer
aur/ayugram-desktop-bin
abs/nano-custom
extra/firefox
Err/local-thing

Prefixes: the name of any sync repository (third-party ones included), aur/, abs/, or Err/ (source unknown).

$ rg keyring /etc/portage/world
cachyos/archlinux-keyring
cachyos/cachyos-keyring
chaotic-aur/chaotic-keyring

Two meanings of @world

  • emerge @world (no -u) — provision: install whatever world lists that is not on the system yet.
  • emerge -u @world (or emerge -u) — upgrade: upgrade everything already installed. It does not read world.
  • emerge --sync — database refresh only.

Custom sets

/etc/portage/sets/<name>.set is invoked as @<name>. One atom per line, # comments allowed. Sets combine freely with each other and with plain packages:

emerge @game-kit @dev-tools neovim
emerge --list-sets

Entries without a prefix are resolved through the official repos first, and through the AUR only if that misses — here ttf-comic-sans comes from the AUR:

$ emerge -at @fonts
>>> Not found in official repos: 'ttf-comic-sans'. Searching AUR...

These are the packages that would be merged, in order:

Calculating dependencies... done!

[ebuild  R ] noto-fonts-1:2026.09.01-1
[ebuild  R ] noto-fonts-emoji-1:2.051-1
[ebuild  R ] ttf-material-icons-2.874-1
[ebuild  R ] aur/ttf-comic-sans-5.14-1
[ebuild  R ] `-- gnu-free-fonts-20120503-9

Total: 8 package(s)

--regen-world / --regen-sets @name re-resolve repo prefixes. Add --regen-sort to alphabetize a set (this drops comments and grouping).

Layout of /etc/portage

/etc/portage/
├── make.conf
├── env/                 # env files for package.env
├── package.env/         # a file, or a directory of files
├── package.mask/        # a file, or a directory of files
├── sets/                # custom sets: <name>.set
├── world
├── lastaction.state     # emerge's own state files
└── resume.state

make.conf

/etc/portage/make.conf and ~/.config/emerge/make.conf are aura-emerge's own config (not makepkg.conf). The system file is read first and the user file last; the last key wins.

A real config from a working machine:

#EMERGE_DEFAULT_OPTS=""
#
CFLAGS="-march=znver3 -O2 -pipe -fno-plt -fexceptions -Wp,-D_FORTIFY_SOURCE=3 -Wformat -Werror=format-security -fstack-clash-protection -fcf-protection -fstack-protector-strong -falign-functions=32 -falign-loops=32 -ftree-vectorize -funroll-loops"
CXXFLAGS="$CFLAGS -Wp,-D_GLIBCXX_ASSERTIONS"
CPPFLAGS="$CFLAGS"

RUSTFLAGS="-C target-cpu=znver3 -C opt-level=3 -C codegen-units=1 -C target-feature=+avx2,+fma,+bmi1,+bmi2,+aes,+sha,+sse4.2,+popcnt,+vaes,+vpclmulqdq,+movbe,+f16c"

LDFLAGS="-Wl,-O1 -Wl,--sort-common -Wl,--no-as-needed -Wl,-z,relro -Wl,-z,now -Wl,-z,pack-relative-relocs"

MAKEFLAGS="-j16"
NINJAFLAGS="-j16"

BUILDENV="!distcc color check !sign"
OPTIONS="strip docs !libtool !staticlibs emptydirs zipman purge !debug !lto"
  • Syntax: flat shell-style assignments — KEY="value", KEY='literal', KEY=(a b c). Lines starting with # are comments. Values are shell-expanded, so -j$(nproc) and CXXFLAGS="$CFLAGS" work.
  • Build flags are applied through a generated makepkg.conf passed to makepkg --config. Each build says so:
>>> applying build flags from /etc/portage/make.conf
>>> caching sources under /home/user/.cache/aura-emerge/sources -- VCS sources (-git/-hg/-svn) fetch incrementally on rebuild instead of re-cloning; pass SRCDEST in makepkg.conf to change this.
  • Source cache: sources are cached under ~/.cache/aura-emerge/sources; VCS sources (-git/-hg/-svn) are fetched incrementally on rebuild instead of re-cloned. Set SRCDEST in makepkg.conf to change the location.
  • EMERGE_DEFAULT_OPTS is spliced into every run and accepts only an allowlist of modifier flags — not actions such as --unmerge.
  • Conflicts: contradicting pairs (--aur/--abs, --no-sandbox/--unshare-net-build, …) are rejected, or the config side is dropped when the command line is more specific.
  • --ignore-default-opts skips the defaults for one run; emerge --info shows the loaded files and the expanded values.

package.mask

/etc/portage/package.mask lists packages this machine never installs. It is a standing decision, not a prompt: a masked package is refused even when its PKGBUILD is clean, when it is pulled in as a transitive AUR dependency, or when you request it by name.

ayugram-desktop-bin            # bare name: any source
aur/*-bin                      # only from the AUR, '*' allowed
extra/nano                     # only from that official repo
*-git                          # anything matching, any source

File or directory

Like Portage, the path may be a single file or a directory. In a directory every regular file is read — any name, no extension needed, dotfiles skipped — in filename order.

A real directory-style mask and what it does:

$ cat /etc/portage/package.mask/emacs.mask
emacs
emacs-*
ecb
semi

$ emerge emacs

 * The following package(s) are masked and will not be installed:

  emacs
    masked by emacs (/etc/portage/package.mask/emacs.mask:1)

 * Edit /etc/portage/package.mask (a file, or a directory of files) to change that.

Entry syntax

  • One entry per line; blank lines and lines starting with # are ignored.
  • An optional repo/ prefix (aur, abs, or an official repo name) limits the entry to that source. Without it the entry matches everywhere.
  • * matches any run of characters. Other allowed characters: letters, digits and @ . _ + -.
  • A trailing # reason is shown when the mask fires.
  • An invalid entry is skipped with a warning that names the file and line.

Safety

A mask file that is a symlink is refused with a warning — the file is not read.

When a mask fires, aura-emerge lists each package with the entry that blocked it (file:line) and its reason. Explicitly requested packages abort the run rather than being quietly filtered. For a one-run skip use --exclude instead.

package.env

/etc/portage/package.env gives individual packages their own build flags. Each entry names a package and one or more env files from /etc/portage/env/; those files are laid over make.conf for that package's build only.

$ cat /etc/portage/package.env/neovim
abs/neovim lto.conf

$ cat /etc/portage/env/lto.conf
CFLAGS="-march=znver3 -O2 -pipe -fno-plt -ftree-vectorize"
MAKEFLAGS="-j16"
OPTIONS="strip docs !libtool !staticlibs emptydirs zipman purge !debug lto"

The build says which files it used:

$ emerge --abs neovim
>>> Emerging (1 of 1) abs/neovim-0.12.5 (ABS)
…
>>> applying build flags from /etc/portage/make.conf, /etc/portage/env/lto.conf

File or directory

Same as package.mask: package.env may be one file or a directory. In a directory every regular file is read — any name, dotfiles skipped — in filename order.

Entry syntax

  • One entry per line: an atom, then one or more env file names separated by spaces. Blank lines and # comments are ignored.
  • The atom follows the package.mask rules: optional repo/ prefix (aur or abs), * allowed. Without a prefix it matches any source.
  • Env files use make.conf syntax. Only the build variables count (CFLAGS, CXXFLAGS, MAKEFLAGS, OPTIONS, …); EMERGE_DEFAULT_OPTS is ignored with a warning.
  • A package matches by its pkgbase or by any of its pkgnames from .SRCINFO.

Layering

Order of application: make.conf, then every matching entry in file and line order, then each env file in the order it is named on the line. The last layer to set a variable wins, and the variable is replaced as a whole, not merged: an OPTIONS array in an env file replaces the one from make.conf, so list every option you want.

If two layers set the same variable to different values, the build tells you which one won:

>>> Warning: package.env: CFLAGS = '-O0' from /etc/portage/package.env/20-b:1 [slow] overrides '-O3 -pipe' from /etc/portage/package.env/10-a:1 [fast.conf]

Safety

A symlinked package.env file or env file is refused with a warning. An invalid entry, or an env file that is missing or unreadable, is skipped with a warning naming the file and line; the rest still applies.

Only AUR and ABS builds are affected — official packages are installed by pacman and not built here.

--exclude / --keep-going

--exclude

--exclude <atom> (repeatable or comma-separated) leaves a package out of the current run: installs, -u, @world, depclean/prune and revdep.

emerge -u --exclude linux --exclude aur/ayugram-desktop-bin
emerge --exclude firefox @world

Names are compared bare, so --exclude extra/nano and --exclude nano both skip nano. Skipped packages are reported: >>> N package(s) skipped by --exclude: …. Unlike package.mask, an exclude is not persistent: it applies to one run only.

--keep-going

Without it a batch stops at the first failure. With --keep-going every failed atom is recorded together with a short reason (each atom once), the rest of the batch continues, and an end-of-run summary is printed to stderr.

>>> Warning: the following package(s) were not found anywhere (official repos or AUR) and were skipped:
    aur/foo
…
>>> Warning: not all requested packages were installed successfully.
>>> 1 package(s) failed; `emerge --resume` will retry just those.

 * The following 1 package(s) failed to build or install:

  aur/foo (not found in official repos or the AUR)

 * Everything else in this run completed. Retry just the failures with emerge --resume.

The exit code is non-zero if anything failed. emerge --resume then retries only the failed packages.

-t / --tree, --deep

--tree prints the plan as a dependency tree (emerge -pt style). By default one level is nested; --deep nests the full chain and --deep=N caps it at N levels.

emerge -apt noctalia --aur
emerge -pt noctalia --aur --deep
emerge deepin-session --ask --tree --deep=3

A real run — the requested package is at the top of the tree, while installation goes bottom-up, so dependencies are built before the packages that need them:

$ emerge -at system/openssh-openrc --deep

These are the packages that would be merged, in order:

Calculating dependencies... done!

[ebuild  N ] openssh-openrc-20210505-1
[ebuild  N ] `-- openrc-0.63.3-2
[ebuild  N ]   `-- artix-cgroups-0.7.2-1
[ebuild  N ]   `-- inetutils-2.8-1.1
[ebuild  N ]   `-- netifrc-0.7.14-1
[ebuild  N ]   `-- libeinfo-0.63.3-2

Total: 6 package(s)

>>> Verifying ebuild manifests
>>> Emerging (1 of 6) artix-cgroups-0.7.2-1
>>> Emerging (2 of 6) inetutils-2.8-1.1
>>> Emerging (3 of 6) netifrc-0.7.14-1
>>> Emerging (4 of 6) libeinfo-0.63.3-2
>>> Emerging (5 of 6) openrc-0.63.3-2
>>> Emerging (6 of 6) openssh-openrc-20210505-1
...
:: Продовжити встановлення? [Y/n] n
  • N — new package, R — reinstall.
  • Packages from the AUR are shown with their aur/ prefix.
  • An atom may carry a repo prefix on the command line, as in system/openssh-openrc.

Merge / unmerge log

/var/log/emerge.log is an append-only, human-readable record of merges and unmerges — Portage's emerge.log for pacman/AUR/ABS atoms. One line per event:

2026-09-21 08:51:44  MERGE    aur    noctalia-5.1.0-1.1        (12s)
2026-09-21 08:52:10  MERGE    aur    libqalculate-5.12.0-1.1   (9s)
2026-09-21 09:03:02  MERGE    extra  nano-8.0-1  vim-9.1-1     (4s)
2026-09-21 09:10:05  UNMERGE  -      old-package-2.0-1
  • Durations are real. AUR/ABS packages build one at a time, so each gets its own timer. A pacman -S/-R batch is a single transaction: it is logged as one line with every atom and the batch's total time.
  • Time format: 12s, 1m5s, 1h2m3s.
  • Writing: the file is root-owned, so lines are appended through sudo tee -a. Logging is best-effort — a failed write is silent and never fails or slows a merge that already happened. A symlinked log path is refused.
  • emerge --info reads the log and shows the number of merges and unmerges plus the cumulative build time. If the file is missing or unreadable, that line is simply omitted.

Arch news

emerge --news reads the Arch Linux news feed, eselect-news style. Manual interventions are announced there, so check it before a big upgrade.

emerge --news          # list the 30 latest, unread marked N
emerge --news 3        # read item 3 (marks it read)
emerge --news all      # mark everything as read
$ emerge --news
>>> Fetching Arch Linux news...
>>> Arch Linux News (https://archlinux.org/news/)
   1  [N]  22 Sep 2026  Mkinitcpio >=42 requires manual intervention for TPM2-based unlocking of LUKS devices
   2  [N]  21 Jul 2026  virtualbox-ext-vnc >= 7.2.12-2 requires manual intervention
   3  [ ]  12 Jun 2026  Active AUR malicious packages incident

>>> 2 new news item(s). Use `emerge --news <N>` to read one, `emerge --news all` to dismiss all.
  • Read state is kept per user in ~/.cache/aura-emerge/news.state — no root needed.
  • Before -u, a quick heads-up shows how many news items are unread. If the feed cannot be fetched the upgrade is never blocked.
  • If the feed is unreachable, --news itself exits with an error.

Usage highlights

emerge neovim                              # repos → AUR fallback
emerge neovim-git --aur                    # AUR only, recursive AUR deps
emerge neovim --abs                        # ABS in bwrap
emerge -u @world                           # full upgrade (does not read world)
emerge @world                              # provision from world
emerge --scan neovim-git --aur             # audit only
emerge --install-pkgbuild ~/src/my-pkg     # local PKGBUILD (scanner + sandbox)
emerge -u --devel                          # upgrade + rebuild moved -git
emerge --revdep-rebuild                    # broken shared-library links
emerge --batchinstall pkgs.txt             # mass-install from list
emerge --news                              # Arch news
emerge --undo                              # undo last install/unmerge
emerge --resume                            # resume interrupted run

See the Flags page for the full table.

Security: PKGBUILD scanner

Before every AUR install, the raw PKGBUILD and its .install hook (install=, which runs as root) are fetched from cgit and scanned. $pkgname/$pkgbase in the hook name are expanded first. If cgit cannot be reached this is reported as “nothing to check”, not as clean; once the package is cloned, the clone itself is scanned when its content differs from what was pre-scanned.

Two layers

  1. AST (tree-sitter-bash) — structural checks that survive quoting, concatenation and env-wrapper tricks that defeat plain text matching. It only matches statically known command names; if parsing fails, the line heuristics take over.
  2. Line heuristics — text patterns and exact indicators of compromise (IOCs).

Two severities

SeverityPrinted asMeaning
ConfirmedIocAlert, matched a known-malicious IOCExact match with a documented campaign: low chance of a false positive.
SuspiciousWarning, detected suspicious fragmentHeuristic: worth reading, may be a false positive.

Confirmed IOCs

  • Known-malicious package names (atomic-lockfile, js-digest, lockfile-js) — the Atomic Arch npm/bun infostealer campaign, June 2026.
  • Published payload SHA-256 hashes (openconnect-sso wave, Jul/Aug 2026).
  • The compromised.txt marker from the 2018 acroread/balz/minergate AUR takeover.
  • The requested package itself being on the list of AUR packages hijacked in the early-August 2026 wave (also applies to openconnect-sso and storageexplorer-bin). Absence from that list does not mean a package is clean.

Heuristic checks

PatternWhy it matters
curl|sh, wget|shRuns a remote script straight in a shell
eval "$(curl …)", source <(curl …)Runs fetched content without a literal pipe
base64 / hex decode, | sh, \xHH runs, openssl decryptObfuscated or inline-stashed payloads
python -c exec/eval, sh -c payloadsInline obfuscated execution
sudo / pkexec / doas in the build scriptmakepkg builds unprivileged on purpose; this escalates mid-build
chmod 777World-writable / executable permissions
raw IPv4, .onion, paste sitesHardcoded C2 or second-stage delivery
npm/bun/yarn/pip/gem installing a named package mid-buildHow the Atomic Arch payload was smuggled in
command substitution outside any functionRuns whenever anything merely sources the PKGBUILD (--printsrcinfo, an AUR helper's metadata read)
executable installed under a generic tool name (linter, hasher, validator, …)Payload-disguise technique of the early-August 2026 wave
TracerPid, LD_PRELOAD probesAnti-debugger / anti-sandbox fingerprinting

Example

A deliberately hostile test package (output shortened, … marks omitted lines):

$ emerge --install-pkgbuild ./scaner-test --ask
>>> Scanning scaner-test for suspicious patterns...
>>> 'scaner-test' wasn't scanned before cloning (cgit fetch failed or this pkgbase was only resolved after cloning) -- scanning the clone directly...

>>> ===================================
>>> Alert, matched a known-malicious IOC (scaner-test)
>>> ===================================
>>> file PKGBUILD line 29: references 'atomic-lockfile' - a known-malicious package name from a documented AUR supply-chain campaign (Atomic Arch, June 2026)
>>> file PKGBUILD line 11: sha256 'e73a35b3e75e94746428d1a207703d6335933deadee7d1d9c9d0328df7b9df77' matches a published payload hash from the openconnect-sso-anchored AUR wave (Jul/Aug 2026)
>>> file scaner-test-therandtxt.install line 3: references 'compromised.txt' - the exact marker file dropped by the 2018 acroread/balz/minergate AUR takeover
>>> file scaner-test-therandtxt.install line 2: references 'js-digest' - a known-malicious package name from a documented AUR supply-chain campaign (Atomic Arch, June 2026)
>>> Read full file: ./scaner-test/PKGBUILD
>>> Read full file: ./scaner-test/scaner-test-therandtxt.install

>>> ===================================
>>> Warning, detected suspicious fragment (scaner-test)
>>> ===================================
>>> file PKGBUILD line 16: downloads and pipes a remote script straight into a shell (curl/wget | sh)
>>> file PKGBUILD line 18: decodes a base64 blob (possible obfuscated payload)
>>> file PKGBUILD line 25: sets world-writable/executable permissions (chmod 777)
>>> file PKGBUILD line 10: fetches from or references a hardcoded raw IP address instead of a domain
>>> file PKGBUILD line 26: invokes sudo/pkexec/doas from inside the build script - makepkg builds unprivileged on purpose, so this escalates privilege mid-build; the exact mechanism reported in the openconnect-sso-anchored AUR wave (Jul/Aug 2026)
>>> file PKGBUILD line 7: references a .onion address - legitimate PKGBUILDs don't hardcode Tor hidden-service addresses; matches the Tor-backed second-stage delivery reused across the June 2026 and Jul/Aug 2026 AUR campaigns
>>> … 13 more findings …
>>> Read full file: ./scaner-test/PKGBUILD
>>> Read full file: ./scaner-test/scaner-test-therandtxt.install

>>> 'scaner-test''s cloned PKGBUILD/.install content (which differs from what was pre-scanned) matches known-suspicious patterns. Review it yourself before proceeding:
    ./scaner-test
>>> Continue anyway? [y/N] n
>>> Aborted.
Not a hard block
Findings are reported with file/line and a cgit link. You get Continue anyway? [y/N] — the decision stays with you.

Audit only

emerge --scan neovim-git --aur
emerge --install-pkgbuild ~/src/my-pkg --scan

--scan reports findings without building or installing anything. It needs at least one package name (or --install-pkgbuild <PATH> for a local checkout) and does not support --abs yet.

The scanner is a blocklist, so a clean result is not a guarantee. That is what the sandbox is for.

bwrap sandbox

The scanner is a blocklist: a PKGBUILD it misses would still run arbitrary shell as your user. The sandbox is the second layer. pkgver/prepare/build/check/package run inside bubblewrap (/usr/bin/bwrap) when it is installed.

What the jail looks like

  • Filesystem: the whole root is mounted read-only; /proc and /dev are fresh; /tmp is an empty tmpfs.
  • Writable: only the build directory. Configured PKGDEST/SRCDEST/SRCPKGDEST/BUILDDIR outside it get their own writable bind and matching env var.
  • No real home / session: empty tmpfs over /home and /run — no SSH keys, secret GPG, browser profile, session D-Bus or agents. Environment is cleared to an allowlist.
  • Isolation: --unshare-all, --new-session, --die-with-parent, capabilities dropped; PKGBUILD and *.install re-bound read-only.
  • GnuPG: public-only keyring copy, mounted read-only (signatures verify; no private keys, build cannot plant a key).

Network

Shared by default. With --unshare-net-build the download phase keeps the network (the declared source=() entries), while build()/check()/package() get none — so a stray cargo build reaching crates.io fails loudly. Loopback stays up for tools that need it; there is still no route outside.

Toolchain quirks handled for you

  • rustup: RUSTUP_HOME is pointed back at the real path so cargo still resolves a toolchain. CARGO_HOME is not restored (it may hold credentials.toml) — a fresh writable directory inside the build dir is used instead, and dependencies are re-fetched.
  • fakeroot: package() runs under fakeroot, which fails with “cannot preserve ownership” in a user namespace with no uid 0. A small fakeroot shim re-runs the real one in a nested uid-0-mapped bwrap layer. The shim lives in /var/tmp, read-only inside the jail, so build() cannot replace it, and it is deleted afterwards.
Outside the sandbox
Dependency installation and the final pacman -U need real root and never execute PKGBUILD code, so they run outside the jail. The finished *.pkg.tar.* is still audited first (setuid, .INSTALL, alpm hooks, systemd, sudoers, …).
Known gap
A different PKGDEST/SRCDEST set in /etc/makepkg.conf (visible inside the jail) overrides the injected value. Rare in practice.
FlagEffect
--no-sandboxPlain makepkg (with a warning)
--unshare-net-buildNo network during build()/check()/package()

Without bubblewrap installed, builds fall back to plain makepkg.

PKGBUILD review

--pkgbuild-view shows the PKGBUILD that is about to be built and asks before the build starts. It works for AUR, ABS and --install-pkgbuild, but only for packages you requested directly — never for transitive dependencies or batch paths. It runs after --edit.

emerge neovim-git --aur --pkgbuild-view
emerge --install-pkgbuild ~/src/my-pkg --pkgbuild-view

What you see

  • First time: the full PKGBUILD.
  • Next time: a unified diff against the copy shown last time (PKGBUILD (previous) → PKGBUILD (current)), or “unchanged since last shown”.
  • The last-shown copies live in ~/.cache/aura-emerge/pkgbuild-view/<pkgbase>.PKGBUILD (under $XDG_CACHE_HOME if it is set). They exist only to make diffs possible and play no security role — the scanner does its own comparison of what it fetched against what was cloned.

The prompts

  1. Continue with this build? [Y/n] — Enter builds.
  2. On n: Open it in $EDITOR instead of skipping it? [y/N]. Answering no skips this package.
  3. On y the PKGBUILD opens in $EDITOR (then $VISUAL, then nano). Save and close to continue building; .SRCINFO is regenerated from your edit, unless you pass --skip-srcinfo-regen.

If the PKGBUILD cannot be read, you get a warning and the review is skipped for that package. The scanner and the sandbox still apply as usual.

--install-pkgbuild <PATH> builds a local checkout through the same scanner + sandbox pipeline. It is recorded in world as Err/ unless -1 is given.

Note: --scan does not support --abs yet. For ABS, use --pkgbuild-view during a normal install.

Devel upstream check

The version on an AUR page for -git/-hg/-svn/-bzr packages often lags the real upstream, so a plain version comparison never sees new commits. --devel (with -u) and --check-devel (report only, no sudo needed) ask the upstream directly.

emerge -u --devel
emerge --check-devel

How it works

  • Only installed foreign packages (AUR/local) whose name ends in -git, -hg, -svn or -bzr are considered.
  • For -git packages the first git+ URL in source=() is taken (with #branch= if present) and git ls-remote asks the remote for its current commit — no clone.
  • -hg/-svn/-bzr are recognized but not checked yet; they appear in the “could not determine” note.

The first run only records a baseline

The last upstream commit seen for each package is kept in ~/.cache/aura-emerge/devel.state. A package checked for the first time is recorded but never counted as moved, so the first --check-devel normally reports nothing. Later runs compare against that baseline.

Result

  • Packages whose upstream moved are listed as U entries. With -u --devel they join the upgrade as devel (upstream moved); packages already upgraded by version are not checked twice.
  • “Can't tell” is never treated as “out of date”: a missing git+ source, a failed fetch or a non-git VCS lands in the “could not determine” note.
  • --exclude and package.mask hold a package back at its installed version.

--revdep-rebuild

Finds installed binaries whose shared-library dependencies no longer resolve, and fixes them. After an icu/openssl/boost soname bump a package can satisfy every declared dependency while its binaries link against a .so that no longer exists. This is different from @preserved-rebuild, which only checks declared dependencies via pacman -T. Gentoo hides the problem behind preserved-libs; here it is “rebuild once you notice”, automated.

emerge --revdep-rebuild
emerge --revdep-rebuild -p

What is scanned

  • ELF files owned by packages under /usr/bin, /usr/lib, /usr/lib32, /usr/libexec, /usr/local/lib and /opt (huge files are skipped).
  • Their DT_NEEDED entries, with RPATH/RUNPATH ($ORIGIN expanded), checked against the linker's search directories — the built-ins plus /etc/ld.so.conf and its includes.
  • The report groups findings by package: the missing sonames and the first few affected files. Broken files that no package owns are listed separately.

What gets fixed

  • AUR/local packages are rebuilt through the normal sandboxed path, and the scanner runs first.
  • Official packages: the package that ships the lost soname is looked up in the file database (pacman -F) and, if it is not installed, installed with pacman -S --needed --asdeps.
  • If nothing in the file database provides a soname, you are told to run emerge --regen in case the database is stale, or to check whether the library was dropped upstream.
  • If the wanted libraries are already installed, the note points at a possible mixed 32/64-bit case.

With -p it only reports. Otherwise it asks Rebuild/install the package(s) above? [y/N]. --exclude and package.mask apply, and --keep-going is respected. The exit code is non-zero if anything failed.

Known limits
A library of the wrong architecture at the right path counts as present. Plugins loaded with dlopen() are invisible to an ELF scan. Files replaced outside pacman are judged by what is on disk now.
Aura
fosskers/aura? No — after v2.1, Aura is no longer part of this project. Aura-Emerge is a separate, security-first reimplementation.