Aura-Emerge
AuraEmerge
GitHub Install
Arch · Portage-style · Security-first

Aura-Emerge

Gentoo-style emerge for Arch — packages from official repos, the AUR, and ABS. PKGBUILDs get scanned for supply-chain tricks; untrusted build steps run inside a bwrap sandbox.

Features

Everything you install lands in a world file — install once, keep track forever. Official packages go through pacman; AUR and ABS are built by emerge itself.

Core

Gentoo-style workflow

@world, custom sets, --tree, --exclude, --keep-going, merge log — Portage habits that still work on Arch.

Security

PKGBUILD scanner

Before every AUR build: AST + heuristics for curl|sh, interpreter -e/-c (python/perl/ruby/node/lua), paste sites, known IOCs, and more. You still choose whether to continue.

Sandbox

bwrap sandbox

Untrusted phases under bubblewrap — no real $HOME//run, cleared env, public GPG only, then archive audit before pacman -U.

Sources

Repos · AUR · ABS

Official packages through pacman, AUR via git + RPC, ABS via pkgctl — same scanner and sandbox for all three.

Mask

package.mask

A permanent “never install” list — even as a transitive AUR dependency. Separate from one-shot --exclude.

Maintenance

Revdep & devel

--revdep-rebuild finds broken library links; --devel rebuilds -git packages when upstream moves on.

Quick start

Not installed yet? See the installation guide.

  1. Install a package — repos first, AUR if needed:
    emerge neovim
  2. Force AUR, review the PKGBUILD, confirm before the build:
    emerge neovim-git --aur --pkgbuild-view -a
  3. Full system upgrade (repos + AUR):
    emerge -u @world
  4. Bring the machine in line with your world file:
    emerge @world

World & sets

Path: /etc/portage/world. Every explicitly installed package is recorded automatically and removed on unmerge. Editable by hand - one atom per line, optional repo prefix:

extra/firefox
aur/ayugram-desktop-bin
core/nano
abs/nano-custom

Two meanings of @world

  • emerge @world (no -u) — provision: install whatever world lists that is not already on the system.
  • emerge -u / emerge -u @world — upgrade: upgrade everything already installed. Does not read world.
  • emerge --sync — database refresh only.

Custom sets

Files under /etc/portage/sets/<name>.set are invoked as @<name>:

# /etc/portage/sets/game-kit.set
steam
lutris
gamemode
aur/protonup-qt

emerge @game-kit @dev-tools neovim
emerge --list-sets

make.conf

/etc/portage/make.conf (and ~/.config/emerge/make.conf) is aura-emerge's own config — default flags plus build-env overrides applied via a generated makepkg.conf.

# EMERGE_DEFAULT_OPTS spliced into every run
EMERGE_DEFAULT_OPTS="--pkgbuild-view --unshare-net-build"

CFLAGS="-march=native -O2 -pipe"
CXXFLAGS="$CFLAGS"
RUSTFLAGS="-C target-cpu=native"
MAKEFLAGS="-j$(nproc)"
OPTIONS=(strip docs !debug lto)
BUILDENV=(!distcc color check !sign)

Use --ignore-default-opts for a single run without the defaults. emerge --info shows what was loaded and the effective expanded values.

Usage highlights

Command What it does
emerge pkg Repos first, AUR if the package is not there
emerge pkg --aur AUR only, with AUR deps resolved recursively
emerge pkg --abs Build from ABS inside the sandbox
emerge -apt pkg --aur Ask, pretend, show the dependency tree
emerge -u --devel Upgrade, and rebuild -git packages whose upstream moved
emerge --scan pkg --aur Scan the PKGBUILD only — no build
emerge --revdep-rebuild Find binaries with broken library links and fix them
emerge --news Arch Linux news
emerge -c / -C pkg Depclean / unmerge

Full flag list: Flags page, emerge --help, or the generated emerge(1) man page.

Security: PKGBUILD scanner

Before every AUR install, the raw PKGBUILD (and any .install hook) is fetched from cgit and scanned in two layers:

  1. AST (tree-sitter-bash) — curl|sh, base64/xxd pipes, process substitution, eval "$(curl …)", sudo/pkexec/doas, python/perl/ruby/node/lua inline-exec, top-level command substitution, and more.
  2. Line heuristics — chmod 777, raw IPs, foreign package managers, paste sites, .onion, anti-sandbox probes, known campaign IOCs.

Built *.pkg.tar.* files are audited before pacman -U (setuid, .INSTALL, alpm hooks, systemd, sudoers, …).

Not a hard block
Findings are reported with file/line and a cgit link. You get Continue anyway? [y/N] — the decision stays with you.
emerge --scan neovim-git --aur
emerge --install-pkgbuild ~/src/my-pkg --scan

bwrap sandbox

AUR and ABS builds run pkgver / prepare / build / check / package inside a bubblewrap namespace when bubblewrap is installed:

  • tmpfs over /home and /run — no real home, no session bus/agents
  • Cleared environment; public-only GPG; PKGBUILD/*.install read-only
  • Writes only in the build dir; network optional via --unshare-net-build
  • Fakeroot shim under /var/tmp; archive audit before pacman -U

Dependency install and final pacman -U stay outside the sandbox — they do not execute PKGBUILD-authored code.

emerge pkg --aur --unshare-net-build   # no net during build()
emerge pkg --aur --no-sandbox          # plain makepkg (with warning)

package.mask

/etc/portage/package.mask (file or directory of files) — packages this machine never installs, even as a transitive dependency:

ayugram-desktop-bin            # any source
aur/*-bin                      # never AUR -bin packages
*-git                          # no devel packages on this box
extra/nano                     # specific repo/name

A masked package hard-stops the request. Use --exclude for a one-run skip instead.