Everyone using manjaro could stop complaining and just try to use the appimage which should work fine for you... Link:
Search Criteria
Package Details: librewolf-bin 133.0.3-1
Package Actions
Git Clone URL: | https://aur.archlinux.org/librewolf-bin.git (read-only, click to copy) |
---|---|
Package Base: | librewolf-bin |
Description: | Community-maintained fork of Firefox, focused on privacy, security and freedom. |
Upstream URL: | https://librewolf-community.gitlab.io/ |
Keywords: | browser web |
Licenses: | GPL, MPL, LGPL |
Conflicts: | librewolf |
Provides: | librewolf |
Submitter: | lsf |
Maintainer: | lsf |
Last Packager: | lsf |
Votes: | 407 |
Popularity: | 10.84 |
First Submitted: | 2019-06-16 13:12 (UTC) |
Last Updated: | 2024-12-15 09:43 (UTC) |
Dependencies (16)
- dbus (dbus-gitAUR, dbus-selinuxAUR)
- ffmpeg (ffmpeg-nvcodec-11-1-gitAUR, ffmpeg-amd-full-gitAUR, ffmpeg-cudaAUR, ffmpeg-full-gitAUR, ffmpeg-gitAUR, ffmpeg-fullAUR, ffmpeg-decklinkAUR, ffmpeg-headlessAUR, ffmpeg-amd-fullAUR, ffmpeg-libfdk_aacAUR, ffmpeg-obsAUR, ffmpeg-ffplayoutAUR)
- gtk3 (gtk3-no_deadkeys_underlineAUR, gtk3-classicAUR, gtk3-classic-xfceAUR, gtk3-patched-filechooser-icon-viewAUR)
- libpulse (pulseaudio-dummyAUR, libpulse-gitAUR)
- libxt
- mime-types (mailcap)
- nss (nss-hgAUR)
- startup-notification
- ttf-font (neuropol-ttfAUR, ttf-win7-fontsAUR, ttf-ms-win8AUR, ttf-ms-win8-arabicAUR, ttf-ms-win8-hebrewAUR, ttf-ms-win8-seaAUR, ttf-ms-win8-indicAUR, ttf-ms-win8-japaneseAUR, ttf-ms-win8-koreanAUR, ttf-ms-win8-zh_cnAUR, ttf-ms-win8-zh_twAUR, ttf-ms-win8-thaiAUR, ttf-ms-win8-otherAUR, ttf-kidsAUR, ttf-liberation-sans-narrowAUR, ttf-cavafy-scriptAUR, ttf-ms-fontsAUR, ttf-dejavu-ibAUR, ttf-zeldaAUR, ttf-oxygenAUR, ttf-oxygen-gfAUR, ttf-share-gfAUR, ttf-gostAUR, otf-inconsolata-dzAUR, ttf-d2codingAUR, ttf-agaveAUR, ttf-caracteresAUR, ttf-cuprumAUR, ttf-autour-oneAUR, ttf-impallari-milongaAUR, ttf-impallari-miltonianAUR, ttf-clarity-cityAUR, ttf-ms-win10AUR, ttf-ms-win10-japaneseAUR, ttf-ms-win10-koreanAUR, ttf-ms-win10-seaAUR, ttf-ms-win10-thaiAUR, ttf-ms-win10-zh_cnAUR, ttf-ms-win10-zh_twAUR, ttf-ms-win10-otherAUR, ttf-win10AUR, ttf-bmonoAUR, ttf-pt-astra-factAUR, ttf-weblysleekuiAUR, ttf-pt-astra-sansAUR, ttf-pt-astra-serifAUR, ttf-pt-sansAUR, ttf-pt-serifAUR, ttf-pt-monoAUR, ttf-pt-root_uiAUR, ttf-xo-fontsAUR, ttf-paratypeAUR, ttf-plemoljp-binAUR, ttf-dejavu-emojilessAUR, noto-fonts-variable-liteAUR, ttf-lucida-fontsAUR, ttf-plemoljpAUR, ttf-juiseeAUR, ttf-ms-win10-autoAUR, ttf-karlaAUR, noto-fonts-latin-greek-cyrillicAUR, apple-fontsAUR, ttf-ms-win11-autoAUR, ttf-ms-win10-cdnAUR, noto-fonts-liteAUR, ttf-noto-sans-vfAUR, ttf-noto-serif-vfAUR, ttf-noto-sans-mono-vfAUR, ttf-ibm-plex-sans-scAUR, ttf-ms-win11AUR, ttf-ms-win11-japaneseAUR, ttf-ms-win11-koreanAUR, ttf-ms-win11-seaAUR, ttf-ms-win11-thaiAUR, ttf-ms-win11-zh_cnAUR, ttf-ms-win11-zh_twAUR, ttf-ms-win11-otherAUR, gnu-free-fonts, noto-fonts, ttf-bitstream-vera, ttf-croscore, ttf-dejavu, ttf-droid, ttf-ibm-plex, ttf-input, ttf-input-nerd, ttf-liberation)
- git (git-gitAUR, git-glAUR) (make)
- hunspell-en_US (hunspell-en_us) (optional) – Spell checking, American English
- libnotify (libnotify-gitAUR) (optional) – Notification integration
- networkmanager (networkmanager-gitAUR, networkmanager-iwdAUR) (optional) – Location detection via available WiFi networks
- pulseaudio (pulseaudio-dummyAUR, pulseaudio-gitAUR) (optional) – Audio support
- speech-dispatcher (speech-dispatcher-gitAUR) (optional) – Text-to-Speech
- xdg-desktop-portal (xdg-desktop-portal-gitAUR) (optional) – Screensharing with Wayland
Required by (28)
- edge-frfox (requires librewolf) (optional)
- ff2mpv-go-git (requires librewolf) (optional)
- ff2mpv-rust (requires librewolf) (optional)
- firefox-gnome-theme (requires librewolf) (optional)
- librewolf-comment-out-cfg-hook (requires librewolf)
- librewolf-extension-bitwarden-bin (requires librewolf)
- librewolf-extension-bitwarden-git (requires librewolf) (optional)
- librewolf-extension-darkreader (requires librewolf)
- librewolf-extension-darkreader-bin (requires librewolf)
- librewolf-extension-gnome-shell-integration (requires librewolf)
- librewolf-extension-istilldontcareaboutcookies-bin (requires librewolf)
- librewolf-extension-kagisearch-bin (requires librewolf)
- librewolf-extension-localcdn-bin (requires librewolf)
- librewolf-extension-plasma-integration (requires librewolf)
- librewolf-extension-return-youtube-dislike-bin (requires librewolf)
- librewolf-extension-tridactyl-bin (requires librewolf)
- librewolf-extension-ublock-origin-bin (requires librewolf)
- librewolf-extension-uget-integration-bin (requires librewolf)
- librewolf-extension-vimiumc-bin (requires librewolf)
- librewolf-extension-xdman8-browser-monitor-bin (requires librewolf)
- Show 8 more...
Sources (7)
- default192x192.png
- git+https://gitlab.com/librewolf-community/browser/source.git#tag=133.0.3-1
- https://gitlab.com/api/v4/projects/44042130/packages/generic/librewolf/133.0.3-1/librewolf-133.0.3-1-linux-arm64-package.tar.bz2
- https://gitlab.com/api/v4/projects/44042130/packages/generic/librewolf/133.0.3-1/librewolf-133.0.3-1-linux-arm64-package.tar.bz2.sig
- https://gitlab.com/api/v4/projects/44042130/packages/generic/librewolf/133.0.3-1/librewolf-133.0.3-1-linux-x86_64-package.tar.bz2
- https://gitlab.com/api/v4/projects/44042130/packages/generic/librewolf/133.0.3-1/librewolf-133.0.3-1-linux-x86_64-package.tar.bz2.sig
- librewolf.desktop
Latest Comments
« First ‹ Previous 1 2 3 4 5 6 7 8 .. 19 Next › Last »
spsf64 commented on 2024-04-26 17:08 (UTC)
ron2138 commented on 2024-04-26 16:47 (UTC) (edited on 2024-04-26 16:47 (UTC) by ron2138)
Manjaro site shows
- pacman April 26, 2024: stable has 6.0.2-18, testing has 6.1.0-7, unstable has 6.1.0-7
- pacman-contrib April 26, 2024: stable has 1.10.4-1, testing has 1.10.5-1, unstable has 1.10.5-1
As stated earlier I, ron2138, use pacman 6.0.2-9 and pacman-contrib 1.10.4-3. Current versions in arch stable are 6.1.0-3, and 1.10.5-1, respectively. For arch stable, pacman 6.1.0-3 is 6.0.2-9 successor. While pacman-contrib had 1.10.4-4 in between 1.10.4-3 and 1.10.5-1.
muvvenby commented on 2024-04-26 08:36 (UTC)
FWIW I have this issue with the failing validity check on Manjaro stable install with pamac and yay. I could check later with my EndeavourOS install.
ron2138 commented on 2024-04-26 00:53 (UTC) (edited on 2024-04-26 16:33 (UTC) by ron2138)
With the suggested SKIP checksum, I get:
$ makepkg --verifysource --force
==> Making package: librewolf-bin 125.0.2-1 (Fri 26 Apr 2024 12:23:23 AM UTC)
==> Retrieving sources...
-> Updating source git repo...
-> Found default192x192.png
-> Found librewolf.desktop
-> Found librewolf-125.0.2-1-linux-x86_64-package.tar.bz2
-> Found librewolf-125.0.2-1-linux-x86_64-package.tar.bz2.sig
==> Validating source files with sha256sums...
source ... Skipped
default192x192.png ... Passed
librewolf.desktop ... Passed
==> Validating source_x86_64 files with sha256sums...
librewolf-125.0.2-1-linux-x86_64-package.tar.bz2 ... Passed
librewolf-125.0.2-1-linux-x86_64-package.tar.bz2.sig ... Skipped
==> Verifying source file signatures with gpg...
librewolf-125.0.2-1-linux-x86_64-package.tar.bz2 ... Passed
(The reason for --force
is because I already built the package. makepkg
is not willing to run without it.)
I think it does validate the source after the SKIP at sha256sums
is evaluated.
==> Validating source_x86_64 files with sha256sums...
librewolf-125.0.2-1-linux-x86_64-package.tar.bz2 ... Passed
librewolf-125.0.2-1-linux-x86_64-package.tar.bz2.sig ... Skipped
I haven't looked what was in the PKGBUILD in previous versions. The current problem could be related to the source
, source_aarch64
, source_x86_64
, sha256sums
, sha256sums_x86_64
, and sha256sums_aarch64
arrays. And the way makepkg
verifies the sums. I agree this is what is being called hands waiving rather then a concise explanation. But, since there is a source_x86_64
verification, I have not tried harder.
I have this issue, and I am not on Manjaro. As lsf suggested at 2024-04-25 19:51 (UTC), I deliberately keep pacman/pacman-contrib versions behind. I have other issues with the up to date versions, which is why I have downgraded. Waiting to see if those issues get resolved in their next versions. On the other hand, even though I am hardly building AUR packages, this is the 1st time I run into such an issue. Could it be the very few other AUR packages I built lately have issues I am not aware of?
lsf commented on 2024-04-25 19:51 (UTC) (edited on 2024-04-25 19:58 (UTC) by lsf)
*she.
more to the point though: while it still builds/verifies cleanly for me, it doesn't make sense to have a checksum on a folder / git checkout. I didn't manually add it, I usually just trust updpkgsums
to do its job. For some reason though, it insists on adding a checksum… for the git checkout's folder this time.
So skipping the verification for that checkout would be a reasonable approach for now. I'll still try to find out why it's in there this time around at all, and then see about updating the PKGBUILD ^^
(sorry for the trouble this seems to have caused!)
/edit: just in case: are those folks who have that issue on manjaro? maybe it's just part of the newer(ish) pacman/pacman-contrib versions, seems like manjaro is a bit behind there still?
Rollingthunder commented on 2024-04-25 19:33 (UTC)
I get the same error ron2138 so guess it's the same for all of us but (If I understand it correctly) skipping the verification is not a fix, it's a bypass at most and not a particularly convincing one, cause why would I wanna have potential errors or even malicious code in a browser source? Especially since he seems to have removed the SKIP command from a previous version, thus probably wanting to improve it. It seems to me the sha256 used in the pkgbuild is just wrong as the one I get from the source.tar.gz.sha256sum on Codeberg¹ is not found in it, but ² instead.
¹ aafe820d94a535728bc4d247a120f3ceed2d6df49b044c60b231009ab06a1f27
² 84513d4d5387f09231bb2f426596f24897babfc77c8e502001650531e375f9f9
Now is that an argument against unsigned sha256sums or just a human error?
ron2138 commented on 2024-04-25 15:49 (UTC) (edited on 2024-04-25 19:08 (UTC) by ron2138)
I get the following after previously downloading librewolf-125.0.2-1-linux-x86_64-package.tar.bz2*
. Could be the same issue as Exod1us reported at 2024-04-24 18:22 (UTC).
$ ls --size librewolf-125*
94648 librewolf-125.0.2-1-linux-x86_64-package.tar.bz2
4 librewolf-125.0.2-1-linux-x86_64-package.tar.bz2.sig
$ makepkg --verifysource
==> Making package: librewolf-bin 125.0.2-1 (Thu 25 Apr 2024 03:28:11 PM UTC)
==> Retrieving sources...
-> Updating source git repo...
-> Found default192x192.png
-> Found librewolf.desktop
-> Found librewolf-125.0.2-1-linux-x86_64-package.tar.bz2
-> Found librewolf-125.0.2-1-linux-x86_64-package.tar.bz2.sig
==> Validating source files with sha256sums...
source ... NOT FOUND
default192x192.png ... Passed
librewolf.desktop ... Passed
==> ERROR: One or more files did not pass the validity check!
That particular ERROR solved by issuing
$ sed -i "/sha256sums=(/s:'.*:'SKIP':" PKGBUILD
before makepkg --verifysource
. I hope it will also solves Exod1us issue reported at 2024-04-24 18:22 (UTC), if he will issue that sed
command right after he obtained the PKGBUILD
file. But have not verified this last statement.
Exod1us commented on 2024-04-24 18:22 (UTC)
Whith the last update he can't get the source. Error when update
Derson5 commented on 2024-04-22 13:15 (UTC)
There was new release https://codeberg.org/librewolf/source/releases/tag/125.0.1-1
aljustiet commented on 2024-04-13 12:23 (UTC)
ignxcy: Same question
Pinned Comments
lsf commented on 2021-11-10 12:14 (UTC) (edited on 2023-04-17 07:18 (UTC) by lsf)
https://wiki.archlinux.org/title/Arch_User_Repository#Acquire_a_PGP_public_key_if_needed
gpg --keyserver hkp://keyserver.ubuntu.com --search-keys 031F7104E932F7BD7416E7F6D2845E1305D6E801
/edit: starting with 112.0-1, the binaries are signed with the maintainers shared key, so
gpg --keyserver hkp://keyserver.ubuntu.com --search-keys 662E3CDD6FE329002D0CA5BB40339DD82B12EF16
should do the trick instead. I've also signed the key with the previously used key, so you have at least some guarantee that it's not a malicious attack :)