You are not logged in.

#1 2020-08-16 18:48:06

fisch02
Member
Registered: 2020-08-16
Posts: 2

Libretro hacked, backup of cloned repos/downloads from buildbot needed

Hi there,

libretros buildbot and github organization have been hacked a few hours ago.
Details about it can be found over on the Libretro blog.
In short, an attacker gained access to the buildbot server and github organization and deleted many repos by force-pushing a blank commit to them, as well as basically wiped the buildbot server.

If you happen to have cloned any of the affected repos or have copies of files from buildbot, keep these and get in contact with them.
This includes users of packages, who have build them from source using the PKGBUILDs, but have not removed the build directory (Some aur helpers like yay also keep the build directory).
Hopefully some maintainers also have kept a local copy of the affected repos.

For Archlinux this unfortunately means, that any package from the Archlinux repos or the AUR, that uses affected repos, can currently not be build.

Offline

#2 2020-08-16 23:26:35

eschwartz
Fellow
Registered: 2014-08-08
Posts: 4,097

Re: Libretro hacked, backup of cloned repos/downloads from buildbot needed

What about forks?

On our build server dragon.archlinux.org I see these clones, but haven't checked precisely how up to date they are. I believe alucryd builds all/most official repository packages for the libretro ecosystem on dragon, using git cloned sources, so it should be trending towards up to date. Is there a list of currently affected repos which libretro is looking for restoration info? The github repo listing is not stable and I didn't check each one.

$ ls -d *Retro* *retro*
libretro-beetle-pce/         libretro-bsnes/      libretro-dolphin/          libretro-mgba/              libretro-ppsspp/         libretro-snes9x/
libretro-beetle-pce-fast/    libretro-bsnes2014/  libretro-flycast/          libretro-mupen64plus-next/  libretro-redream/        libretro-yabause/
libretro-beetle-psx/         libretro-citra/      libretro-gambatte/         libretro-overlays/          libretro-retrodream/     RetroArch/
libretro-beetle-supergrafx/  libretro-core-info/  libretro-genesis-plus-gx/  libretro-parallel-n64/      libretro-sameboy/        retroarch-assets/
libretro-blastem/            libretro-desmume/    libretro-melonds/          libretro-play/              libretro-shaders-slang/

Last edited by eschwartz (2020-08-16 23:26:53)


Managing AUR repos The Right Way -- aurpublish (now a standalone tool)

Offline

#3 2020-08-17 16:06:44

fisch02
Member
Registered: 2020-08-16
Posts: 2

Re: Libretro hacked, backup of cloned repos/downloads from buildbot needed

I do not have a list of affected repos, but libretro was already able to restore more than half of the affected repos with the help of contributers, who have kept local copies of the repos.
If anything is still missing, I will write here, however buildbot is still not restored.

Offline

Board footer

Powered by FluxBB