The Sovereign Foundation has invested €562,000 in modernizing the package management in Arch Linux.

The developers of the Arch Linux distribution have announced receiving an investment of 562,000 euros from the STF (Sovereign Tech Fund), established in Germany to stimulate the development of open digital infrastructure and open-source ecosystems. The fund was created with resources provided by the German Ministry of Economics and Climate Protection and is overseen by the Federal Agency for Disruptive Innovations SPRIND. The funds are allocated for modernizing the ALPM (Arch Linux Package Management) toolbox, which develops specifications, utilities, and libraries for tasks such as creating and using packages, as well as managing repositories.

As part of the project, an attempt is being made to structure the interfaces related to package management and provide utilities and wrappers written in the Rust programming language. The specifications and utilities developed by the project are based on the functionality of Pacman. The transition to Rust after using C in Pacman is explained by the reduced likelihood of memory-related errors. The initiative aims to integrate support for all repository management and package creation/check/install capabilities into ALPM, as well as provide functionality that can replace some features of the Pacman package manager.

The allocated funds are planned to be used to finance the work of 4 developers on the ALPM project on a part-time basis over 15 months. Work started in October and will continue until the end of 2025. Among the tasks planned to be addressed during this work, the following are mentioned:

  • Creating formal specifications for the data formats used in packages. Currently, Arch Linux packages use undocumented or poorly documented types of files and metadata. Information about the low-level structure of packages is intended to be generalized in the form of versioned specifications that clearly regulate all types of permissible files and metadata.
  • Implementing a simplified artifact verification mechanism for package artifacts based on digital signatures, utilizing OpenPGP but not relying on the old centralized key repository of GnuPG.
  • Providing a Rust library for creating, verifying, and installing individual packages that meet the requirements of formal specifications explicitly defining the acceptable content of packages and the methods for their creation and processing.
  • Providing a Rust library for managing packages in the system (handling the state of the set of packages that comprise the system). To ensure compatibility with older applications using the libalpm library (e.g., used in pacman), a wrapper with C-API is planned.
  • Preparing a supporting PGPKI (Web of Trust) and distribution-agnostic OpenPGP stack for verifying distribution artifacts. Alternatives in Rust are planned to be used instead of GnuPG.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster