Arch Linux pacaur¶
Warning
pacaur is unmaintained. The original pacaur repository is archived (last commit 2018) and the E5ten fork has had no commits since 2021; migrate to paru or yay.
- ID
pacaur- Home page
- Version requirement
>= 4
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:alpm·pkg:pacaur- CLI name
pacaur- Every call
pacaur --noconfirm --color never <command>- Issues and PRs
- Source
AUR helper wrapping pacman, driven through the pacaur binary.
Inherits every operation, parser and forced argument from Pacman; only
the binary and version probe differ. Routing through pacaur is what lets
--query --upgrades report AUR updates on top of the official repositories.
Unlike pacman, the helper must run as the regular user: it aborts under
root (you cannot perform this operation as root) because makepkg
refuses to build as root, and it invokes sudo pacman itself for the
privileged steps. mpm therefore never wraps it in sudo.
What mpm adds to pacaur¶
Through mpm, pacaur gains:
a one-command
cleanup --orphansthat removes every orphaned dependency at once--extendedsearch, to match against package descriptions
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover pacaur alongside pacman, paru, yay and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your pacaur commands, in mpm¶
You already know pacaur: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
extended search backfilled by |
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
Selecting and configuring pacaur¶
Deselect pacaur for a single run with --no-pacaur, or persist the choice in your configuration:
[mpm]
pacaur = false
The arguments and environment variables listed in the box atop this page are forced on every pacaur call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Keep it enabled but tune how mpm drives it with a per-manager override:
[mpm.managers.pacaur]
timeout = 900
mpm config-template pacaur prints every overridable attribute as a ready-to-paste block.
Recipes¶
A few jobs you would otherwise script around pacaur, one mpm command each:
Snapshot and clone a machine:
mpm --pacaur dump pacaur.toml, thenmpm restore pacaur.tomlon the next one.Export a compliance SBOM:
mpm --pacaur sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --pacaur doctorrelays Arch Linux pacaur’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
Arch Linux pacaur runs sudo from inside its own commands: mpm never wraps it, keeps an already-warm credential cache alive for those internal escalations, and warns when a mutating call goes silent on a terminal with a cold cache, since a password prompt may be hiding in the stream.
See privilege escalation for the full policy.
Cooldown¶
State of Arch Linux pacaur’s release-age gating, from the cooldown support table:
Status: ❌ None (Arch AUR helper)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: AUR
Retraction: None at the version level: an AUR package is a git repository with no per-version artifact to withdraw, so remediation is a maintainer push or deletion of the whole package
Publish date: ✅ server-set
LastModified, the push timestampmpm’syayoverlay gates on. Git commit dates are client-set (GIT_COMMITTER_DATE), forgeable, and never consulted
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --allow-unsupported-managers opts back in.
Version probe¶
The version is probed by running:
$ pacaur --version
pacaur 4.8.6
and extracted with:
r"pacaur\s+(?P<version>\S+)"
Changelog¶
7.4.0(2026-07-25)The AUR helpers are no longer wrapped in
sudo: they refuse or break under root (makepkgrejects root builds, paru aborts AUR transactions, pacaur aborts its sync operations) and escalate through their own internalsudo pacmancalls, whichmpmnow tracks with theinternal_sudomarker (warm credential-cache keepalive, hidden-prompt watchdog). This also lets yay’s cooldown environment overlay reach the process, where thesudowrap used to strip it.
6.2.0(2026-03-25)Add
--color neveroption to all invocations.
5.9.0(2022-11-20)Implement
pacaursupport. Closes #816.