Don't Put Tilde In Your Path

Hacker News by 2 min read 29x views
Don't Put Tilde In Your Path

Share Post

I was playing alongside the nono delegate sandboxing tool and it greeted me alongside a warning: PATH entries the sandbox can compose to: ~/.local/bin/ which looked suspicious.

nono alert concerning PATH entries the sandbox can compose to

In another words, doing this in your ~/.bashrc or ~/.zshrc:

export PATH="$PATH:~/.local/bin/" 

will not develop the ~ (tilde) into the residence way (or $HOME) as the tilde to residence enlargement happens lone in unquoted inputs, as additionally the bash records says:

If a term starts alongside an unquoted tilde character (‘~’), all of the characters up to the archetypal unquoted slash (…) are considered a tilde-prefix. (…)

Bash checks all changeable project for unquoted tilde-prefixes immediately following a ‘:’ or the archetypal ‘=’, and performs tilde enlargement in these cases. (…)

So alternatively of having /home/<user>/.local/bin/ added to PATH we end up alongside ./~/.local/bin/ added to PATH.

And to fix this, we can do this:

export PATH="$PATH:$HOME/.local/bin/" 

Note that the unquoted type export PATH=$PATH:~/.local/bin really plant in Bash and Zsh, since tilde enlargement is additionally performed in changeable assignments following = and following all :. But relying on that is susceptible as for example, a whitespace volition interrupt the changeable assignment.

The issue can additionally be seen here:

$ ls -la total 0 drwxr-xr-x@ 2 dc personnel 64 Oct 2 13:37 . drwxr-x---+ 105 dc personnel 3360 Oct 2 13:37 .. $ mkdir -p ./~/.local/bin/ $ printf '#include <stdio.h>\nint main() { puts("hello"); }'>a.c; gcc a.c -o ./~/.local/bin/kek $ PATH="~/.local/bin/" kek hello $ tree -f . ├── ./~ │ └── ./~/.local │ └── ./~/.local/bin │ └── ./~/.local/bin/kek └── ./a.c 4 directories, 2 files 

Demo showing that a literal tilde in PATH resolves to a ./~/ directory in the current operating directory

As we can see, the kek binary was established and executed from ./~/.local/bin/ — the residence directory was never involved.

Check your PATH

You can quickly inspect whether you have this issue with:

$ echo "$PATH" | grep -- '~' 

or, to see all admission on its own line:

$ echo "$PATH" | tr ':' '\n' | grep '~' ~/.local/bin/ 

If it prints anything, go fix your .bashrc/.zshrc/.profile and substitute the ~ alongside $HOME :).

Btw, kudos to the nono tool for alert concerning this - equal although the alert could be additional verbose (PR incoming).

Other Article Hacker News
↑
Close Right Ads
Close Left Ads