The tilde in your PATH is probably not your HOME


I used to be taking part in with the nono agent sandboxing software and it greeted me with a warning: PATH entries the sandbox can write to: ~/.native/bin/ which appeared suspicious.

In different phrases, doing this in your ~/.bashrc or ~/.zshrc:

export PATH="$PATH:~/.native/bin/"

won’t develop the ~ (tilde) into the house path (or $HOME) because the tilde to residence enlargement occurs solely in unquoted inputs, as additionally the bash documentation says:

If a phrase begins with an unquoted tilde character (‘~’), all the characters as much as the primary unquoted slash (…) are thought-about a tilde-prefix. (…)

Bash checks every variable project for unquoted tilde-prefixes instantly following a ‘:’ or the primary ‘=’, and performs tilde enlargement in these instances. (…)

So as a substitute of getting /residence//.native/bin/ added to PATH we find yourself with ./~/.native/bin/ added to PATH.

And to repair this, we will do that:

export PATH="$PATH:$HOME/.native/bin/"

Note that the unquoted model export PATH=$PATH:~/.native/bin really works in Bash and Zsh, as a result of tilde enlargement can also be carried out in variable assignments after = and after every :. But counting on that’s fragile as for instance, a whitespace will break the variable project.

The drawback will also be seen right here:

$ ls -la
whole 0
drwxr-xr-x@   2 dc  workers    64 Oct  2 13:37 .
drwxr-x---+ 105 dc  workers  3360 Oct  2 13:37 ..
$ mkdir -p ./~/.native/bin/
$ printf '#embody nint primary() { places("whats up"); }'>a.c; gcc a.c -o ./~/.native/bin/kek
$ PATH="~/.native/bin/" kek
whats up
$ tree -f
.
├── ./~
│   └── ./~/.native
│       └── ./~/.native/bin
│           └── ./~/.native/bin/kek
└── ./a.c

4 directories, 2 information

Demo showing that a literal tilde in PATH resolves to a ./~/ directory in the current working directory

As we will see, the kek binary was discovered and executed from ./~/.native/bin/ — the house listing was by no means concerned.

Check your PATH

You can shortly examine whether or not you’ve this drawback with:

$ echo "$PATH" | grep -- '~'

or, to see every entry by itself line:

$ echo "$PATH" | tr ':' 'n' | grep '~'
~/.native/bin/

If it prints something, go repair your .bashrc/.zshrc/.profile and change the ~ with $HOME :).

Btw, kudos to the nono software for warning about this – despite the fact that the warning might be extra verbose (PR incoming).



Source link