Don't Put Tilde In Your Path

(disconnect3d.pl)

54 points | by arusekk 2 hours ago

8 comments

  • amarshall 35 minutes ago
    Or you can just…not quote the tilde. Folks always seem to reflexively quote “strings” in Bash while not realizing that (almost) everything is a string and most strings are not quoted and it would be odd to do it (e.g. no one is doing `"ls" "-a" "foo"`).
    • dylan604 15 minutes ago
      Unless you're running a shell command from python. That was the first time I saw a command string broken down into "string" arguments for every thing like that.
      • thwarted 10 minutes ago
        In that case, you're not running a "shell command" from python, you're passing arguments to exec. A shell command would be a string interpreted by the shell, and you'd use that for shell syntax things like having the shell do variable interpolation or redirections as part of executing the command.
    • paulddraper 2 minutes ago
      People quote both too often and too little.

      GENERAL RULE

      1. Double-quote dollar sign expressions, and nothing else.

        foo
      
        "$bar"/foo
      
        baz:"$(cat example.txt)"
      
        exec cmd "$@"
      
      2. Single-quote words with a special character, and nothing else.

        'Die Hard'
      
        'ke$ha'
      
      ---

      I should point out that the author's example is NOT fixed by different quoting though.

        # original
        export PATH="$PATH:~/.local/bin/"
      
        # without unnecessary quotes
        export PATH="$PATH":~/.local/bin/
      
      Because tilde expansion happens at the beginning of the word.
    • vips7L 13 minutes ago
      Or just stop using bash. It’s a terrible language to write and has tons of footguns.
    • cr125rider 19 minutes ago
      The trick is to quote explicitly and correctly. “ and ‘ are different.
      • dylan604 15 minutes ago
        why would you use smart quotes in a terminal like that?
        • tom_ 2 minutes ago
          They probably fell foul of some browser text box auto-correct.
        • airstrike 4 minutes ago
          [delayed]
  • duncangh 2 minutes ago
    I should have read the docs before getting ~/ tattooed on my wrist.
  • FeepingCreature 48 minutes ago
    Kind of seems like you should have noticed this by your ~/.local/bin PATH not working?
  • very_good_man 15 minutes ago
    Reminds me of early days of Cursor when it decided it would be a good idea to create a directory named "~" in my repo root!

    That was a scary mistake to unwind!

  • IshKebab 1 hour ago
    Bash footgun #238503.
    • Joel_Mckay 7 minutes ago
      There is a workaround =3

      sudo ln -s /usr/bin/bash /usr/bin/footgun

    • paulddraper 10 minutes ago
      That's standard POSIX.

      Tilde expands when at the beginning of an unquoted word.

      Pretty straightforward.

        ~ or ~/ --> $HOME
      
        ~user --> user's home
      
      ---

      Bash has a few extra.

        ~+ --> $PWD
      
        ~- --> $OLDPWD
      
        ~+N or ~-N --> dirs
    • _ZeD_ 59 minutes ago
      well.. it's in zsh (and probably any other *sh) too
      • vbernat 34 minutes ago
        In Zsh, you can set PATH with path=(~/.local/bin $path). There, it works as shell expansion works.
        • kccqzy 16 minutes ago
          In fish, you can just do `fish_add_path ~/.local/bin`. Adding a directory to your PATH is so common that there’s a function to do it. And it takes effect immediately in all running instances of the shell.
  • gjvc 46 minutes ago
    bad example in the article:

      export PATH="$PATH:$HOME/.local/bin/"
    
    better:

      export PATH="$HOME/.local/bin/:$PATH"
    • Backslasher 25 minutes ago
      Afaik it's habit to give system paths precedence so a malicious script can't shadow e.g. sudo and steal your password, escalating a local file write into root
      • toast0 12 minutes ago
        Otoh, if you don't put your local path first, you can't override system binaries that you want to override.

        Also, if something can write into your path, it can probably write to your shell config and/or the environment variables.

      • paulddraper 15 minutes ago
        AFAIK it's habit to allow your scripts to override system ones, so you can customize behavior.

        I've always seen home dir, homebrew, etc prepending to PATH.

  • hnd9q09qk4 58 minutes ago
    [flagged]
  • mr_mitm 39 minutes ago
    So many headaches could be avoided if we only allowed `[A-Za-z0-9._-]` in paths. (Arguably, even `-` can be problematic.) Encoding issues, expansion, parameter separation, ... and I never saw a convincing case in favor of supporting anything else.
    • dylan604 12 minutes ago
      I always joked about setting a custom keyboard layout to replace the space char with the underscore char specifically for avoiding spaces in file paths.
    • jetbalsa 36 minutes ago
      What about people who do not speak English? or even use Latin letters?
      • mr_mitm 16 minutes ago
        The language I grew up with does use non latin letters, I can manage. Then again, it's only four of them, so I get your point ... but I can dream, can't I?
      • ThunderSizzle 33 minutes ago
        What Latin letter(s) are you referring to?

        The (classical) Latin alphabet can be fully described by the English alphabet.

        • toast0 15 minutes ago
          What about people who do not ((speak English?) or (even use Latin letters?))
        • cowboylowrez 29 minutes ago
          unicode names spit