Don't Put Tilde In Your Path
I was experimenting with the nono sandboxing tool and received a warning message: PATH entries the sandbox can write to include ~/.local/bin/. This raised suspicions. Essentially, adding this to your ~/.bashrc or ~/.zshrc file will not replace the tilde (~) with the home directory path (or $HOME), as the tilde is only expanded in unquoted inputs.
According to the bash documentation, when a word starts with an unquoted tilde character, all characters until the first unquoted slash are treated as a tilde-prefix. Bash checks for tilde-prefixes in variable assignments following a colon (:) or equals sign (=) immediately. Consequently, if we were to add /home/user/.local/bin/ to the PATH, we would end up with ./~/.local/bin/ instead.
Importantly, the unquoted version of export PATH=$PATH:~/.local/bin does function correctly in Bash and Zsh, as tilde expansion is executed within variable assignments after = and after each colon (:). However, relying on this method can be unreliable, as a single whitespace would disrupt the variable assignment. As demonstrated, the kek binary was executed from ./~/.local/bin/, indicating that the home directory was never involved.
To verify if you have this issue, you can run a quick check by executing a command that prints any PATH entries containing a tilde. If anything is printed, it is advisable to fix your .bashrc/.zshrc/.profile file by replacing the tilde with $HOME. The nono tool deserves commendation for raising awareness about this issue, although the warning could be more detailed (PR incoming).
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.