{
  "id": 13716374,
  "title": "Don't Put Tilde In Your Path",
  "url": "https://urgent.news/2026/10/11/dont-put-tilde-in-your-path",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T12:13:13.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://disconnect3d.pl//2026/10/02/dont-put-tilde-in-your-path/"
  },
  "original_language": "en",
  "account": "I was experimenting with the nono sandboxing tool and received a warning message: PATH entries the sandbox can write to include ~/.local/bin/. This raised suspicions. Essentially, adding this to your ~/.bashrc or ~/.zshrc file will not replace the tilde (~) with the home directory path (or $HOME), as the tilde is only expanded in unquoted inputs. According to the bash documentation, when a word starts with an unquoted tilde character, all characters until the first unquoted slash are treated as a tilde-prefix. Bash checks for tilde-prefixes in variable assignments following a colon (:) or equals sign (=) immediately. Consequently, if we were to add /home/user/.local/bin/ to the PATH, we would end up with ./~/.local/bin/ instead. Importantly, the unquoted version of export PATH=$PATH:~/.local/bin does function correctly in Bash and Zsh, as tilde expansion is executed within variable assignments after = and after each colon (:). However, relying on this method can be unreliable, as a single whitespace would disrupt the variable assignment. As demonstrated, the kek binary was executed from ./~/.local/bin/, indicating that the home directory was never involved. To verify if you have this issue, you can run a quick check by executing a command that prints any PATH entries containing a tilde. If anything is printed, it is advisable to fix your .bashrc/.zshrc/.profile file by replacing the tilde with $HOME. The nono tool deserves commendation for raising awareness about this issue, although the warning could be more detailed (PR incoming).",
  "summary": null,
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}