The tilde in your PATH may not be your HOME(disconnect3d.pl) |
The tilde in your PATH may not be your HOME(disconnect3d.pl) |
Have I run into this at some point?
I certainly have.
Have I learned to quote better and only where appropriate from it?
I certainly have.
Bourne compatible shells take a while to learn and require some experience. This won't change, but alternatives exist, with their own caveats.
GENERAL RULE
1. Double-quote dollar sign expressions, and nothing else.
foo
"$bar"/foo
baz:"$(cat example.txt)"
exec cmd "$@"
2. Single-quote words with a special character, and nothing else. 'Die Hard'
'ke$ha'
---I should point out that the author's example is NOT fixed by different quoting though.
# original
export PATH="$PATH:~/.local/bin/"
# without unnecessary quotes
export PATH="$PATH":~/.local/bin/
Because tilde expansion happens at the beginning of the word.If you are using shell scripting (And prefer Bash etc over Python), you would keep using Bash/Fish/Zsh etc. If you are using the CLI to launch applications that don't have a GUI, navigate directories and perform file system operations, then you would use the plain terminal.
I'm not sure why this can't be done. Security people will have a million reasons, I guess it's possible one of them might be valid.
It sounds like you could make it yourself in ~10 lines of Python or bash. I don't see it catching on, though.
Another Bash-ism I need to be careful not to use when trying to be portable.
It is worth noting that on a lot of systems /bin/sh isn't bash (or zsh) so if you want to rely on Bashisms (or just can't be bothered looking for them) be specific and use “#!/bin/bash” for you hashbang. On Debian and similar it is usually dash for instance.
That was a scary mistake to unwind!
Tilde expands when at the beginning of an unquoted word.
Pretty straightforward.
~ or ~/ --> $HOME
~user --> user's home
---Bash has a few extra.
~+ --> $PWD
~- --> $OLDPWD
~+N or ~-N --> dirsscriptPath=$(/usr/bin/realpath "${BASH_SOURCE[0]}")
localPath=$(/usr/bin/dirname "$scriptPath" )
/usr/bin/echo "localPath = '$localPath'"
sudo ln -s /usr/bin/bash /usr/bin/footgun
export PATH="$PATH:$HOME/.local/bin/"
better: export PATH="$HOME/.local/bin/:$PATH"Also, if something can write into your path, it can probably write to your shell config and/or the environment variables.
I've always seen home dir, homebrew, etc prepending to PATH.
And allowing any letters from any language is probably worth the hassle.
The (classical) Latin alphabet can be fully described by the English alphabet.
Using ' and " to pretend to be ‘/’ or “/” is on par with the typewriter days where people would use the l key to stand in for 1 also. A justifiable approximation when technology limitations prevented using the real deal, but an approximation all the same.
Want to quote a command line that may already contain double quotes, in order to pass it as an argument to some other program? No, you don't. It isn't right to want that.