aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDennis Fink2026-05-09 20:14:28 +0200
committerDennis Fink2026-05-09 20:14:28 +0200
commitcfeb338478bb67defce2fb48222a6be3cffc4263 (patch)
treeaa8fa74eef56e00bcb3b01c125460d10e1d88e80
parent7f7341a84176beb4516a6801e16e2eb36557c2c8 (diff)
downloadtranscode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.tar.gz
transcode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.zip
refactor(core): remove hardcoded PATH reset
PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure against PATH injection. For a script invoked manually in the user's own shell the benefit is marginal: if an attacker controls the user's PATH they already have larger problems. The cost is real — tools installed outside these three directories (Homebrew, Nix, ~/.local/bin) silently fail, and the documented workaround of prepending a path at invocation time does not work because the script overwrites PATH immediately on startup. Remove the PATH reset and all associated documentation. The remaining hardening measures (unalias -a, hash -r, strict set -o flags, umask) are retained.
-rw-r--r--README.md8
-rwxr-xr-xtranscode.sh8
-rw-r--r--transcode.sh.122
3 files changed, 0 insertions, 38 deletions
diff --git a/README.md b/README.md
index a01de23..09ee1d3 100644
--- a/README.md
+++ b/README.md
@@ -59,14 +59,6 @@ install -Dm644 transcode.sh.bash-completion \
~/.local/share/bash-completion/completions/transcode.sh
```
-> **PATH note:** the script resets `PATH` to `/bin:/usr/bin:/usr/local/bin`
-> for security. If your `ffmpeg` lives elsewhere (e.g. Homebrew on macOS,
-> Nix), prepend its directory:
->
-> ```sh
-> PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4
-> ```
-
## Configuration
### Presets
diff --git a/transcode.sh b/transcode.sh
index 9125627..807495d 100755
--- a/transcode.sh
+++ b/transcode.sh
@@ -84,14 +84,6 @@ fi
# Unalias everything to avoid unexpected alias expansion
command unalias -a
-# Set a predictable and secure PATH (ignores user-controlled paths).
-# Trade-off: tools installed outside these directories (e.g. ffmpeg via
-# Homebrew on macOS at /opt/homebrew/bin, or via Nix at /nix/store/...)
-# will not be found. In that case, invoke this script via a wrapper that
-# prepends the correct path, e.g.: PATH="/opt/homebrew/bin:$PATH" ./transcode.sh
-PATH='/bin:/usr/bin:/usr/local/bin'
-export PATH
-
# Clear the shell command hash table to avoid stale command lookups
hash -r
diff --git a/transcode.sh.1 b/transcode.sh.1
index 92cefa2..edeaae8 100644
--- a/transcode.sh.1
+++ b/transcode.sh.1
@@ -399,28 +399,6 @@ Load an alternative configuration file:
transcode.sh \-\-config\-file ~/profiles/fast.toml input.mp4
.fi
.RE
-.PP
-Use
-.BR ffmpeg (1)
-installed via Homebrew (macOS):
-.PP
-.RS
-.nf
-PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4
-.fi
-.RE
-.SH NOTES
-The script resets
-.B PATH
-to
-.I /bin:/usr/bin:/usr/local/bin
-for security. If
-.BR ffmpeg (1)
-is installed outside these directories (e.g. via Homebrew or Nix),
-prepend the correct directory to
-.B PATH
-before invoking
-.BR transcode.sh .
.SH SEE ALSO
.BR ffmpeg (1),
.BR ffprobe (1),