diff options
| author | Dennis Fink | 2026-05-09 20:14:28 +0200 |
|---|---|---|
| committer | Dennis Fink | 2026-05-09 20:14:28 +0200 |
| commit | cfeb338478bb67defce2fb48222a6be3cffc4263 (patch) | |
| tree | aa8fa74eef56e00bcb3b01c125460d10e1d88e80 /transcode.sh.1 | |
| parent | 7f7341a84176beb4516a6801e16e2eb36557c2c8 (diff) | |
| download | transcode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.tar.gz transcode.sh-cfeb338478bb67defce2fb48222a6be3cffc4263.zip | |
refactor(core): remove hardcoded PATH reset
PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure
against PATH injection. For a script invoked manually in the user's own
shell the benefit is marginal: if an attacker controls the user's PATH
they already have larger problems. The cost is real — tools installed
outside these three directories (Homebrew, Nix, ~/.local/bin) silently
fail, and the documented workaround of prepending a path at invocation
time does not work because the script overwrites PATH immediately on
startup.
Remove the PATH reset and all associated documentation. The remaining
hardening measures (unalias -a, hash -r, strict set -o flags, umask) are
retained.
Diffstat (limited to '')
| -rw-r--r-- | transcode.sh.1 | 22 |
1 files changed, 0 insertions, 22 deletions
diff --git a/transcode.sh.1 b/transcode.sh.1 index 92cefa2..edeaae8 100644 --- a/transcode.sh.1 +++ b/transcode.sh.1 @@ -399,28 +399,6 @@ Load an alternative configuration file: transcode.sh \-\-config\-file ~/profiles/fast.toml input.mp4 .fi .RE -.PP -Use -.BR ffmpeg (1) -installed via Homebrew (macOS): -.PP -.RS -.nf -PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4 -.fi -.RE -.SH NOTES -The script resets -.B PATH -to -.I /bin:/usr/bin:/usr/local/bin -for security. If -.BR ffmpeg (1) -is installed outside these directories (e.g. via Homebrew or Nix), -prepend the correct directory to -.B PATH -before invoking -.BR transcode.sh . .SH SEE ALSO .BR ffmpeg (1), .BR ffprobe (1), |
