From cfeb338478bb67defce2fb48222a6be3cffc4263 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sat, 9 May 2026 20:14:28 +0200 Subject: refactor(core): remove hardcoded PATH reset PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure against PATH injection. For a script invoked manually in the user's own shell the benefit is marginal: if an attacker controls the user's PATH they already have larger problems. The cost is real — tools installed outside these three directories (Homebrew, Nix, ~/.local/bin) silently fail, and the documented workaround of prepending a path at invocation time does not work because the script overwrites PATH immediately on startup. Remove the PATH reset and all associated documentation. The remaining hardening measures (unalias -a, hash -r, strict set -o flags, umask) are retained. --- README.md | 8 -------- transcode.sh | 8 -------- transcode.sh.1 | 22 ---------------------- 3 files changed, 38 deletions(-) diff --git a/README.md b/README.md index a01de23..09ee1d3 100644 --- a/README.md +++ b/README.md @@ -59,14 +59,6 @@ install -Dm644 transcode.sh.bash-completion \ ~/.local/share/bash-completion/completions/transcode.sh ``` -> **PATH note:** the script resets `PATH` to `/bin:/usr/bin:/usr/local/bin` -> for security. If your `ffmpeg` lives elsewhere (e.g. Homebrew on macOS, -> Nix), prepend its directory: -> -> ```sh -> PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4 -> ``` - ## Configuration ### Presets diff --git a/transcode.sh b/transcode.sh index 9125627..807495d 100755 --- a/transcode.sh +++ b/transcode.sh @@ -84,14 +84,6 @@ fi # Unalias everything to avoid unexpected alias expansion command unalias -a -# Set a predictable and secure PATH (ignores user-controlled paths). -# Trade-off: tools installed outside these directories (e.g. ffmpeg via -# Homebrew on macOS at /opt/homebrew/bin, or via Nix at /nix/store/...) -# will not be found. In that case, invoke this script via a wrapper that -# prepends the correct path, e.g.: PATH="/opt/homebrew/bin:$PATH" ./transcode.sh -PATH='/bin:/usr/bin:/usr/local/bin' -export PATH - # Clear the shell command hash table to avoid stale command lookups hash -r diff --git a/transcode.sh.1 b/transcode.sh.1 index 92cefa2..edeaae8 100644 --- a/transcode.sh.1 +++ b/transcode.sh.1 @@ -399,28 +399,6 @@ Load an alternative configuration file: transcode.sh \-\-config\-file ~/profiles/fast.toml input.mp4 .fi .RE -.PP -Use -.BR ffmpeg (1) -installed via Homebrew (macOS): -.PP -.RS -.nf -PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4 -.fi -.RE -.SH NOTES -The script resets -.B PATH -to -.I /bin:/usr/bin:/usr/local/bin -for security. If -.BR ffmpeg (1) -is installed outside these directories (e.g. via Homebrew or Nix), -prepend the correct directory to -.B PATH -before invoking -.BR transcode.sh . .SH SEE ALSO .BR ffmpeg (1), .BR ffprobe (1), -- cgit v1.3.1