From cfeb338478bb67defce2fb48222a6be3cffc4263 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sat, 9 May 2026 20:14:28 +0200 Subject: refactor(core): remove hardcoded PATH reset PATH='/bin:/usr/bin:/usr/local/bin' was intended as a security measure against PATH injection. For a script invoked manually in the user's own shell the benefit is marginal: if an attacker controls the user's PATH they already have larger problems. The cost is real — tools installed outside these three directories (Homebrew, Nix, ~/.local/bin) silently fail, and the documented workaround of prepending a path at invocation time does not work because the script overwrites PATH immediately on startup. Remove the PATH reset and all associated documentation. The remaining hardening measures (unalias -a, hash -r, strict set -o flags, umask) are retained. --- transcode.sh.1 | 22 ---------------------- 1 file changed, 22 deletions(-) (limited to 'transcode.sh.1') diff --git a/transcode.sh.1 b/transcode.sh.1 index 92cefa2..edeaae8 100644 --- a/transcode.sh.1 +++ b/transcode.sh.1 @@ -399,28 +399,6 @@ Load an alternative configuration file: transcode.sh \-\-config\-file ~/profiles/fast.toml input.mp4 .fi .RE -.PP -Use -.BR ffmpeg (1) -installed via Homebrew (macOS): -.PP -.RS -.nf -PATH="/opt/homebrew/bin:$PATH" transcode.sh input.mp4 -.fi -.RE -.SH NOTES -The script resets -.B PATH -to -.I /bin:/usr/bin:/usr/local/bin -for security. If -.BR ffmpeg (1) -is installed outside these directories (e.g. via Homebrew or Nix), -prepend the correct directory to -.B PATH -before invoking -.BR transcode.sh . .SH SEE ALSO .BR ffmpeg (1), .BR ffprobe (1), -- cgit v1.3.1