logoalt Hacker News

Backslasher • today at 1:56 PM • 5 replies • view on HN

Afaik it's habit to give system paths precedence so a malicious script can't shadow e.g. sudo and steal your password, escalating a local file write into root


Replies

toast0 • today at 2:10 PM

Otoh, if you don't put your local path first, you can't override system binaries that you want to override.

Also, if something can write into your path, it can probably write to your shell config and/or the environment variables.

➕ show 2 replies
3eb7988a1663 • today at 7:38 PM

All sorts of utilities push themselves to the front of path: uv, mise, asdf, python virtual environments, nix shell, etc.

It is a theoretically nice ideal that fails immediately when you want project specific overrides.

➕ show 1 reply
paulddraper • today at 2:06 PM

AFAIK it's habit to allow your scripts to override system ones, so you can customize behavior.

I've always seen home dir, homebrew, etc prepending to PATH.

marcosdumay • today at 3:53 PM

That's important only for the people that add relative names (like '.') to their path.

Most people know better.

gjvc • today at 3:38 PM

by that time it's too late and should have been prevented appearing on the host much earlier