More Things I Wish I’d Known About Bash
zwischenzugs.com
zwischenzugs.com
$ NEWFILE=/tmp/newfile_${RANDOM}
$ touch $NEWFILE
The problem is that any user on the box can create files under /tmp. An attacker can set up a bunch of symlinks like /tmp/newfile_1, ..., /tmp/newfile_99999 pointing to a file owned by your user. When your script then writes into this temporary file, you'll write through the symlink and clobber one of your own files. Especially dangerous if root :)This has been a historic source of software vulnerabilities (often with the PID used instead as the guessable component instead of random, though). One recommended alternative is to use the `mktemp` command instead.
It's in portuguese and I'm not sure if there's an official translation, yet it's easy enough to decipher if you know bash, and Google Translate will do a pretty decent job.
I gift you "Aurelio's Swiss Army Knife of the Bash Shell" - http://aurelio.net/shell/canivete/
That said, that guide doesn't seem to have the tricks from the top article, at least 1-4.
I'll drop this: http://tldp.org/LDP/abs/html/ If anyone, who has to do anything BASH related, has not seen it then they should!
[1]: http://aurelio.net/projects/sedarkanoid/
read -t 5 foo || foo='No reply'
Setting $TMOUT affects all following 'read' commands. Also, setting $TMOUT in an interactive shell sets a timeout for a response to the primary prompt, terminating the shell if the user doesn't respond in time. If the redirection operator is <<-, then all leading
tab characters are stripped from input lines and
the line containing delimiter. This allows here-
documents within shell scripts to be indented in a
natural fashion. cat <<‘EOF’
This will not be ${expanded}
EOF echo $(((RANDOM << 15) + RANDOM))$RANDOM is not cryptographically secure.
UP CTRL-A RIGHT RIGHT e
Which needs less thinking and 6 keystrokes instead of 8.
- Safe-by-default parameter expansion: no word splitting unless you ask for it, even if you don't quote the expansion.
- Ability to use histoy expansions (like !!:gs/foo/bar) on parameter expansions, meaning "${foo:A:h}" is equivalent to "$(dirname $(realpath $foo))"
- Much better array support, including both integer-indexed and associative arrays
- A built-in CLI option parser that's pretty robust ("zparseopts")
- Lazy-loaded functions
- Floating-point arithmetic
Whereas if I stick with bash, I can run my scripts almost everywhere and almost every server I ssh into has a familiar environment. Thus my knowledge of edge cases and scripting idioms from bash pay dividends.
For situations where I need better arrays, associative arrays, floating point arithmetic, I'm probably better off writing it in an actual scripting language.
In the past I've actually downloaded Zsh, compiled it from source, and ran it out of ~/.local/bin with absolutely no issues. But that's not something I'd advise.
One could also use <c-p>,<c-a> and <c-f> to achieve the same result much quicker.
Of course, if you are an emacs user, more power to you with the emacs bindings.
${RANDOM}${RANDOM}
A preferred way would be od -vAn -N4 -tu4 < /dev/urandom
/dev/urandom gives you random bytes, od dumps them in different formats (e.g: hex, octal, decimal and such).This takes 4 random bytes and outputs them as a 4 byte unsigned int.
-v: Don't suppress duplicate lines. (It doesn't make a difference here, because there's always only one line.)
-An: Don't write input offsets.
-N4: Read at most 4 bytes.
-tu4: Print 4-byte unsigned integers.
You can also use pushd -n (where n is a number, although I usually end up needing trial and error to get the right one) to rotate the list of dirs without removing any from the stack - useful if the list has more than 2 directories, or 2+ directories you need to switch between repeatedly.
pushd and popd also work out of the box in Windows command prompt, although you don't get "dirs" or any fancier options like in bash, just push and pop on a plain old stack.
^x^y^
Is that third caret necessary? I've never had to include it. Although that may be zsh taking a shortcut on bash syntax.FWIW, the bug (yes, it's a bug that the Open Group has decided is not a bug, but it really cannot be anything other than a bug!) is this: non-zero exits by commands/functions are ignored when invoked by functions invoked in a conditional expression context.