Why is PATH restricted to /sbin:/usr/sbin:/bin:/usr/bin (no /usr/local/bin) in uwsgi in Debian?

I am writing an uwsgi app that uses subprocess to call an executable installed in /usr/local/bin.

This directory is in www-data's PATH and www-data can launch the command, which can be verified with e.g. those commands:

sudo -u www-data mycommand
sudo -u www-data which mycommand
sudo -u www-data printenv PATH

But it fails in my uwgsi app because /usr/local/bin is not in the PATH.

My investigation led me to /etc/init.d/uwsgi, which reads

# PATH should only include /usr/* if it runs after the mountnfs.sh script
PATH=/sbin:/usr/sbin:/bin:/usr/bin

Things work if I add /usr/local/bin to the PATH in the wsgi file:

os.environ["PATH"] = f"/usr/local/bin:{os.environ['PATH']}"

I could also hardcode the absolute file path in my app, or even make it a configuration parameter.

But I'd like to understand first why the PATH is restricted in the init file.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论