gitk: sanitize 'open' arguments: command pipeline

As in the earlier commits, introduce a function that constructs a pipeline of commands after sanitizing the arguments. Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed Mar 23, 2025 at 22:45 UTC 026c397d911cde55924d7eb1311d0fd6e2e105d5
1 file changed +15 -4
gitk
+15 -4
@@ -82,6 +82,17 @@ proc safe_open_command_redirect {cmd redir} {
82 open |[concat $cmd $redir] r
83 }
84
85 +# opens a pipeline with several commands for reading
86 +# cmds is a list of lists, each of which specifies a command and its arguments
87 +# calls `open` and returns the file id
88 +proc safe_open_pipeline {cmds} {
89 + set cmd {}
90 + foreach subcmd $cmds {
91 + set cmd [concat $cmd | [make_arglist_safe $subcmd]]
92 + }
93 + open $cmd r
94 +}
95 +
96 # End exec/open wrappers
97
98 proc hasworktree {} {
@@ -3970,14 +3981,14 @@ proc show_line_source {} {
3981 set blamefile [file join $cdup $flist_menu_file]
3982 if {$from_index ne {}} {
3983 set blameargs [list \
3973 - | git cat-file blob $from_index \
3974 - | git blame -p -L$line,+1 --contents - -- $blamefile]
3984 + [list git cat-file blob $from_index] \
3985 + [list git blame -p -L$line,+1 --contents - -- $blamefile]]
3986 } else {
3987 set blameargs [list \
3977 - | git blame -p -L$line,+1 $id -- $blamefile]
3988 + [list git blame -p -L$line,+1 $id -- $blamefile]]
3989 }
3990 if {[catch {
3980 - set f [open $blameargs r]
3991 + set f [safe_open_pipeline $blameargs]
3992 } err]} {
3993 error_popup [mc "Couldn't start git blame: %s" $err]
3994 return