gitk: sanitize 'open' arguments: simple commands, readable and writable

As in the previous commits, introduce a function that sanitizes arguments and also keeps the returned file handle writable to pass data to stdin. Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed Mar 21, 2025 at 23:34 UTC 2aeb4484a046a545fb540ba07397b25b13fe6881
1 file changed +9 -2
gitk
+9 -2
@@ -66,6 +66,13 @@ proc safe_open_command {cmd} {
66 open |[make_arglist_safe $cmd] r
67 }
68
69 +# opens a command pipeline for reading and writing
70 +# cmd is a list that specifies the command and its arguments
71 +# calls `open` and returns the file id
72 +proc safe_open_command_rw {cmd} {
73 + open |[make_arglist_safe $cmd] r+
74 +}
75 +
76 # opens a command pipeline for reading with redirections
77 # cmd is a list that specifies the command and its arguments
78 # redir is a list that specifies redirections
@@ -4897,8 +4904,8 @@ proc do_file_hl {serial} {
4904 # must be "containing:", i.e. we're searching commit info
4905 return
4906 }
4900 - set cmd [concat | git diff-tree -r -s --stdin $gdtargs]
4901 - set filehighlight [open $cmd r+]
4907 + set cmd [concat git diff-tree -r -s --stdin $gdtargs]
4908 + set filehighlight [safe_open_command_rw $cmd]
4909 fconfigure $filehighlight -blocking 0
4910 filerun $filehighlight readfhighlight
4911 set fhl_list {}