gitk: sanitize 'exec' arguments: redirect to process

Convert one 'exec' call that sends output to a process (pipeline). Fortunately, the command does not contain any variables. For this reason, just treat it as a "redirection". Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed Mar 29, 2025 at 17:35 UTC 30846b43060c3d57575b59b9aaa80c4bd1688171
1 file changed +2 -2
gitk
+2 -2
@@ -43,7 +43,7 @@ proc safe_exec {cmd} {
43 # executes one command with redirections
44 # no pipelines are possible
45 # cmd is a list that specifies the command and its arguments
46 -# redir is a list that specifies redirections (output, background)
46 +# redir is a list that specifies redirections (output, background, constant(!) commands)
47 # calls `exec` and returns its value
48 proc safe_exec_redirect {cmd redir} {
49 eval exec [make_arglist_safe $cmd] $redir
@@ -9120,7 +9120,7 @@ proc getpatchid {id} {
9120 if {![info exists patchids($id)]} {
9121 set cmd [diffcmd [list $id] {-p --root}]
9122 if {[catch {
9123 - set x [eval exec $cmd | git patch-id]
9123 + set x [safe_exec_redirect $cmd [list | git patch-id]]
9124 set patchids($id) [lindex $x 0]
9125 }]} {
9126 set patchids($id) "error"