gitk: sanitize 'open' arguments: simple commands with redirections

As in the previous commits, introduce a function that sanitizes arguments intended for the process and in addition allows to pass redirections, which are passed to Tcl's 'open' verbatim. Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed Mar 20, 2025 at 20:00 UTC 42a64b41a7a3d01a62f0f34f75bee2bbd00be46f
1 file changed +13 -5
gitk
+13 -5
@@ -66,6 +66,15 @@ proc safe_open_command {cmd} {
66 open |[make_arglist_safe $cmd] r
67 }
68
69 +# opens a command pipeline for reading with redirections
70 +# cmd is a list that specifies the command and its arguments
71 +# redir is a list that specifies redirections
72 +# calls `open` and returns the file id
73 +proc safe_open_command_redirect {cmd redir} {
74 + set cmd [make_arglist_safe $cmd]
75 + open |[concat $cmd $redir] r
76 +}
77 +
78 # End exec/open wrappers
79
80 proc hasworktree {} {
@@ -9906,8 +9915,8 @@ proc resethead {} {
9915 bind $w <Visibility> "grab $w; focus $w"
9916 tkwait window $w
9917 if {!$confirm_ok} return
9909 - if {[catch {set fd [open \
9910 - [list | git reset --$resettype $rowmenuid 2>@1] r]} err]} {
9918 + if {[catch {set fd [safe_open_command_redirect \
9919 + [list git reset --$resettype $rowmenuid] [list 2>@1]]} err]} {
9920 error_popup $err
9921 } else {
9922 dohidelocalchanges
@@ -9978,7 +9987,7 @@ proc cobranch {} {
9987
9988 # check the tree is clean first??
9989 set newhead $headmenuhead
9981 - set command [list | git checkout]
9990 + set command [list git checkout]
9991 if {[string match "remotes/*" $newhead]} {
9992 set remote $newhead
9993 set newhead [string range $newhead [expr [string last / $newhead] + 1] end]
@@ -9992,12 +10001,11 @@ proc cobranch {} {
10001 } else {
10002 lappend command $newhead
10003 }
9995 - lappend command 2>@1
10004 nowbusy checkout [mc "Checking out"]
10005 update
10006 dohidelocalchanges
10007 if {[catch {
10000 - set fd [open $command r]
10008 + set fd [safe_open_command_redirect $command [list 2>@1]]
10009 } err]} {
10010 notbusy checkout
10011 error_popup $err