git-gui: pass redirections as separate argument to git_read

We are going to treat command arguments and redirections differently to avoid passing arguments that look like redirections to the command accidentally. To do so, it will be necessary to know which arguments are intentional redirections. Rewrite direct call sites of git_read to pass intentional redirections as a second (optional) argument. git_read defers to safe_open_command, but we cannot make it safe, yet, because one of the callers of git_read is proc git, which does not yet know which of its arguments are redirections. This is the topic of the next commit. Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed May 4, 2025 at 15:39 UTC 60b0ba0a04c413b716dc33f83285ede26e820668
5 files changed +9 -10
git-gui.sh
+3 -3
@@ -642,11 +642,11 @@ proc safe_open_command {cmd {redir {}}} {
642 return $fd
643 }
644
645 -proc git_read {cmd} {
645 +proc git_read {cmd {redir {}}} {
646 set cmdp [_git_cmd [lindex $cmd 0]]
647 set cmd [lrange $cmd 1 end]
648
649 - return [safe_open_command [concat $cmdp $cmd]]
649 + return [safe_open_command [concat $cmdp $cmd] $redir]
650 }
651
652 proc git_read_nice {cmd} {
@@ -669,7 +669,7 @@ proc git_write {cmd} {
669 }
670
671 proc githook_read {hook_name args} {
672 - git_read [concat [list hook run --ignore-missing $hook_name --] $args 2>@1]
672 + git_read [concat [list hook run --ignore-missing $hook_name --] $args] [list 2>@1]
673 }
674
675 proc kill_file_process {fd} {
lib/checkout_op.tcl
+2 -2
@@ -352,8 +352,8 @@ method _readtree {} {
352 --exclude-per-directory=.gitignore \
353 $HEAD \
354 $new_hash \
355 - 2>@1 \
356 - ]]
355 + ] \
356 + [list 2>@1]]
357 fconfigure $fd -blocking 0 -translation binary
358 fileevent $fd readable [cb _readtree_wait $fd $status_bar_operation]
359 }
lib/choose_repository.tcl
+2 -2
@@ -959,8 +959,8 @@ method _do_clone_checkout {HEAD} {
959 -v \
960 HEAD \
961 HEAD \
962 - 2>@1 \
963 - ]]
962 + ] \
963 + [list 2>@1]]
964 fconfigure $fd -blocking 0 -translation binary
965 fileevent $fd readable [cb _readtree_wait $fd]
966 }
lib/console.tcl
+1 -2
@@ -92,8 +92,7 @@ method _init {} {
92
93 method exec {cmd {after {}}} {
94 if {[lindex $cmd 0] eq {git}} {
95 - lappend cmd 2>@1
96 - set fd_f [git_read [lrange $cmd 1 end]]
95 + set fd_f [git_read [lrange $cmd 1 end] [list 2>@1]]
96 } else {
97 set fd_f [safe_open_command $cmd [list 2>@1]]
98 }
lib/merge.tcl
+1 -1
@@ -239,7 +239,7 @@ Continue with resetting the current changes?"]
239 }
240
241 if {[ask_popup $op_question] eq {yes}} {
242 - set fd [git_read [list read-tree --reset -u -v HEAD 2>@1]]
242 + set fd [git_read [list read-tree --reset -u -v HEAD] [list 2>@1]]
243 fconfigure $fd -blocking 0 -translation binary
244 set status_bar_operation [$::main_status \
245 start \