gitk: sanitize 'exec' arguments: redirections and background

Convert 'exec' calls that both redirect output to a file and run the process in the background. 'safe_exec_redirect' can take both these "redirections" in the second argument simultaneously. Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Johannes Sixt committed Mar 29, 2025 at 17:21 UTC 7a0493edda08fc0d8ee6d5489a50530c768646a1
1 file changed +2 -3
gitk
+2 -3
@@ -9363,8 +9363,7 @@ proc mkpatchgo {} {
9363 set newid [$patchtop.tosha1 get]
9364 set fname [$patchtop.fname get]
9365 set cmd [diffcmd [list $oldid $newid] -p]
9366 - lappend cmd >$fname &
9367 - if {[catch {eval exec $cmd} err]} {
9366 + if {[catch {safe_exec_redirect $cmd [list >$fname &]} err]} {
9367 error_popup "[mc "Error creating patch:"] $err" $patchtop
9368 }
9369 catch {destroy $patchtop}
@@ -9553,7 +9552,7 @@ proc wrcomgo {} {
9552 set id [$wrcomtop.sha1 get]
9553 set cmd "echo $id | [$wrcomtop.cmd get]"
9554 set fname [$wrcomtop.fname get]
9556 - if {[catch {exec sh -c $cmd >$fname &} err]} {
9555 + if {[catch {safe_exec_redirect [list sh -c $cmd] [list >$fname &]} err]} {
9556 error_popup "[mc "Error writing commit:"] $err" $wrcomtop
9557 }
9558 catch {destroy $wrcomtop}