git-gui: assure PATH has only absolute elements.

Since 8f23432b38d9 (windows: ignore empty `PATH` elements, 2022-11-23), git-gui excises all empty paths from $PATH, but still allows '.' or other relative paths, which can also allow executing code from the repository. Let's remove anything except absolute elements. While here, let's remove duplicated elements, which are very common on Windows: only the first such item can do anything except waste time repeating a search. Signed-off-by: Mark Levedahl <mlevedahl@gmail.com> Signed-off-by: Johannes Sixt <j6t@kdbg.org> Signed-off-by: Taylor Blau <me@ttaylorr.com>

Mark Levedahl committed Apr 11, 2025 at 10:08 UTC 8fe7861c5185248a5786e87af71e29000cd4f214
1 file changed +16 -4
git-gui.sh
+16 -4
@@ -88,10 +88,22 @@ proc _which {what args} {
88 set gitguidir [file dirname [info script]]
89 regsub -all ";" $gitguidir "\\;" gitguidir
90 set env(PATH) "$gitguidir;$env(PATH)"
91 - set _search_path [split $env(PATH) {;}]
92 - # Skip empty `PATH` elements
93 - set _search_path [lsearch -all -inline -not -exact \
94 - $_search_path ""]
91 +
92 + set _path_seen [dict create]
93 + foreach p [split $env(PATH) {;}] {
94 + # Keep only absolute paths, getting rid of ., empty, etc.
95 + if {[file pathtype $p] ne {absolute}} {
96 + continue
97 + }
98 + # Keep only the first occurence of any duplicates.
99 + set norm_p [file normalize $p]
100 + if {[dict exists $_path_seen $norm_p]} {
101 + continue
102 + }
103 + dict set _path_seen $norm_p 1
104 + lappend _search_path $norm_p
105 + }
106 + unset _path_seen
107 set _search_exe .exe
108 } else {
109 set _search_path [split $env(PATH) :]