{"thread":{"id":"8444","subject":"[PATCH] filter-branch: use sh -c instead of eval","startedAt":"2007-06-05T16:57:34Z","lastAt":"2007-06-06T20:53:48Z","messageCount":3,"participants":["Matthias Lederhofer","Johannes Sixt","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"44081","messageId":"20070605165734.GA21708@moooo.ath.cx","threadId":"8444","inReplyTo":null,"subject":"[PATCH] filter-branch: use sh -c instead of eval","fromName":"Matthias Lederhofer","fromEmail":"matled@gmx.net","sentAt":"2007-06-05T16:57:34Z","receivedAt":"2007-06-05T16:57:34Z","isPatch":true,"sender":{"key":"matled@gmx.net","avatar":null},"body":"If filters use variables with the same name as variables\nused in the script the script breaks.  Executing the filters\nin a separate process prevents accidential modification of\nthe variables in the main process.\n\nSigned-off-by: Matthias Lederhofer <matled@gmx.net>\n---\nThis one goes on top of the last patch, adding the < /dev/null.\n\nExample:\n% git filter-branch --tree-filter 'commit=foo' bar \n94ddd5151901a2b62820facc1bcf578abf842c8a (1/2) fatal: ambiguous argument 'foo': unknown revision or path not in the working tree.\nUse '--' to separate paths from revisions\nfatal: ambiguous argument 'foo': unknown revision or path not in the working tree.\nUse '--' to separate paths from revisions\n94ddd5151901a2b62820facc1bcf578abf842c8a\n[..]\nhead: cannot open `../map/81208e18e22e0f1c7c73a4ea5bbd5150c0ee65c2'\nfor reading: No such file or directory\nusage: git-update-ref [-m <reason>] (-d <refname> <value> | [--no-deref] <refname> <value> [<oldval>])\n---\n git-filter-branch.sh |   18 +++++++++---------\n 1 files changed, 9 insertions(+), 9 deletions(-)\n\ndiff --git a/git-filter-branch.sh b/git-filter-branch.sh\nindex 73e7c01..b446011 100644\n--- a/git-filter-branch.sh\n+++ b/git-filter-branch.sh\n@@ -54,9 +54,9 @@\n # Filters\n # ~~~~~~~\n # The filters are applied in the order as listed below. The COMMAND\n-# argument is always evaluated in shell using the 'eval' command.\n-# The $GIT_COMMIT environment variable is permanently set to contain\n-# the id of the commit being rewritten. The author/committer environment\n+# argument is always evaluated in shell using sh -c \"$filter\".  The\n+# $GIT_COMMIT environment variable is permanently set to contain the id\n+# of the commit being rewritten. The author/committer environment\n # variables are set before the first filter is run.\n #\n # A 'map' function is available that takes an \"original sha1 id\" argument\n@@ -349,21 +349,21 @@ while read commit; do\n \n \teval \"$(set_ident AUTHOR <../commit)\"\n \teval \"$(set_ident COMMITTER <../commit)\"\n-\teval \"$filter_env\" < /dev/null\n+\tsh -c \"$filter_env\" < /dev/null\n \n \tif [ \"$filter_tree\" ]; then\n \t\tgit-checkout-index -f -u -a\n \t\t# files that $commit removed are now still in the working tree;\n \t\t# remove them, else they would be added again\n \t\tgit-ls-files -z --others | xargs -0 rm -f\n-\t\teval \"$filter_tree\" < /dev/null\n+\t\tsh -c \"$filter_tree\" < /dev/null\n \t\tgit-diff-index -r $commit | cut -f 2- | tr '\\n' '\\0' | \\\n \t\t\txargs -0 git-update-index --add --replace --remove\n \t\tgit-ls-files -z --others | \\\n \t\t\txargs -0 git-update-index --add --replace --remove\n \tfi\n \n-\teval \"$filter_index\" < /dev/null\n+\tsh -c \"$filter_index\" < /dev/null\n \n \tparentstr=\n \tfor parent in $(get_parents $commit); do\n@@ -376,11 +376,11 @@ while read commit; do\n \t\tfi\n \tdone\n \tif [ \"$filter_parent\" ]; then\n-\t\tparentstr=\"$(echo \"$parentstr\" | eval \"$filter_parent\")\"\n+\t\tparentstr=\"$(echo \"$parentstr\" | sh -c \"$filter_parent\")\"\n \tfi\n \n \tsed -e '1,/^$/d' <../commit | \\\n-\t\teval \"$filter_msg\" | \\\n+\t\tsh -c \"$filter_msg\" | \\\n \t\tsh -c \"$filter_commit\" git-commit-tree $(git-write-tree) $parentstr | \\\n \t\ttee ../map/$commit\n done <../revs\n@@ -410,7 +410,7 @@ if [ \"$filter_tag_name\" ]; then\n \t\t[ -f \"../map/$sha1\" ] || continue\n \t\tnew_sha1=\"$(cat \"../map/$sha1\")\"\n \t\texport GIT_COMMIT=\"$sha1\"\n-\t\tnew_ref=\"$(echo \"$ref\" | eval \"$filter_tag_name\")\"\n+\t\tnew_ref=\"$(echo \"$ref\" | sh -c \"$filter_tag_name\")\"\n \n \t\techo \"$ref -> $new_ref ($sha1 -> $new_sha1)\"\n \n-- \n1.5.2.1.860.g78ab5-dirty\n"},{"id":"44094","messageId":"f44bvq$klu$1@sea.gmane.org","threadId":"8444","inReplyTo":"20070605165734.GA21708@moooo.ath.cx","subject":"Re: [PATCH] filter-branch: use sh -c instead of eval","fromName":"Johannes Sixt","fromEmail":"johannes.sixt@telecom.at","sentAt":"2007-06-05T19:02:18Z","receivedAt":"2007-06-05T19:02:18Z","isPatch":true,"sender":{"key":"j6t@kdbg.org","avatar":"https://avatars.githubusercontent.com/u/14810926?v=4"},"body":"Matthias Lederhofer wrote:\n\n> If filters use variables with the same name as variables\n> used in the script the script breaks.  Executing the filters\n> in a separate process prevents accidential modification of\n> the variables in the main process.\n> @@ -349,21 +349,21 @@ while read commit; do\n>  \n>  eval \"$(set_ident AUTHOR <../commit)\"\n>  eval \"$(set_ident COMMITTER <../commit)\"\n> -     eval \"$filter_env\" < /dev/null\n> +     sh -c \"$filter_env\" < /dev/null\n\nNACK.\n\nThe eval is on purpose here. $filter_env must be able export GIT_AUTHOR* and\nGIT_COMMITTER* variables here.\n\nGenerally, it might be useful that one filter sets or exports variables that\nare then available for subsequent filters or the next commit. Therefore, I\nthink it's actually a feature to have eval instead of sh -c even if there\nis a chance that the filter overwrites internal variables. \n\n-- Hannes\n"},{"id":"44186","messageId":"7vd508ztwj.fsf@assigned-by-dhcp.cox.net","threadId":"8444","inReplyTo":"f44bvq$klu$1@sea.gmane.org","subject":"Re: [PATCH] filter-branch: use sh -c instead of eval","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2007-06-06T20:53:48Z","receivedAt":"2007-06-06T20:53:48Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Johannes Sixt <johannes.sixt@telecom.at> writes:\n\n> Matthias Lederhofer wrote:\n>\n>> If filters use variables with the same name as variables\n>> used in the script the script breaks.  Executing the filters\n>> in a separate process prevents accidential modification of\n>> the variables in the main process.\n>> @@ -349,21 +349,21 @@ while read commit; do\n>>  \n>>  eval \"$(set_ident AUTHOR <../commit)\"\n>>  eval \"$(set_ident COMMITTER <../commit)\"\n>> -     eval \"$filter_env\" < /dev/null\n>> +     sh -c \"$filter_env\" < /dev/null\n>\n> NACK.\n>\n> The eval is on purpose here. $filter_env must be able export GIT_AUTHOR* and\n> GIT_COMMITTER* variables here.\n\nTrue.  The other hunks may be improvements, though.\n"}]}