From: Mark Levedahl Date: Wed, 29 Apr 2026 20:14:06 GMT Subject: Re: [PATCH v2 1/1] git-gui: protect rev-parse --show-toplevel call Message-ID: <0100848a-d408-49f0-aeb1-8835c8775539@gmail.com> In-Reply-To: On 4/29/26 1:32 PM, Shroom Moo wrote: > When starting git-gui from a directory that is a bare repository or > where the working tree is missing, git-gui previously executed > 'rev-parse --show-toplevel' without error handling. This caused a > fatal Tcl error ("this operation must be run in a work tree"). > > Wrap the call in a catch to prevent the fatal error. The existing > error paths after this call already handle bare repos and missing > worktrees appropriately. > > Signed-off-by: Shroom Moo > --- > git-gui/git-gui.sh | 4 +++- > 1 file changed, 3 insertions(+), 1 deletion(-) > > diff --git a/git-gui/git-gui.sh b/git-gui/git-gui.sh > index 23fe76e498..aee37685e1 100755 > --- a/git-gui/git-gui.sh > +++ b/git-gui/git-gui.sh > @@ -1169,7 +1169,9 @@ if {![file isdirectory $_gitdir]} { > load_config 0 > apply_config > > -set _gitworktree [git rev-parse --show-toplevel] > +if {[catch {set _gitworktree [git rev-parse --show-toplevel]}]} { > + set _gitworktree {} > +} > > if {$_prefix ne {}} { > if {$_gitworktree eq {}} { Unfortunately, this allows starting git-gui inside the separate gitdir created by git clone --separate-git-dir=/some/where/else ... There is no hint where the workdir is, but git recognizes the repository is not bare: git rev-parse --is-bare-repository ==> false git rev-parse --is-inside-git-dir ==> true git rev-parse --is-inside-work-tree ==> false git rev-parse --show-toplevel ==> fatal: must be run in a work tree git worktree list ==> absolute path to gitdir (not a worktree) As git-gui has no protection against modifying what is effectively a bare repository, allowing git-gui to run in this directory is dangerous, or possibly just very confusing. git refuses to work in this gitdir: "git status" run in the above gitdir gives: "fatal: this operation must be run in a work tree." The simplest safe thing is to catch the error and abort with a more useful message than currently provided. Or perhaps, check git rev-parse --is-inside-git-dir and abort, and do so before trying --show-toplevel. Mark