git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v3 11/12] git-gui: check browser/blame arguments carefully

From
Mark Levedahl <mlevedahl@gmail.com>
Date
May 31, 2026, 23:02 UTC
Message-ID
<20260531230225.126817-12-mlevedahl@gmail.com>
In-Reply-To
<20260531230225.126817-1-mlevedahl@gmail.com>

git gui offers two related commands, browser and blame, that provide graphical interfaces driven by git ls-tree and git blame. As such, the arguments to git-gui need to satisfy those two git commands. But, git-gui does not assure this leading to confusing or incorrect results. For instance 'git browser <non-existent path>' shows a blank browser window rather than error message.

Also, commit 3e45ee1ef2 ("git-gui: Smarter command line parsing for browser, blame", 2007-05-08) implemented code to allow giving path before rev on the command line, and unconditionally uses the worktree to disambiguate. As a result, the following command run in a current git-gui checkout of the master branch shows the master branch version of blame.tcl, when none should be shown as that file does not exist in gitgui-0.6.0.

  git gui blame lib/blame.tcl gitgui-0.6.0

This 'file before rev' feature in git-gui mirrors ideas considered when git's user interface was very young, but no such feature is documented for any git command. Rather than try to fix an idea git itself rejected, let's just remove this broken and hopefully unused feature.

git-gui browser|blame both accept 'rev' and 'path' as command line arguments. rev defaults to 'HEAD' if not given, while path must be given. path names a directory tree to ls-tree or a file to blame. path must exist in rev for ls-tree and for blame. In addition git blame will include uncommitted changes from the worktree file at 'path' if rev is not given (thus defaulting to HEAD), but still requires that the file exists in HEAD.

So, let's clean up the parser to check that the arguments are usable.
- give a full synopsis, including '--' that may be used to separate rev and
  path. (as path is the required final arg, -- gives no extra info)
- explicitly check the number of arguments
- use rev-parse to assure a user supplied rev is valid
- use ls-tree to assure that path exists in rev
- for blame only, with no rev given and a worktree existing, also assure
  that path points to a file in the worktree

With these changes, error messages are thrown by the parser if the path or rev are not known: no blank or erroneous displays are created. Also, this avoids accessing the worktree except in the specific use case supported by blame / git-blame, meaning browser|blame now also work without a worktree.

Signed-off-by: Mark Levedahl <mlevedahl@gmail.com>
---
 git-gui.sh | 122 +++++++++++++++++++++++++++--------------------------
 1 file changed, 63 insertions(+), 59 deletions(-)
diff --git a/git-gui.sh b/git-gui.sh
index 16d6b3051a..22939215a6 100755
--- a/git-gui.sh
+++ b/git-gui.sh
@@ -3000,101 +3000,105 @@ proc normalize_relpath {path} {
 	}
 }
 
+proc show_parse_err {err} {
+	if {[tk windowingsystem] eq "win32"} {
+		catch {wm withdraw .}
+		error_popup $err
+	} else {
+		puts stderr $err
+	}
+	exit 1
+}
+
 # -- Not a normal commit type invocation?  Do that instead!
 #
 switch -- $subcommand {
 browser -
 blame {
 	if {$subcommand eq "blame"} {
-		set subcommand_args {[--line=<num>] rev? path}
+		set subcommand_args {[--line=<num>] [rev] [--] <filename>}
+		set required_pathtype blob
 	} else {
-		set subcommand_args {rev? path}
+		set subcommand_args {[rev] [--] <dirname>}
+		set required_pathtype tree
 	}
-	if {$argv eq {}} usage
+	set maxargs [llength $subcommand_args]
+	set nargs [llength $argv]
+	if {$nargs < 1 || $nargs > $maxargs} usage
 	set head {}
 	set path {}
 	set jump_spec {}
-	set is_path 0
-	foreach a $argv {
-		set p [file join $_prefix $a]
 
-		if {$is_path || [file exists $p]} {
-			if {$path ne {}} usage
-			set path [normalize_relpath $p]
-			break
+	set iarg 0
+	foreach a $argv {
+		incr iarg
+		if {$iarg == $nargs} {
+			# final argument is path
+			set path [normalize_relpath [file join $_prefix $a]]
 		} elseif {$a eq {--}} {
-			if {$path ne {}} {
-				if {$head ne {}} usage
-				set head $path
-				set path {}
+			# allow before required final arg that must be path
+			if {$iarg != $nargs - 1} {
+				usage
 			}
-			set is_path 1
 		} elseif {[regexp {^--line=(\d+)$} $a a lnum]} {
-			if {$jump_spec ne {} || $head ne {}} usage
+			# --line can only be the first arg
+			if {$iarg != 1 || $subcommand ne {blame}} usage
 			set jump_spec [list $lnum]
 		} elseif {$head eq {}} {
-			if {$head ne {}} usage
 			set head $a
-			set is_path 1
 		} else {
 			usage
 		}
 	}
-	unset is_path
 
-	if {$head ne {} && $path eq {}} {
-		if {[string index $head 0] eq {/}} {
-			set path [normalize_relpath $head]
-			set head {}
+	# If head not given, use current branch (HEAD),
+	# and blame will use worktree if there is one.
+	set use_worktree 0
+	if {$head eq {}} {
+		load_current_branch
+		set head $current_branch
+		if {$subcommand eq {blame} && ![is_bare]} {
+			if {![file isfile $path]} {
+				show_parse_err [mc "fatal: no such file '%s' in worktree" $path]
+			}
+			set use_worktree 1
+		}
+	} else {
+		if {[catch {
+				set commitid \
+					[git rev-parse --verify --end-of-options \
+					[strcat $head "^{commit}"]]
+			}]} {
+			show_parse_err [mc "fatal: '%s' is not a valid rev'" $head]
 		} else {
-			set path [normalize_relpath $_prefix$head]
-			set head {}
+			set current_branch $head
 		}
 	}
 
-	if {$head eq {}} {
-		load_current_branch
-	} else {
-		if {[regexp [string map "@@ [expr $hashlength - 1]" {^[0-9a-f]{1,@@}$}] $head]} {
-			if {[catch {
-					set head [git rev-parse --verify $head]
-				} err]} {
-				if {[tk windowingsystem] eq "win32"} {
-					tk_messageBox -icon error -title [mc Error] -message $err
-				} else {
-					puts stderr $err
-				}
-				exit 1
-			}
+	# check path is known in head, and is file / directory as required
+	set pathtype {}
+	catch {set pathtype [git ls-tree {--format=%(objecttype)} $head $path]}
+	if {$pathtype ne {} && $path eq {.}} {
+		# ls-tree gives contents of root-dir, we need root-dir itself
+		set pathtype {tree}
+	}
+
+	if {$pathtype ne $required_pathtype} {
+		switch -- $required_pathtype {
+			tree {show_parse_err \
+				[mc "'%s' is not a directory in rev '%s'" $path $head]}
+			blob {show_parse_err \
+				[mc "'%s' is not a filename in rev '%s'" $path $head]}
 		}
-		set current_branch $head
 	}
 
 	wm deiconify .
 	switch -- $subcommand {
 	browser {
-		if {$jump_spec ne {}} usage
-		if {$head eq {}} {
-			if {$path ne {} && [file isdirectory $path]} {
-				set head $current_branch
-			} else {
-				set head $path
-				set path {}
-			}
-		}
 		browser::new $head $path
 	}
 	blame   {
-		if {$head eq {} && ![file exists $path]} {
-			catch {wm withdraw .}
-			tk_messageBox \
-				-icon error \
-				-type ok \
-				-title [mc "git-gui: fatal error"] \
-				-message [mc "fatal: cannot stat path %s: No such file or directory" $path]
-			exit 1
-		}
-		blame::new $head $path $jump_spec
+		blame::new [expr {$use_worktree ? {} : $head}] $path $jump_spec
 	}
 	}
 	return
-- 
2.54.0.99.14
Previous: Mark LevedahlNext: Mark Levedahl
Message 117 of 134 in “git-gui: handle bare repo or missing worktree”
  1. git-gui: handle bare repo or missing worktreeShroom Moo, Apr 21, 2026
  2. Johannes SixtApr 29, 2026
  3. 1/1 git-gui: protect rev-parse --show-toplevel callShroom Moo, Apr 29, 2026
  4. Mark LevedahlApr 29, 2026
  5. 1/1 git-gui: handle missing worktree and separated gitdirShroom Moo, Apr 30, 2026
  6. Mark LevedahlApr 30, 2026
  7. Shroom MooMay 1, 2026
  8. Johannes SixtMay 1, 2026
  9. Mark LevedahlMay 1, 2026
  10. Mark LevedahlMay 2, 2026
  11. Johannes SixtMay 3, 2026
  12. Mark LevedahlMay 4, 2026
  13. Mark LevedahlMay 5, 2026
  14. Johannes SixtMay 6, 2026
  15. Mark LevedahlMay 6, 2026
  16. Johannes SixtMay 6, 2026
  17. Mark LevedahlMay 6, 2026
  18. Mark LevedahlMay 7, 2026
  19. 1/1 git-gui: handle missing worktree and separated gitdirShroom Moo, May 1, 2026
  20. 1/1 git-gui: restructure repository startupShroom Moo, May 4, 2026
  21. Johannes SixtMay 6, 2026
  22. 0/3 git-gui: robustify startup and fix environment handlingShroom Moo, May 6, 2026
  23. 0/3 git-gui: robustify startup and fix environment handlingShroom Moo, May 9, 2026
  24. Mark LevedahlMay 14, 2026
  25. 00/11 Improve git gui operation without a worktreeMark Levedahl, May 14, 2026
  26. 01/11 git-gui: allow specifying path '.' to the browserMark Levedahl, May 14, 2026
  27. Johannes SixtMay 15, 2026
  28. Mark LevedahlMay 16, 2026
  29. 02/11 git-gui: refactor browser / blame argument parsingMark Levedahl, May 14, 2026
  30. Johannes SixtMay 15, 2026
  31. Mark LevedahlMay 16, 2026
  32. 04/11 git-gui: put choose_repository::pick in a procMark Levedahl, May 14, 2026
  33. Aina BootMay 15, 2026
  34. Mark LevedahlMay 15, 2026
  35. Johannes SixtMay 15, 2026
  36. Mark LevedahlMay 16, 2026
  37. 05/11 git-gui: use --absolute-git-dirMark Levedahl, May 14, 2026
  38. Johannes SixtMay 15, 2026
  39. Mark LevedahlMay 16, 2026
  40. 03/11 git-gui: guard set/unset of GIT_DIR and GIT_WORK_TREEMark Levedahl, May 14, 2026
  41. Johannes SixtMay 15, 2026
  42. Mark LevedahlMay 16, 2026
  43. 06/11 git gui: GIT_DIR / GIT_WORK_TREE make any discovery error fatalMark Levedahl, May 14, 2026
  44. 07/11 git-gui: use rev-parse exclusively to find a repositoryMark Levedahl, May 14, 2026
  45. Johannes SixtMay 15, 2026
  46. Mark LevedahlMay 16, 2026
  47. 08/11 git-gui: simplify [is_bare] to report if a worktree is knownMark Levedahl, May 14, 2026
  48. Johannes SixtMay 16, 2026
  49. 09/11 git-gui: support using repository parent dir as a worktreeMark Levedahl, May 14, 2026
  50. Johannes SixtMay 16, 2026
  51. Mark LevedahlMay 16, 2026
  52. 10/11 git-gui: improve worktree discoveryMark Levedahl, May 14, 2026
  53. Johannes SixtMay 16, 2026
  54. Mark LevedahlMay 16, 2026
  55. Johannes SixtMay 19, 2026
  56. Mark LevedahlMay 19, 2026
  57. 11/11 git-gui: add gui and pick as explicit subcommandsMark Levedahl, May 14, 2026
  58. Johannes SixtMay 16, 2026
  59. Mark LevedahlMay 16, 2026
  60. Johannes SixtMay 19, 2026
  61. Mark LevedahlMay 19, 2026
  62. Johannes SixtMay 19, 2026
  63. Johannes SixtMay 16, 2026
  64. 00/11 Improve git gui operation without a worktreeMark Levedahl, May 20, 2026
  65. 01/11 git-gui: guard set/unset of GIT_DIR and GIT_WORK_TREEMark Levedahl, May 20, 2026
  66. Johannes SixtMay 22, 2026
  67. Mark LevedahlMay 22, 2026
  68. Johannes SixtMay 23, 2026
  69. Aina BootMay 23, 2026
  70. Mark LevedahlMay 23, 2026
  71. 02/11 git-gui: return status from choose_repository::pickMark Levedahl, May 20, 2026
  72. Johannes SixtMay 22, 2026
  73. 04/11 git-gui: use rev-parse exclusively to find a repositoryMark Levedahl, May 20, 2026
  74. Johannes SixtMay 22, 2026
  75. Mark LevedahlMay 22, 2026
  76. Mark LevedahlMay 22, 2026
  77. 05/11 git-gui: simplify [is_bare] to report if a worktree is knownMark Levedahl, May 20, 2026
  78. 06/11 git-gui: use git rev-parse for worktree discoveryMark Levedahl, May 20, 2026
  79. Johannes SixtMay 23, 2026
  80. 07/11 git-gui: try harder to find worktree from gitdirMark Levedahl, May 20, 2026
  81. Shroom MooMay 21, 2026
  82. Mark LevedahlMay 21, 2026
  83. Shroom MooMay 22, 2026
  84. Mark LevedahlMay 22, 2026
  85. Johannes SixtMay 23, 2026
  86. Shroom MooMay 23, 2026
  87. Johannes SixtMay 23, 2026
  88. Mark LevedahlMay 23, 2026
  89. 03/11 git-gui: use --absolute-git-dirMark Levedahl, May 20, 2026
  90. Johannes SixtMay 22, 2026
  91. 08/11 git-gui: use HEAD as current branch when detached (bug fix)Mark Levedahl, May 20, 2026
  92. Johannes SixtMay 23, 2026
  93. 09/11 git-gui: allow specifying path '.' to the browserMark Levedahl, May 20, 2026
  94. Johannes SixtMay 23, 2026
  95. Mark LevedahlMay 23, 2026
  96. 10/11 git-gui: adapt blame/browser parsing for bare operationMark Levedahl, May 20, 2026
  97. Shroom MooMay 21, 2026
  98. Mark LevedahlMay 21, 2026
  99. Shroom MooMay 22, 2026
  100. fixup git-gui: allow blame to show uncommitted changesMark Levedahl, May 23, 2026
  101. Johannes SixtMay 23, 2026
  102. 11/11 git-gui: add gui and pick as explicit subcommandsMark Levedahl, May 20, 2026
  103. Johannes SixtMay 24, 2026
  104. Johannes SixtMay 24, 2026
  105. Mark LevedahlMay 25, 2026
  106. 00/12 Improve git gui operation without a worktreeMark Levedahl, May 31, 2026
  107. 01/12 git-gui: use HEAD as current branch when detachedMark Levedahl, May 31, 2026
  108. 02/12 git-gui: remove unnecessary 'cd $_gitworktree' from do_gitkMark Levedahl, May 31, 2026
  109. 03/12 git-gui: guard set/unset of GIT_DIR and GIT_WORK_TREEMark Levedahl, May 31, 2026
  110. 04/12 git-gui: do not change global vars in choose_repository::pickMark Levedahl, May 31, 2026
  111. 05/12 git-gui: use --absolute-git-dirMark Levedahl, May 31, 2026
  112. 06/12 git-gui: use rev-parse exclusively to find a repositoryMark Levedahl, May 31, 2026
  113. 07/12 git-gui: use git rev-parse for worktree discoveryMark Levedahl, May 31, 2026
  114. 08/12 git-gui: simplify [is_bare] to report if a worktree is knownMark Levedahl, May 31, 2026
  115. 09/12 git-gui: try harder to find worktree from gitdirMark Levedahl, May 31, 2026
  116. 10/12 git-gui: allow specifying path '.' to the browserMark Levedahl, May 31, 2026
  117. 11/12 git-gui: check browser/blame arguments carefullyMark Levedahl, May 31, 2026
  118. 12/12 git-gui: add gui and pick as explicit subcommandsMark Levedahl, May 31, 2026
  119. Johannes SixtJun 2, 2026
  120. Mark LevedahlJun 2, 2026
  121. Johannes SixtJun 2, 2026
  122. Shroom MooApr 29, 2026
  123. 2/3 git-gui: disable gitk visualization when no worktree availableShroom Moo, May 6, 2026
  124. 1/3 git-gui: restructure repository startupShroom Moo, May 6, 2026
  125. 3/3 git-gui: handle GIT_DIR and GIT_WORK_TREE earlyShroom Moo, May 6, 2026
  126. Mark LevedahlMay 7, 2026
  127. Aina BootMay 9, 2026
  128. Shroom MooMay 9, 2026
  129. 1/3 git-gui: restructure repository startupShroom Moo, May 9, 2026
  130. Johannes SixtMay 15, 2026
  131. 3/3 git-gui: handle GIT_DIR and GIT_WORK_TREE earlyShroom Moo, May 9, 2026
  132. Johannes SixtMay 15, 2026
  133. 2/3 git-gui: disable gitk visualization when no worktree availableShroom Moo, May 9, 2026
  134. Johannes SixtMay 15, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.