git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: BUG: git-gui no longer executes hook scripts

From
Mark Levedahl <mlevedahl@gmail.com>
Date
Sep 15, 2023, 23:33 UTC
Message-ID
<454d8b7b-96df-ec8f-2285-e022de66c66c@gmail.com>
In-Reply-To
<xmqq5y4bgxy1.fsf@gitster.g>
On 9/15/23 13:15, Junio C Hamano wrote:
Show 16 quoted lines
> Junio C Hamano <gitster@pobox.com> writes:
>
>> Shouldn't this "is it absolute" check with "$cmd" also check if $cmd
>> has either forward or backward slash in it?
>>
>> Checking the use of _which with fixed arguments, it is used to spawn
>> git, gitk, nice, sh; and _which finding where they appear on the
>> search path does sound sane.  But _which does not seem to have the "if
>> given a command with directory separator, the search path does not
>> matter.  The caller means it is relative to the $cwd" logic at all,
>> so it seems it is the callers responsibility to make sure it does
>> not pass things like ".git/hooks/pre-commit" to it.
> In other words, something along this line may go in the right
> direction (I no longer speak Tcl, and this is done with manual in
> one hand, while typing with the other hand).
>

I think a simpler fix is just to examine the number of path components - more than one means a relative or absolute command (/foo splits into two parts). The below works for me on Linux.

diff --git a/git-gui/git-gui.sh b/git-gui/git-gui.sh
index 277a2b1c8c..0c39d9fa26 100755
--- a/git-gui/git-gui.sh
+++ b/git-gui/git-gui.sh
@@ -118,7 +118,7 @@ proc sanitize_command_line {command_line from_index} {
     set i $from_index
     while {$i < [llength $command_line]} {
         set cmd [lindex $command_line $i]
-       if {[file pathtype $cmd] ne "absolute"} {
+       if {[llength [file split $cmd]] < 2} {
             set fullpath [_which $cmd]
             if {$fullpath eq ""} {
                 throw {NOT-FOUND} "$cmd not found in PATH"


We could also wrap the entirety of commit aae9560a in

     if {[is_Windows]} { ... }

as all of this code is fixing a Windows specific vulnerability, though a 
fix like the above is needed regardless.

Mark
Previous: Junio C HamanoNext: Mark Levedahl
Message 4 of 25 in “BUG: git-gui no longer executes hook scripts”
  1. Mark LevedahlSep 15, 2023
  2. Junio C HamanoSep 15, 2023
  3. Junio C HamanoSep 15, 2023
  4. Mark LevedahlSep 15, 2023
  5. git-gui - re-enable use of hook scriptsMark Levedahl, Sep 16, 2023
  6. Junio C HamanoSep 16, 2023
  7. git-gui - re-enable use of hook scriptsMark Levedahl, Sep 16, 2023
  8. Junio C HamanoSep 16, 2023
  9. Mark LevedahlSep 17, 2023
  10. git-gui - use git-hook, honor core.hooksPathMark Levedahl, Sep 17, 2023
  11. Johannes SchindelinSep 18, 2023
  12. Junio C HamanoSep 18, 2023
  13. Mark LevedahlSep 18, 2023
  14. Junio C HamanoSep 18, 2023
  15. Pratyush YadavSep 20, 2023
  16. Mark LevedahlSep 20, 2023
  17. Junio C HamanoSep 20, 2023
  18. Junio C HamanoSep 20, 2023
  19. Johannes SchindelinSep 18, 2023
  20. Junio C HamanoSep 18, 2023
  21. Pratyush YadavSep 20, 2023
  22. Junio C HamanoSep 16, 2023
  23. Mark LevedahlSep 16, 2023
  24. Mark LevedahlSep 16, 2023
  25. Junio C HamanoSep 16, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.