Use POSIX control-char check in PR-title validation

Address cross-review FIX: the title re-validation used GNU-only
`grep -P`. Switch to POSIX `[[:cntrl:]]` under LC_ALL=C so the check
is portable; C1 chars are already stripped box-side by sanitize_pr_title.
This commit is contained in:
Adam Moussa 2026-06-25 13:45:36 -04:00
parent a705859ea3
commit c8a023fcd5

View file

@ -1286,8 +1286,11 @@ jobs:
# smuggle newlines/control chars/over-long content into the PR metadata.
title="$fallback_title"
if [ -n "$PR_TITLE" ]; then
# Reject any C0/C1 control char (incl. newline/tab) or > 70 chars.
if printf '%s' "$PR_TITLE" | LC_ALL=C grep -qP '[\x00-\x1f\x7f-\x9f]'; then
# Reject any control char (incl. newline/tab/NUL/DEL) or > 70 chars.
# POSIX [[:cntrl:]] under LC_ALL=C (no GNU-only `grep -P`): matches
# 0x00-0x1f + 0x7f. C1 (0x80-0x9f) is already stripped box-side by
# sanitize_pr_title; this is the defense-in-depth re-check (§4.6).
if printf '%s' "$PR_TITLE" | LC_ALL=C grep -q '[[:cntrl:]]'; then
echo "::warning::pr_title rejected (control chars); using fallback"
elif [ "$(printf '%s' "$PR_TITLE" | wc -m)" -gt 70 ]; then
echo "::warning::pr_title rejected (too long); using fallback"