From c8a023fcd525af41bdbf9d1ce2719a02358229ed Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 25 Jun 2026 13:45:36 -0400 Subject: [PATCH] Use POSIX control-char check in PR-title validation Address cross-review FIX: the title re-validation used GNU-only `grep -P`. Switch to POSIX `[[:cntrl:]]` under LC_ALL=C so the check is portable; C1 chars are already stripped box-side by sanitize_pr_title. --- .github/workflows/agent-team-apply-verify.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/agent-team-apply-verify.yml b/.github/workflows/agent-team-apply-verify.yml index 28e3bf1..62995ba 100644 --- a/.github/workflows/agent-team-apply-verify.yml +++ b/.github/workflows/agent-team-apply-verify.yml @@ -1286,8 +1286,11 @@ jobs: # smuggle newlines/control chars/over-long content into the PR metadata. title="$fallback_title" if [ -n "$PR_TITLE" ]; then - # Reject any C0/C1 control char (incl. newline/tab) or > 70 chars. - if printf '%s' "$PR_TITLE" | LC_ALL=C grep -qP '[\x00-\x1f\x7f-\x9f]'; then + # Reject any control char (incl. newline/tab/NUL/DEL) or > 70 chars. + # POSIX [[:cntrl:]] under LC_ALL=C (no GNU-only `grep -P`): matches + # 0x00-0x1f + 0x7f. C1 (0x80-0x9f) is already stripped box-side by + # sanitize_pr_title; this is the defense-in-depth re-check (ยง4.6). + if printf '%s' "$PR_TITLE" | LC_ALL=C grep -q '[[:cntrl:]]'; then echo "::warning::pr_title rejected (control chars); using fallback" elif [ "$(printf '%s' "$PR_TITLE" | wc -m)" -gt 70 ]; then echo "::warning::pr_title rejected (too long); using fallback"