From 2fc441493eb887199c279e2eff990f3f4cd0deef Mon Sep 17 00:00:00 2001 From: Julian Oes Date: Mon, 21 Sep 2026 11:15:57 +1200 Subject: [PATCH] ci(commit_checks): pass the PR title through the environment (#28772) The PR title was interpolated directly into the shell command, so bash parsed it as syntax before argparse ever saw it. A title containing double quotes split into several arguments and failed the check for the wrong reason, and a hostile title could run arbitrary commands on the runner. Pass it via the environment like the labeler workflow already does, so it is data rather than syntax. Also make sure a report exists when the check fails without writing one, otherwise the posting step dies on a missing comment.md and hides the actual error. Assisted-by: Claude:claude-opus-5 Signed-off-by: Julian Oes --- .github/workflows/commit_checks.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/commit_checks.yml b/.github/workflows/commit_checks.yml index b3bf0882b8e..fb8b813ae34 100644 --- a/.github/workflows/commit_checks.yml +++ b/.github/workflows/commit_checks.yml @@ -30,8 +30,10 @@ jobs: - name: Check PR title id: check + env: + PR_TITLE: ${{ github.event.pull_request.title }} run: | - python3 Tools/ci/check_pr_title.py "${{ github.event.pull_request.title }}" --markdown-file comment.md && rc=0 || rc=$? + python3 Tools/ci/check_pr_title.py "$PR_TITLE" --markdown-file comment.md && rc=0 || rc=$? echo "exit_code=$rc" >> "$GITHUB_OUTPUT" - name: Post or clear comment @@ -40,6 +42,9 @@ jobs: GH_TOKEN: ${{ github.token }} run: | if [ "${{ steps.check.outputs.exit_code }}" != "0" ]; then + if [ ! -s comment.md ]; then + echo "The PR title check failed without producing a report." > comment.md + fi python3 Tools/ci/pr_comment.py --marker pr-title --pr "$PR_NUMBER" --result fail < comment.md else python3 Tools/ci/pr_comment.py --marker pr-title --pr "$PR_NUMBER" --result pass