ci: harden invisible-unicode check against unusual filenames

Use find -type f -print0 with xargs -0 so paths containing whitespace are
not split, and only regular files are passed to perl.

Signed-off-by: Mateen Anjum <mateenali66@gmail.com>
pull/32139/head
Mateen Anjum 5 months ago
parent 389d7ddf59
commit 647cdd379f
No known key found for this signature in database
GPG Key ID: C8F3C7DA9ED10BE9

@ -24,7 +24,7 @@ find_files() {
-o -wholename '*third_party*' \ -o -wholename '*third_party*' \
\) -prune \ \) -prune \
\) \ \) \
\( -name '*.go' -o -name '*.sh' \) -type f \( -name '*.go' -o -name '*.sh' \) -print0
} }
# Disallow invisible or bidi Unicode codepoints in source files. These are # Disallow invisible or bidi Unicode codepoints in source files. These are
@ -35,7 +35,7 @@ find_files() {
# U+FEFF byte order mark / zero-width no-break space # U+FEFF byte order mark / zero-width no-break space
# U+202A-U+202E bidi explicit formatting # U+202A-U+202E bidi explicit formatting
# U+2066-U+2069 bidi isolates # U+2066-U+2069 bidi isolates
matches=$(find_files | xargs perl -CSD -ne ' matches=$(find_files | xargs -0 perl -CSD -ne '
if (/[\x{200B}-\x{200D}\x{FEFF}\x{202A}-\x{202E}\x{2066}-\x{2069}]/) { if (/[\x{200B}-\x{200D}\x{FEFF}\x{202A}-\x{202E}\x{2066}-\x{2069}]/) {
chomp; chomp;
print "$ARGV:$.: $_\n"; print "$ARGV:$.: $_\n";

Loading…
Cancel
Save