From 80c9e51c9cf849fafdc899bfac0fffa655b0d4dd Mon Sep 17 00:00:00 2001 From: Jeffery Date: Wed, 24 Jun 2026 10:52:00 +0000 Subject: [PATCH] =?UTF-8?q?fix(entrypoint):=20=E5=BC=B7=E5=8C=96=20auth=20?= =?UTF-8?q?=E9=8E=96=E5=AE=9A=E8=88=87=20output=20delimiter?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- entrypoint.sh | 46 +++++++++++++++++++++++++++++++--------------- 1 file changed, 31 insertions(+), 15 deletions(-) diff --git a/entrypoint.sh b/entrypoint.sh index 12537b7..af34afe 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -9,6 +9,7 @@ die() { cleanup() { rm -f "${auth_file:-}" "${auth_path:-}" "${codex_output:-}" + rmdir "${auth_lock:-}" 2>/dev/null || true } trap cleanup EXIT @@ -24,13 +25,13 @@ fi CODEX_HOME="${CODEX_HOME:-/root/.codex}" PROMPT="${PROMPT:-請自我介紹}" mkdir -p "$CODEX_HOME" || die "Unable to create CODEX_HOME." +umask 077 auth_file="$(mktemp "$CODEX_HOME/auth.XXXXXX")" auth_path="$CODEX_HOME/auth.json" +auth_lock="$CODEX_HOME/auth.lock" -if [[ -e "$auth_path" ]]; then - die "Refusing to overwrite existing Codex auth.json." -fi +mkdir "$auth_lock" || die "Unable to lock Codex auth.json." if ! printf '%s\n' "$OAUTH" | base64 -d > "$auth_file"; then die "OAUTH must be valid base64 encoded Codex auth.json." @@ -40,26 +41,41 @@ if ! jq -e 'type == "object"' "$auth_file" >/dev/null; then die "Decoded OAUTH must be a JSON object." fi +if [[ -e "$auth_path" ]]; then + die "Refusing to overwrite existing Codex auth.json." +fi + install -m 600 "$auth_file" "$auth_path" rm -f "$auth_file" codex_output="$(mktemp)" -set +e -codex exec \ - --dangerously-bypass-approvals-and-sandbox \ - --skip-git-repo-check \ - --model "$MODEL" \ - "$PROMPT" 2>&1 | tee "$codex_output" -codex_status="${PIPESTATUS[0]}" -set -e +run_codex() { + set +e + codex exec \ + --dangerously-bypass-approvals-and-sandbox \ + --skip-git-repo-check \ + --model "$MODEL" \ + "$PROMPT" 2>&1 | tee "$codex_output" + local status="${PIPESTATUS[0]}" + set -e + return "$status" +} + +if run_codex; then + codex_status=0 +else + codex_status="$?" +fi if [[ -n "${GITHUB_OUTPUT:-}" ]]; then - if [[ -r /proc/sys/kernel/random/uuid ]]; then - output_delimiter="CODEX_OUTPUT_$(cat /proc/sys/kernel/random/uuid)" - else + while :; do output_delimiter="CODEX_OUTPUT_$(mktemp -u XXXXXXXXXXXXXXXX)" - fi + + if ! grep -qxF "$output_delimiter" "$codex_output"; then + break + fi + done if [[ "$codex_status" -eq 0 ]]; then echo "status=completed" >> "$GITHUB_OUTPUT"