#!/bin/bash set -eo pipefail die() { echo "$1" >&2 exit 1 } cleanup() { rm -f "${auth_file:-}" "${auth_path:-}" "${codex_output:-}" rmdir "${auth_lock:-}" 2>/dev/null || true } trap cleanup EXIT if [[ -z "${OAUTH:-}" ]]; then die "OAUTH is required: provide base64 encoded Codex auth.json." fi if [[ -z "${MODEL:-}" ]]; then die "MODEL is required." fi CODEX_HOME="${CODEX_HOME:-/root/.codex}" PROMPT="${PROMPT:-請自我介紹}" mkdir -p "$CODEX_HOME" || die "Unable to create CODEX_HOME." umask 077 auth_file="$(mktemp "$CODEX_HOME/auth.XXXXXX")" auth_path="$CODEX_HOME/auth.json" auth_lock="$CODEX_HOME/auth.lock" mkdir "$auth_lock" || die "Unable to lock Codex auth.json." if ! printf '%s\n' "$OAUTH" | base64 -d > "$auth_file"; then die "OAUTH must be valid base64 encoded Codex auth.json." fi if ! jq -e 'type == "object"' "$auth_file" >/dev/null; then die "Decoded OAUTH must be a JSON object." fi if [[ -e "$auth_path" ]]; then die "Refusing to overwrite existing Codex auth.json." fi install -m 600 "$auth_file" "$auth_path" rm -f "$auth_file" codex_output="$(mktemp)" run_codex() { set +e codex exec \ --dangerously-bypass-approvals-and-sandbox \ --skip-git-repo-check \ --model "$MODEL" \ "$PROMPT" 2>&1 | tee "$codex_output" local status="${PIPESTATUS[0]}" set -e return "$status" } if run_codex; then codex_status=0 else codex_status="$?" fi if [[ -n "${GITHUB_OUTPUT:-}" ]]; then while :; do output_delimiter="CODEX_OUTPUT_$(mktemp -u XXXXXXXXXXXXXXXX)" if ! grep -qxF "$output_delimiter" "$codex_output"; then break fi done if [[ "$codex_status" -eq 0 ]]; then echo "status=completed" >> "$GITHUB_OUTPUT" else echo "status=failed" >> "$GITHUB_OUTPUT" fi { echo "output<<$output_delimiter" cat "$codex_output" echo "$output_delimiter" } >> "$GITHUB_OUTPUT" fi exit "$codex_status"