Files
John T. MyersandJohn Myers 4d16a2a6f4 feat(gator): improve review output and launch compatibility (#2896)
* feat(gator): render human-readable review findings

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* feat(gator): collapse operational review metadata

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(gator): support canonical sandbox startup

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(gator): preserve credential placeholder identity

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* feat(gator): resolve addressed review threads

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(agents): preserve provider profile revisions

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Co-authored-by: John Myers <johntmyers@users.noreply.github.com>
2026-08-25 19:59:04 +00:00

101 lines
2.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
set -euo pipefail
if [[ $# -ne 1 ]]; then
echo "usage: exec.sh <prompt-file>" >&2
exit 2
fi
require_env() {
local name="$1"
[[ -n "${!name:-}" ]] || { echo "missing required env: $name" >&2; exit 1; }
}
require_env CODEX_AUTH_ACCESS_TOKEN
require_env CODEX_AUTH_ACCOUNT_ID
require_env GITHUB_TOKEN
PROMPT_FILE="$1"
export GH_TOKEN="$GITHUB_TOKEN"
export GH_PROMPT_DISABLED=1
export GH_NO_UPDATE_NOTIFIER=1
export GH_NO_EXTENSION_UPDATE_NOTIFIER=1
export GH_TELEMETRY=false
export DO_NOT_TRACK=1
export HOME="${OPENSHELL_AGENT_HOME:-/sandbox/home}"
echo "openshell-agent: preparing Codex harness auth and workspace" >&2
mkdir -p "$HOME/.codex"
node - <<'NODE'
const fs = require("fs");
const path = `${process.env.HOME}/.codex/auth.json`;
const b64u = (obj) => Buffer.from(JSON.stringify(obj)).toString("base64url");
// Preserve gateway-issued revision and stable-handle placeholders verbatim.
// Endpoint-bound credentials reject identityless aliases by design.
const providerValue = (envName) => process.env[envName];
const now = Math.floor(Date.now() / 1000);
const fallbackIdToken = [
b64u({ alg: "none", typ: "JWT" }),
b64u({
iss: "https://auth.openai.com",
aud: "codex",
sub: "openshell-agent",
email: "agent@openshell.local",
iat: now,
exp: now + 3600,
}),
"placeholder",
].join(".");
fs.writeFileSync(path, JSON.stringify({
auth_mode: "chatgpt",
OPENAI_API_KEY: null,
tokens: {
id_token: providerValue("CODEX_AUTH_ID_TOKEN") || fallbackIdToken,
access_token: providerValue("CODEX_AUTH_ACCESS_TOKEN"),
refresh_token: providerValue("CODEX_AUTH_REFRESH_TOKEN") || "gateway-managed-refresh-token",
account_id: providerValue("CODEX_AUTH_ACCOUNT_ID"),
},
last_refresh: new Date().toISOString(),
}, null, 2));
NODE
chmod 600 "$HOME/.codex/auth.json"
WORK="$(mktemp -d)"
cd "$WORK"
CODEX_BIN="${CODEX_BIN:-codex}"
ADAPTER_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
PAYLOAD_DIR="$(cd "$ADAPTER_DIR/../../.." && pwd)"
if [[ -x "$PAYLOAD_DIR/runtime/harnesses/codex/codex" ]]; then
CODEX_BIN="$PAYLOAD_DIR/runtime/harnesses/codex/codex"
fi
CODEX_MODEL="${CODEX_MODEL:-gpt-5.5}"
CODEX_REASONING="${CODEX_REASONING:-high}"
echo "openshell-agent: invoking Codex bounded cycle (model=$CODEX_MODEL, reasoning=$CODEX_REASONING)" >&2
CODEX_EXEC_ARGS=(
exec
--skip-git-repo-check
--sandbox danger-full-access
--ephemeral
)
if "$CODEX_BIN" exec --help 2>/dev/null | grep -q -- "--ignore-user-config"; then
CODEX_EXEC_ARGS+=(--ignore-user-config)
fi
if "$CODEX_BIN" exec --help 2>/dev/null | grep -q -- "--ignore-rules"; then
CODEX_EXEC_ARGS+=(--ignore-rules)
fi
exec "$CODEX_BIN" "${CODEX_EXEC_ARGS[@]}" \
-c "model=\"${CODEX_MODEL}\"" \
-c "model_reasoning_effort=\"${CODEX_REASONING}\"" \
- \
< "$PROMPT_FILE"