← Files Codex SecurityARCHIVED FILE

scripts/launch_codex_security_mcp

1.75 KB · Oct 7, 2026 · 06:02 UTC

↓ Download file

See the change to this file →

#!/bin/sh
set -eu

PATH="${PATH:-/usr/bin:/bin}:/opt/homebrew/bin:/usr/local/bin:/usr/bin:/bin"
export PATH

launcher_dir=$(CDPATH= cd "$(dirname "$0")" && pwd)
server_path=$launcher_dir/../mcp/server.mjs
if [ "${1:-}" = "--helper" ]; then
  server_path=$launcher_dir/../mcp/helpers.mjs
fi
launch_node() {
  node_command=$1
  shift
  if [ "${1:-}" = "--helper" ]; then
    shift
    # Preserve POSIX argv and HOME bytes without temporary files or consuming stdin.
    exec 4<&0
    wait_helper() {
      if wait "$!" 2>&-; then exit 0; else exit $?; fi
    }
    forward_signal() {
      if [ -n "${!:-}" ]; then
        kill -s "$1" "$!" 2>&- || :
        wait_helper
      fi
      exit "$2"
    }
    trap 'forward_signal HUP 129' HUP
    trap 'forward_signal INT 130' INT
    trap 'forward_signal TERM 143' TERM
    printf '%s\000' "${HOME+x}" "${HOME-}" "$@" | od -An -v -tx1 | tr -d ' \n' |
      "$node_command" "$server_path" --helper 3<&0 0<&4 4<&- &
    exec 4<&-
    wait_helper
  fi
  exec "$node_command" "$server_path" "$@"
}

cache_root=${XDG_CACHE_HOME:-${HOME:-}/.cache}
codex_resources=
case "${CODEX_CLI_PATH:-}" in
  */*) codex_resources=${CODEX_CLI_PATH%/*} ;;
esac

for candidate in \
  "${CODEX_MCP_NODE_PATH:-}" \
  "${CODEX_BROWSER_USE_NODE_PATH:-}" \
  "${CODEX_ELECTRON_RESOURCES_PATH:-}/cua_node/bin/node" \
  "$codex_resources/cua_node/bin/node" \
  "$cache_root/codex-runtimes/codex-primary-runtime/dependencies/node/bin/node"
do
  if [ -n "$candidate" ] && [ -x "$candidate" ]; then
    launch_node "$candidate" "$@"
  fi
done

if node_path=$(command -v node); then
  launch_node "$node_path" "$@"
fi

printf '%s\n' 'Codex Security could not find a Node runtime. Reinstall or update Codex, or set CODEX_MCP_NODE_PATH to an executable Node runtime.' >&2
exit 127

SHA-256: 56794e736a1e8f588f9959a2e707ea3ed9bc7d4d2b796c132e91d5fbed59e600