Codex stopped protected Hermes services during local cleanup
Open 💬 0 comments Opened Apr 25, 2026 by twe-cloud
During a local cleanup task, Codex incorrectly treated Hermes as disposable and stopped the protected Hermes gateway / WhatsApp bridge. It then attempted repeated recovery actions that caused churn and temporary unavailability.
Impact:
- Protected service was stopped without explicit approval
- Recovery attempts were noisy and made the state harder to reason about
- This is a critical controls failure for destructive local operations
Requested fix:
- Add hard protections / denylist support for user-marked critical services
- Require explicit allowlists for shutdown actions
- Verify ownership / launchd parentage before stopping any service
- Stop immediately when a service is marked protected or respawns under launchd