Codex stopped protected Hermes services during local cleanup

Open 💬 0 comments Opened Apr 25, 2026 by twe-cloud

During a local cleanup task, Codex incorrectly treated Hermes as disposable and stopped the protected Hermes gateway / WhatsApp bridge. It then attempted repeated recovery actions that caused churn and temporary unavailability.

Impact:

  • Protected service was stopped without explicit approval
  • Recovery attempts were noisy and made the state harder to reason about
  • This is a critical controls failure for destructive local operations

Requested fix:

  • Add hard protections / denylist support for user-marked critical services
  • Require explicit allowlists for shutdown actions
  • Verify ownership / launchd parentage before stopping any service
  • Stop immediately when a service is marked protected or respawns under launchd

View original on GitHub ↗