Repository navigation
Codex and Hermes never left an intent record, because their edits name the file inside the patch - #71
Merged
Conversation
…e the file inside the patch Hook mode read only tool_input.file_path / path. Codex apply_patch and Hermes patch(mode=patch) send V4A patch text with the paths inside it, relative to the payload's cwd, so the live ledger held 3,689 claude-code records and none from either agent. Parse Add/Update/Move-to targets out of any V4A patch in tool_input; a direct path still wins. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The intent ledger lets a supervised agent vouch for its own writes: the harness calls
aegis.py intent hook <tool>after each file write, and a surface change whose bytes match a record grades LOW instead of HIGH. On this Mac,~/.aegis/intent.jsonlholds 3,689claude-coderecords and zero from Codex or Hermes. Because of that, some agent-config edits those two agents made still alert.There were two reasons, and only one of them was in aegis:
tool_input.file_path/path. Codex'sapply_patchand Hermes'spatch(mode=patch)send V4A patch text and no path field. The files they write are named inside the patch (*** Add File:,*** Update File:,*** Move to:), relative to the payload'scwd.Write|Edit|…, Claude Code's tool names. Codex never calls those, so the hook never fired. Hermes had no entry at all.What
_v4a_patch_paths(text, cwd)collects the files a V4A patch leaves on disk. An Update followed by a Move to records the destination. Delete File is skipped because there is no content to attest. Only line-start markers count, so prose that quotes a marker is not treated as a write._intent_hook_paths(payload)checks the direct path first (Claude Code; Hermeswrite_fileandpatch(mode=replace)). If there isn't one, it reads every V4A patch intool_input: a dict value, a list element (the older Codex["apply_patch", patch]form), or a bare string (Codex freeform).Evidence
patchpayload each attest every written file. The Move to and Delete cases are pinned, and a prose line that mentions a marker yields nothing. Both tests failed before the change and pass after it.custody.jsonl).Not in this PR
Outside the repo, the Codex
hooks.jsonmatcher now includesapply_patch, and Hermesconfig.yamlhas a newpost_tool_callentry. Each agent's own consent gate has to approve the changed hook (Codextrusted_hash, the Hermes shell-hook allowlist). That approval is the operator's, and it happens at the next launch.🤖 Generated with Claude Code