Files
deepseek-harness/packages/hooks/hooks-codex/README.md
T
Tianyi Cui 774d460889 Expose audited hardcoded tunables as plugin config
The audit swept every packages/*/* plugin for the new AGENTS.md
convention (no hardcoded tunables in plugins) and exposes each finding
as a defaulted, validated Config field. Defaults are the previously
hardcoded values throughout, so no deployment or golden changes.

- tool-fs (had NO Config): readLimit, readMaxLineLength, readMaxBytes,
  readStreamMinSize. The caps thread through ReadToolCaps/ReadWindow —
  read-render already documented that the consumer applies the caps, so
  they become explicit per-request fields.
- tool-web: searchMaxResults (WEB_SEARCH_MAX_RESULTS stays as the
  schemastery default). Also fixes the stale GREP_LIMIT references in
  search.ts and the web-capability-seam RFC (no such constant exists).
- bash-local: graceMs (SIGTERM->SIGKILL escalation grace). The
  RunInternals.graceMs test seam is gone: graceMs is now a required
  SpawnSpec field filled from config, so tests exercise the real
  config path and the defaults live in exactly one place.
- subagent-acp: disposeEofGraceMs / disposeGraceMs. The AcpRunSpec
  fields become required for the same one-defaulting-layer reason.
- session-persistence-sqlite: journalMode ('wal' default; the
  rollback-journal modes serve filesystems where WAL's shared-memory
  files do not work, e.g. network mounts).
- hooks-claude + hooks-codex: stderrSummaryMaxChars for the persisted
  hook/result stderr summary. The duplicated summarize() helpers merge
  into hook-protocol's summarizeStderr(stderr, maxChars), beside the
  HookResultRecord field it feeds, with the bound parameterized the
  same way runHook's defaultTimeoutMs already is.
- compact-basic: charsPerToken for the token estimator (default 4, the
  English-text heuristic; CJK-heavy deployments need ~1-2 or compaction
  fires far too late). Also corrects the BasicCompactService class doc,
  which claimed defaults the required-field config never had.
- fs-local: deletes the dead STREAM_MIN_SIZE constant and the dead
  FsIoInternals.streamMinSize seam — the read-routing bound lives in
  the consumer (tool-fs), where it is now config. This is item 1 of
  the proposed prune-write-only-fs-surface RFC, annotated accordingly.

Every new field gets range validation (following the existing
assertPositiveFinite pattern), a README row, and tests covering the
configured behavior, the schema default, and load-time rejection.
2026-07-04 17:37:23 +08:00

4.3 KiB

@deepseek-ai/dsh-hooks-codex

A cordis plugin that runs a user's existing Codex hooks.json on the harness's canonical interception seams. The Codex dialect half of the hooks subsystem. The dialect-agnostic primitives come from @deepseek-ai/dsh-hook-protocol; this bridge owns the Codex-specific payloads, matcher mode, and decision mapping.

Codex's hook protocol is a deliberate subset of Claude Code's (same hooks.json shape):

  • Five hook points only: PreToolUse, PostToolUse, SessionStart, UserPromptSubmit, Stop — no subagent / notification / compaction hooks.
  • Regex-only matchers (no literal fast path; the matcher is always an unanchored regex).
  • snake_case stdin payloads with turn_id/model extras, written without a trailing newline.
  • No env vars and no command substitution (a literal ${…} in a command survives verbatim).
  • A block-only decision modelallow/ask are not honored; a hook can only block, never pre-approve.

A native cordis plugin could do everything this bridge does, more powerfully; the bridge exists only to run UNMODIFIED external Codex hooks faithfully (see the interception-seams RFC).

Config

import type { Config } from '@deepseek-ai/dsh-hooks-codex'
const config: Config = {
  configPath: '/path/to/.codex/hooks.json', // required
  model: 'deepseek-v4',                      // optional: stamped on every payload (Codex includes `model`)
  defaultTimeoutMs: 600_000,                 // optional: per-hook timeout when a hook sets none
  stderrSummaryMaxChars: 500,                // optional: char cap on the hook/result event's persisted stderr summary
}

In a cordis.yml:

- dsh-hooks-codex:
    configPath: ./.codex/hooks.json
    model: deepseek-v4

The config is parsed once at load. configPath is process-level — a relative path resolves against the process launch cwd at load time, not per-session (TODO(per-session-hook-config)). A read/parse failure is contained (logs + registers nothing). Only sync type: 'command' hooks run — a non-command or async: true hook is parsed-and-skipped with a warning. A hook accepts timeout or the timeoutSec alias. Events outside the five Codex points are dropped at parse.

The hooks themselves run in the agent's session workspace: for the agent-scoped points the bridge passes the session's cwd as the hook process's working directory, so a hook operates in the user's project tree, not the server launch dir.

Hook points → seam Decisions

Codex hook Harness seam Mapping
SessionStart agent/session-start (emit) a plain-stdout hook's output → additionalContext → agent.inject()
UserPromptSubmit agent/prompt-submit (waterfall) block (exit 2) → PromptDecision.block; additionalContext-only → delegate via next() then fold context onto the downstream decision
PreToolUse tools/pre-execute (waterfall) blockPreToolDecision.deny (no allow/ask)
PostToolUse tools/post-execute (waterfall) blockblock with feedback; additionalContext-only → delegate via next() then fold context onto the downstream decision
Stop agent/turn-continuation (waterfall) a blocking Stop hook forces continue with the reason as next-step steering

A tool call's payload carries the real tool_name (the same value the matcher tests) and Codex's tool_input: { command } shape (the command arg when present, else ''). The matcher subject is the tool name (PreToolUse/PostToolUse) or the session source (SessionStart); UserPromptSubmit/Stop ignore matchers.

Context source

Injected context carries an explicit { kind: 'plugin', plugin: 'hooks-codex' } source (agent.inject() would otherwise default it to { kind: 'user' }).

Deferred

Stop loop-guard (TODO(stop-loop-guard)): as in CC, a Stop hook that unconditionally blocks would force-continue every step (stop_hook_active is always false here); the loop-guard is deferred. A hook author must self-limit until it lands.

systemMessage: a hook's user-facing warning is logged + warned, not surfaced — there is no user-message channel on these seams yet (only model-facing additionalContext).