The Desktop capabilities panel renders a PostSetupRunner button for any
provider that declares `post_setup`, and spawns `hermes tools post-setup
openai_codex` with stdin=DEVNULL and HERMES_NONINTERACTIVE=1. There the
prompt falls back to its default and a device-code login started with
nobody to complete it. When `is_noninteractive()` the hook now prints
`hermes auth add openai-codex` and returns; the panel already shows the
needs_auth pill.
Also lists `openai_codex` in the `hermes tools post-setup` help.
A/B: new test (HERMES_NONINTERACTIVE=1, login stub fails the test if
called) red before, green after; tests/hermes_cli/test_image_gen_picker.py
11 passed.
Subcommands whose handler was a closure defined inside main() — memory, acp,
tools, insights, skills, pairing, plugins, mcp, claw — have their handler
promoted to a top-level function and their parser block extracted into
hermes_cli/subcommands/<name>.py (build_<name>_parser, injected handler).
These 9 had zero closure-over-main-locals, so promotion is a pure relocation.
acp/mcp parser blocks use the shared add_accept_hooks_flag helper.
main() 1798 -> 954 LOC (71% below the 3297 Phase-2 starting point);
add_parser calls in main.py 89 -> 28.
Deferred: sessions, computer-use, secrets handlers reference <name>_parser
(for a no-subcommand print_help fallback) — left in place to avoid the
_self_parser indirection; minority, low value.
Behavior-neutral: all 9 subcommands' --help (incl nested subactions) byte-
identical to pre-extraction (diff-verified). tests/hermes_cli/ 6519 passed /
0 failed; new test_subcommands_followup.py covers the 9 builders.