Files
hermes-agent/website/docs/reference
Siddharth Balyan 333898b353 feat: setup profile sessions get the setup toolset by profile role; nothing else can grant it (#119491)
The setup toolset (empty until NS-964 registers request_catalog_install)
is reserved for the profile whose backend-written profile.yaml carries
role: setup. Two points enforce it:

- Grant: tui_gateway/server.py::_load_enabled_toolsets folds the in-scope
  profile's role toolsets into all three return paths (configured CLI
  toolsets, coding posture, HERMES_TUI_TOOLSETS pin), next to the
  client-surface set. The pin keeps it too: an operator pin picks
  configurable toolsets and must not strip the profile's own.
- Deny: model_tools._select_tool_names strips toolsets reserved for any
  other role from every selection, including None/"all", a saved
  platform_toolsets list, profiles.configure and the env pin. That is the
  one point every surface's selection passes, so a default session cannot
  get the tool by any route.

The role is read with read_profile_meta on get_hermes_home(), which under a
session's home override is that session's profile dir (no directory scan).
setup stays out of _HERMES_CORE_TOOLS, CONFIGURABLE_TOOLSETS and the
platform-native recovery loop (it has no tools, so the loop skips it).

Linear NS-963.
2026-09-23 02:27:53 +05:30
..