Files
hermes-agent/tests
teknium1 4e2bd09229 fix(gateway): adopt a bare legacy user unit that pins this custom HERMES_HOME (#109476)
After the native-identity change for custom roots (#105525 / PR #106611) a
custom HERMES_HOME names its service `hermes-gateway-<8hex>`, but an install
made before that change left the bare `hermes-gateway.service` user unit
pinning that same root. `_systemd_unit_installed()` only probed the recomputed
name, so `gateway restart/stop/status` saw no unit: `restart` fell through to a
foreground `run_gateway()` while the still-enabled legacy unit's Restart=always
looped on the instance lock ("Gateway already running") and the shell hung on
the foreground gateway.

`_bare_unit_pinned_home()` already made an installed bare SYSTEM unit the
naming authority for root; the user scope now does the same with its own bare
USER unit. A unit whose pinned HERMES_HOME resolves to this home is this home's
service whatever it is named, so every lifecycle command (restart, stop, status,
install-in-place, uninstall) discovers and adopts it. The match is exact-home
only: a bare unit pinning another home — including the production default from
a temp-home harness — still yields this home's own suffix, and an unprivileged
process never reads the system unit (the profile-aliasing hazard the root gate
existed for).

No new legacy name is added to `_LEGACY_SERVICE_NAMES`: that sweep removes
units, and the bare unit is the correct unit for a default home.

WHEN L5 (lifecycle commands run against an env-bound home) / WHERE T4 (user systemd unit), T1.

(cherry picked from commit 037ff16bea7d1e4ce513543ebd14320ccf49b1a3)
2026-09-28 04:04:23 -07:00
..