fix(gateway): setup.status / setup.runtime_check scope the launch profile under multiplex

`_readiness_check` bound a secret scope only for a named non-launch
profile and used nullcontext for the launch profile. Once the process
multiplexes (`set_multiplex_active(True)`) `get_secret` fails closed, so
the launch profile's `setup.runtime_check` died on the first profile-scoped
read inside `resolve_runtime_provider` (`HERMES_CODEX_BASE_URL` in
`_pool_entry_mode_and_url`, added by b62bb2a3d5) and the Desktop showed
onboarding while sessions — which resolve under
`_session_profile_runtime_scope` — worked fine.

Route the launch profile through the same helper: `profile_home=None`
binds the launch profile's frozen `.env` scope only when multiplexing is
active (`_profile_runtime_scope_tokens` returns None otherwise, keeping
the single-profile `os.environ` fallthrough for systemd / `op run`
injection). The unknown-profile `ok:False` answer is untouched — no
`@_profile_scoped`, whose `_profile_home` raise would turn it into an
error.

Slimmer shape than the PR's `scope_launch_profile` flag: the flag guarded
nothing the helper does not already decide, and setup.status reads the
same `.env`-derived state.

Fixes #112061
This commit is contained in:
KoNit-K
2026-09-15 11:57:59 -07:00
committed by Teknium
parent 57c9e92ae3
commit 5910de20bc
2 changed files with 45 additions and 5 deletions
+6 -5
View File
@@ -248,18 +248,19 @@ def _readiness_check(rid, params, probe):
stay isolated); ``scoped`` is the ``{"profile": ...}`` payload stamp (``{}`` for the launch
profile). An unknown profile answers ``ok=False`` (never a JSON-RPC error, never a quiet answer
for the launch profile instead)."""
import contextlib
profile = str(params.get("profile") or "").strip() if isinstance(params, dict) else ""
scope = contextlib.nullcontext()
home = None
if profile:
from hermes_cli import profiles as profiles_mod
if not profiles_mod.profile_exists(profile):
return _ok(rid, {"ok": False, "profile": params.get("profile"),
"error": f"Profile '{profile}' does not exist on this backend."})
home = _profile_home(profile)
if home is not None:
scope = _session_profile_runtime_scope({"profile_home": str(home)})
with scope:
# ``profile_home=None`` is the launch profile: once this process multiplexes its probe must
# run under its own frozen secret scope too (``_profile_runtime_scope_tokens`` binds nothing in
# a single-profile process), or the first profile-scoped read inside the resolver
# (``HERMES_CODEX_BASE_URL`` for openai-codex) fails closed and the UI shows onboarding.
with _session_profile_runtime_scope({"profile_home": str(home) if home is not None else None}):
payload = probe(profile, {"profile": profile} if profile else {})
return _ok(rid, payload)