On Linux, Electron's safeStorage requires the --password-store Chromium
switch to select the correct keychain backend. Without it,
isEncryptionAvailable() returns false, hardening.ts refuses to persist
remote gateway tokens, and users are forced back to the
HERMES_DESKTOP_REMOTE_URL / HERMES_DESKTOP_REMOTE_TOKEN env fallback.
- hermes_cli/main.py: _detect_linux_password_store() probes KDE session
env vars, GNOME Keyring's control socket, then a D-Bus ping of
org.freedesktop.secrets (covers any Secret Service implementation,
e.g. KeePassXC). The result is bridged into the desktop subprocess env
as HERMES_DESKTOP_PASSWORD_STORE for both source and packaged launches.
- The user override lives in config.yaml (desktop.password_store,
default "auto") rather than a new user-facing HERMES_* env var, per
AGENTS.md. An explicit HERMES_DESKTOP_PASSWORD_STORE env var still
wins over config and detection, matching desktop.disable_gpu
semantics.
- apps/desktop/electron/bootstrap-platform.ts:
resolveLinuxPasswordStore() validates the bridged value; main.ts
applies it via app.commandLine.appendSwitch('password-store', ...)
before app ready. Unknown values log a warning and are skipped.
- Tests: detector + bridging coverage (packaged and source launch
paths, config override, env-var precedence, linux-only gating) in
tests/hermes_cli/test_gui_command.py; resolver coverage in
bootstrap-platform.test.ts (vitest electron project).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>