336227bf00
Reshape of the cherry-picked fix from #104194: - The SOUL.md gate + `register_profile_gateway(start_now=False)` now live in `hermes_cli/service_manager.py::register_unregistered_profile_gateway`, next to the s6 manager and `_profile_dir_for_gateway_service` it needs, instead of a private reach-in from the 6.5k-line `hermes_cli/gateway.py` facade. The facade only decides "start repairs, stop/restart re-raise" and keeps ONE error handler (S6Error is a RuntimeError; register's ValueError/RuntimeError/OSError surface as the same `✗` + exit 1). - Tests trimmed from four to two invariants: start on a real profile registers `down` and then starts; stop on an unregistered profile / start on a directory without SOUL.md keep the original error and mint nothing (parametrized). Dropped: the registration-failure traceback test (covered by the single except clause) and the duplicate no-marker/stop split. The test now resolves the profile dir through the real HERMES_HOME mapping instead of monkeypatching `_profile_dir_for_gateway_service`. - Docs: docker.md multi-profile section says `gateway start` inside the container registers a slot for a profile created from the host.