58f6678e6d
When FTS5 index corruption prevents INSERT INTO messages, the gateway accumulates messages in _pending_messages (memory-only). On shutdown, .clear() discards the only surviving copy — permanent user data loss. Changes: - Add gateway/shutdown_flush.py with flush_pending_to_file() and recover_pending_to_db() for two-phase data preservation. - Patch gateway/run.py: flush runner._pending_messages before clear() in _stop_impl_body, and recover on startup after runner.start(). - Patch gateway/platforms/base.py: flush adapter._pending_messages before clear() in the adapter shutdown path. Recovery behavior: - Reads pending JSON files from ~/.hermes/pending_messages/ - Inserts messages into state.db directly - Per-session isolation: one corrupt session doesn't block others - Successful recovery deletes the flush file - Failed recovery re-saves for next startup retry