d3e2ace1dd
`hermes profile delete` read the target profile's gateway.pid raw and SIGTERMed it. When that pid file was poisoned by a sibling profile's gateway (the #89315 shape), deleting profile A killed profile B's running gateway. - gateway/status.py: `_pid_record_belongs_to_profile()` helper — a pid record whose recorded home differs from the expected profile home is not ours; legacy records without a home prove nothing and are left alone. - hermes_cli/profiles.py: `_stop_gateway_process` refuses (and says so) when the record belongs to another profile; still stops its own gateway. The stop/restart paths in hermes_cli/gateway.py did not need a guard: `get_running_pid()` already filters cross-profile records and unlinks the poisoned pid file before any kill can happen — verified live; the test for that path now pins the real contract (returns False, other process alive, poisoned pid file gone). Live repro (unpatched main): `_stop_gateway_process(tim_home)` -> "Gateway stopped (PID ...)" and the OTHER profile's process exits -15. After: "Refusing to stop PID ..." and the process stays alive. 8 tests; sabotage (guard removed) fails 1.