8d9684c9da
`hermes profile export default` crashed with `shutil.Error` when HERMES_HOME pointed outside ~/.hermes (common in Docker deployments) and the workspace contained broken symlinks. Two root causes: 1. `copytree` defaults to `symlinks=False` and follows link targets; broken ones crash. #58397 (liuhao1024) drafted a minimal `symlinks=True` flag fix; this PR adopts that change. 2. `copytree` was invoked against the entire HERMES_HOME root (which doubles as cwd in Docker layouts). The post-hoc blacklist at `_DEFAULT_EXPORT_EXCLUDE_ROOT` is a fixed-length enumerate-and-pray list that can't anticipate every unrelated sibling directory (`x11-dev/`, etc.). Replaced with a positive allow-list at `_DEFAULT_EXPORT_INCLUDE_ROOT` enumerating the known Hermes profile artifacts (config, persona, skills, cron, scripts, sessions, plugins, memories, knowledge, preferences). Sensitive runtime surfaces (`state.db`, `logs/`, auth files, other profiles) are intentionally not in the allow-list so the export stays a portable, credential-free snapshot of the user-facing surface — which means the existing `test_export_default_excludes_infrastructure` regressions remain green. Adds two regression tests: * test_export_default_uses_allowlist_for_unrelated_dirs — >x11-dev< sibling directories must not leak into the archive. * test_export_default_handles_broken_symlinks — symlinks inside allowed artifacts survive instead of crashing the export. closing that PR as superseded once this lands. Closes #58394