71aa0d635e
`hermes -p <profile> setup gateway` (and `hermes setup` / `hermes import`) reach the service step through `ensure_gateway_service`, which only knew "is THIS profile's unit running" — a satellite served by the default multiplexer has no unit of its own, so the step printed "Installing the gateway background service ..." and registered a launchd plist / systemd unit that the #97120 start guard then refused, leaving a stray dead service the user had to find and remove by hand (#111958). Route both setup surfaces through one shared predicate: `_served_profile_needs_no_service` wraps `named_profile_served_by_running_multiplexer` (the same probe `profile create`, cron liveness and the run/start/install guards use), prints the "already served" note and returns True so `ensure_gateway_service` and the `hermes gateway setup` wizard (#111962's hunk) skip the install. Default profile and non-multiplex hosts are unchanged. Adds the invariant for the `ensure_gateway_service` path (served → no install, unserved → still installs). Docs: multi-profile-gateways.md names the skipped step. Co-authored-by: kvnloo <7121943+kvnloo@users.noreply.github.com>