28138f2524
Under gateway.multiplex_profiles the routed handler runs inside _profile_runtime_scope, but the adapter's delivery side (_process_message_background -> _extract_response_content, weixin's own send()) extracts and validates the reply's MEDIA: / bare-path attachments after that scope was reset. Docker translation in platforms/base.py (_docker_sandbox_dir_candidates via get_active_profile_name, _parse_docker_volume_mounts via the scope-aware TERMINAL_DOCKER_VOLUMES) therefore resolved a secondary's /output or /root path against the DEFAULT profile's sandbox and mounts: dropped as "not found on this host", or a same-named file from the default's mount delivered instead (#109024). Add GatewayRunner._media_delivery_scope_for_source (home + terminal policy, no secret hydration: path validation reads no credentials and runs on the loop) and enter it from BasePlatformAdapter._media_delivery_scope around the two extraction sites that run outside the turn scope. The streamed path (_deliver_media_from_response), the background task and cron delivery already run inside their profile scope. Co-authored-by: joaomarcos <joaomarcosdias444@gmail.com>