3dedff6a12
The source-name strip added alongside the external-source fix ran unconditionally. Outside multiplexing there is no other profile to leak from -- os.environ IS this profile's environment -- so popping those names relied on the routed scope overlay putting each one back, which in turn relies on the per-home snapshot recorded at boot. Correct today, but it made a single-profile child's credentials depend on bookkeeping that has nothing to do with isolation. Guard it the way strip_launch_profile_env guards itself: no multiplexing, no strip. A single-profile no_agent child now keeps a byte-identical env even if a source's snapshot were ever missing. Pinned by a regression that runs a real child with a source-owned name in os.environ and no multiplex context; making the strip unconditional fails it. (cherry picked from commit afa429b30a1c9c9b4c011f7d2426a9f099911596)