3ef1c4200b
#69090 scoped MATRIX_RECOVERY_KEY itself (via _scoped_recovery_key()) so a secondary profile resolves its own recovery key under multiplex, but left its sibling, MATRIX_RECOVERY_KEY_OUTPUT_FILE, on a bare os.getenv(). _recovery_key_output_path() is called from inside _verify_or_bootstrap_cross_signing(), which runs fully inside _profile_runtime_scope for a secondary profile: when that profile bootstraps a new recovery key, it either doesn't get written to a file at all, or gets written to the default profile's configured path, depending on which one has the env var set. Route it through the same _get_scoped_secret() helper _scoped_recovery_key() already uses. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> (cherry picked from commit fb765ee49b2f1a1853e52fb901d25f767180a2fc)