6bd29f26f6
Codex refresh tokens are single-use with rotation-family reuse detection. _save_codex_tokens resolved the state via the profile's root fallback but always persisted into the ACTIVE (profile) store, so a profile-scoped refresh left the global store holding the consumed refresh token — the next process to read it replayed it and OpenAI revoked the whole rotation family, forcing a manual device-code re-auth (#87503; observed four times on one multi-profile deployment). Mirror the xAI source-aware save (#43589/#74339): resolve the state with _load_provider_state_with_source; when the grant came from the global root, write the rotated chain back to root only — singleton AND credential_pool entries, under the root store's own lock, without creating a shadowing profile key. Best-effort, with the same pytest seat belt as the xAI path. Fixes #87503