8ebc3d420f
Under multiplex a secondary profile reads FEISHU_GROUP_POLICY from its own secret scope only (deliberate 0.21.3 isolation), so a profile whose .env carries no FEISHU_* policy keys falls back to `allowlist` with an empty FEISHU_ALLOWED_USERS and every human group message is rejected while DMs keep working. That deny was logged only at DEBUG, making it look like the events never arrived (#111420). Keep the scoped read as is — no environ fallthrough. Instead, the first group drop caused by the untouched allowlist default logs once at WARNING naming the chat and the keys to set (FEISHU_GROUP_POLICY / FEISHU_ALLOWED_USERS in the profile's own .env, or group_rules in its config.yaml). Operator-configured denies (populated allowlist, per-chat rule, non-allowlist policy) and later drops stay at DEBUG. The predicate lives in the topical sibling feishu_admission_diagnostics.py. Docs: the Group Message Policy section now states the per-profile read and where to put the keys under a multiplexed gateway. Co-authored-by: bear0328 <bear0328@users.noreply.github.com> Co-authored-by: NanPan <111261006+poijygfdyy@users.noreply.github.com>