ca6b189a7c
Review follow-ups on the refresh transaction: - `_provider_state_transaction` takes a `timeout_seconds` applied to BOTH the active and the root lock. The refresh passes max(default, refresh timeout + 5 s); before, only the profile lock used that budget and root's lock kept the 15 s default, so the waiting profile raised TimeoutError instead of adopting whenever the peer's POST ran long. The regression test now holds the endpoint past the lock floor and fails without the passthrough. - Peer adoption requires a stored access token as well as a rotated refresh token; an incomplete stored pair falls through to the refresh. - `_save_codex_tokens` keeps its body: the per-path lock is reentrant, so the refresh calls it inside the open transaction (as the CLI-recovery path already did) instead of a split-out helper.