7a86397a46
Port the run-ownership invariants from PR #93747 onto main's `_run_owners` model in gateway/platforms/api_server_runs.py: - `_request_owns_run` no longer admits run state that exists without an owner stamp. Under gateway.multiplex_profiles every served profile holds a valid key, so the "backward compatibility" branch made the boundary allow-all whenever provenance was missing. Unstamped state now fails closed; only an in-memory owner match or a durable idempotency record under the caller's own scope admits a run. - POST /api/sessions/{id}/chat/stream claims `_run_owners` at the run mint, inside the request's profile scope, so its run is confined to the creating profile like /v1/runs. - Owner release is tied to "no run-keyed state survives" (`_release_run_owner_if_forgotten`) and runs at every retirement point (task finally, SSE stream close, both sweep loops, chat-stream finally), not only the terminal-status sweep — no stranded entries, no stateful id ever left unowned. Docs: note that runs are per-profile scoped (replaces the now-false visibility admonition proposed in PR #92822). Fixes #93689 Fixes #90415 Supersedes #93747, #93704, #92822 Co-authored-by: RickyYii <237135932+RickyYii@users.noreply.github.com> Co-authored-by: liuhao1024 <11816344+liuhao1024@users.noreply.github.com>