971d81f892
The pooled worker closure captured the caller's live `messages` list and compress_context explicitly supports plugin/legacy context engines that mutate that list in place — so after a host timeout, a late engine could rewrite the live conversation (roles, ordering, persisted content) concurrently with the resumed turn. The worker now deep-snapshots the transcript on the worker thread before any engine code runs; the caller's list object is never handed to pooled code. Results reach caller-visible state only through the returned value of an ADMITTED commit (the host discards results on timeout/cancel), and durable SessionDB mutation was already gated behind the commit fence. No-op passes map the unchanged snapshot back to the caller's original list so identity-based no-op detection and flush dedup keep working. Document the thread-safety contract for context-engine and memory-provider extension points (they now run on pooled threads) in the module docstring and the context-engine plugin guide. Regression: an in-place-mutating engine plus host timeout proves the caller's live transcript is byte-identical WHILE the worker is still blocked inside the engine (released only after the assertions). PR #76354 review, blocking finding 3 / merge gate 3.