0fd59b447a
_launch_external_cron_worker wrapped fifty lines of dispatch, payload write and scope hydration in the routed-fire multiplex context, though only build_subprocess_env / strip_launch_profile_env read it. Compute `multiplex_active` once (process flag OR routed fire), serialize it into the payload, and set the context for exactly the env build inside the existing secret-scope try/finally. Drop restore_managed_env on this path: the worker re-runs load_hermes_dotenv -> _apply_managed_env at import and strip_launch_profile_env already leaves managed keys in place. _run_job_script now overlays the installed scope and re-applies managed keys only under multiplex. In a single-profile process the scope is os.environ, so the overlay could only re-sanitize values the child already inherits; the "no-op outside multiplex" comment is now literal.