2952dc62bc
Under `gateway.multiplex_profiles`, a Feishu adapter is built and connected inside `_profile_runtime_scope` (HERMES_HOME override + secret scope as contextvars), but two hops started from an EMPTY context and so executed under the LAUNCH profile: - `feishu_comment.handle_drive_comment_event` ran the whole comment AIAgent turn on a bare `loop.run_in_executor(None, ...)`: model/credential resolution raised `UnscopedSecretError` (silent empty reply), or — when the default profile held the same key — used the default profile's config/model/state for a secondary profile's doc. - `FeishuAdapter._connect_websocket` ran the lark WS client on a bare executor thread. The SDK fires every event/card callback on that thread and they hop back to the adapter loop via `run_coroutine_threadsafe`, which copies the CALLER's context — so all pre-handler work (inbound media caching, `.update_response` marker, FEISHU_REACTIONS env, drive comments) ran unscoped. The pending-inbound drainer thread spawned from that callback had the same shape. Carry the scope across each hop with `contextvars.copy_context().run`. For the SDK-owned thread the snapshot is taken once at `_connect_websocket` (inside the profile scope; the restart supervisor task inherits it too), so no per-callback re-scoping is needed. Supersedes the `_submit_on_loop` re-scoping approach of #63962 (nateEc, earliest fix): scoping the WS thread at its source covers every callback without rebuilding the secret scope per call. Co-authored-by: Nathan Shan <nathanielcrush51@gmail.com>