def6d6fe1b
Asserts the behavior contract that run_one_job installs a profile secret scope around run_job under multiplexing (so resolve_runtime_provider's get_secret does not fail-close with UnscopedSecretError) and tears it down afterward. Mutation-verified: fails on unmodified main with the exact UnscopedSecretError, passes with the fix.