c012a364eb
The speak-stream WebSocket resolved its URL through the bare v1 getConnection/getGatewayWsUrl pair, which answers for the PRIMARY backend. When a registry remote connection rides over a machine that also has a local Hermes install (the common case — the installer always installs the full agent), spoken replies dialed the LOCAL backend and hit its unconfigured TTS, while chat (connectionScoped REST) correctly went remote. Users saw 'configure STT/TTS' although their remote gateway had voice fully configured. Resolve the PCM socket through the same (connectionId, profile) bridges store/gateway's openSecondary uses, and never overwrite a backend-namespace profile the registry mint already wrote into the URL (SSH remoteProfile aliasing, sharedRemote scoping). Every REST audio call already carried connectionScoped(); this was the one remaining self-built audio URL. Contract pinned by voice-playback.routing.test.ts (sabotage-verified: 2/4 fail on the old resolver).