Under `gateway.multiplex_profiles`, a Feishu adapter is built and connected inside
`_profile_runtime_scope` (HERMES_HOME override + secret scope as contextvars), but two
hops started from an EMPTY context and so executed under the LAUNCH profile:
- `feishu_comment.handle_drive_comment_event` ran the whole comment AIAgent turn on a bare
`loop.run_in_executor(None, ...)`: model/credential resolution raised
`UnscopedSecretError` (silent empty reply), or — when the default profile held the same
key — used the default profile's config/model/state for a secondary profile's doc.
- `FeishuAdapter._connect_websocket` ran the lark WS client on a bare executor thread. The
SDK fires every event/card callback on that thread and they hop back to the adapter loop via
`run_coroutine_threadsafe`, which copies the CALLER's context — so all pre-handler work
(inbound media caching, `.update_response` marker, FEISHU_REACTIONS env, drive comments)
ran unscoped. The pending-inbound drainer thread spawned from that callback had the same
shape.
Carry the scope across each hop with `contextvars.copy_context().run`. For the SDK-owned
thread the snapshot is taken once at `_connect_websocket` (inside the profile scope; the
restart supervisor task inherits it too), so no per-callback re-scoping is needed.
Supersedes the `_submit_on_loop` re-scoping approach of #63962 (nateEc, earliest fix):
scoping the WS thread at its source covers every callback without rebuilding the secret
scope per call.
Co-authored-by: Nathan Shan <nathanielcrush51@gmail.com>