resolve_runtime_provider() selects a provider-scoped credential pool and returns
it as runtime["credential_pool"]; oneshot and the gateway hand it to AIAgent, but
acp_adapter/session.py::_make_agent dropped it, so a long-lived ACP process had
_credential_pool=None and could not refresh/rotate on HTTP 401 after OAuth
token expiry — the only recovery was restarting the ACP process (#70292).
Forward the pool by identity like the other surfaces. The pool is already
provider-scoped and its selected entry matches the agent's initial api_key, so
the existing account-isolation guards are preserved rather than bypassed.
Salvaged from PR #70293 (the cherry-pick claimed in #77029 never reached
acp_adapter/session.py); regression test asserts the pool object is retained.
Fixes#70292