Review findings on the assignee-login gate (#122689):
- MAJOR: served_profile_child_env(inherit_credentials=True) overlays only the
assignee's own GH_TOKEN/GH_CONFIG_DIR but HOME/XDG_CONFIG_HOME stay the
launch process's, so a profile with no login of its own fell through to
~/.config/gh/hosts.yml - the ambient login the gate promises never to use.
For a routed assignee home with neither token nor config dir, pin
GH_CONFIG_DIR to <profile_home>/gh; gh then exits 4 (authentication
required), which _api classifies as auth naming the profile.
- MINOR (a): an ASSIGNED card whose profile cannot be resolved was fail-open
(env=None -> completing process's full ambient login). Resolution now
happens inside collect_acceptance and raises _GateAuthError naming the
profile; only genuinely unassigned cards keep the ambient path.
- MINOR (c): Codex refresh 200/non-JSON body no longer sets relogin_required,
so the new exit-78 startup gate cannot turn an edge misfire into a sticky
terminal block (invalid_json_relogin=False, as xAI already does).
- MINOR (b)+(d) docs: GH_TOKEN must live in the profile's .env/secret source
(a shell/systemd export is scrubbed); skipped_nonspawnable {assignee} row
in the worker telemetry table; startup relogin-required failure exits 78.