_stamp_event_profile, _stamp_routed_profile, the platform-event handlers' ad-hoc
source.profile / _authorization_profile_home writes and _hm_admit_event's own
ProfileRouteRejected retry each re-derived part of the identity next to
resolve_identity. GatewayAdapterLifecycleMixin._canonicalize is now the single
runner-side call: the per-profile and default message / busy / platform-event
handlers, _admit_primary_source, the adapter auth-check callback and the shared
_handle_message gate all go through it. A rejected route is dropped with the
same disposition on every path; nothing falls through to agent:main.