Once a `serve` backend hosts a second profile home, get_secret() fails closed for any
body with no secret scope installed. Two off-turn paths rebuilt the system prompt with
only HERMES_HOME bound (or nothing at all), so the external memory provider's
system_prompt_block() -> get_secret("OPENVIKING_API_KEY") raised UnscopedSecretError
and the launch profile lost its memory block:
- `session.context_breakdown` (tui_gateway/methods_session.py): the Desktop status bar
refetches it after every turn, which is the once-per-turn warning in #112927; it also
resolved a secondary session's provider credential and home from the launch profile.
- `_persist_live_session_system_prompt` (tui_gateway/server.py): model switch / one-turn
restore re-persist. Bound HERMES_HOME alone (#50233); now the full runtime scope.
Both now enter `_session_profile_runtime_scope(session)` (home + secrets + terminal
policy, the launch profile's frozen scope when profile_home is None), the same binding
the turn itself uses. config.show is scoped in the salvaged commits before this one.
Regression (red on base): tests/tui_gateway/test_multi_profile_hosting_fail_closed.py::
test_off_turn_prompt_rebuilds_run_under_the_sessions_profile_scope — A->B->A over two
homes, each rebuild sees its own home and MEM_PROVIDER_KEY, os.environ untouched.
Refs #112927