The install runs `sudo <pm> ...` in its own session and drained stdout with a
blocking `for line in proc.stdout`; the timeout only `killpg(SIGKILL)`ed the
group. From an unprivileged Hermes that signal reaches the sudo leader but not
the root-owned apt/dnf child, which keeps the pipe's write end open: the drain
never saw EOF, `install_packages` never returned, and the per-profile install
slot stayed taken until the gateway restarted (every later Install click:
"an install is already running").
Now the drain is readiness-polled against the deadline, so it ends on time
regardless of what survived; the group gets SIGTERM (dpkg can finish its
transaction) then SIGKILL after a grace; `install timed out` is streamed to the
pane; the leader is reaped best effort and the slot is released by the
existing finally.
Test: tests/tools/test_bot_desktop_install.py — a stand-in leader whose
grandchild sits in its own session holding our stdout; install_packages must
return within 3 s, report the timeout, and leave the slot claimable (hung
3.0 s on bc36ddb5f9).