The diagnostic from the last run named the mismatch:
cwd=.../home/.hermes/.desktop-smoke-home HERMES_PYTHON_SRC_ROOT=(unset)
expected=.../home/.hermes/hermes-agent
command=".../hermes-agent/venv/bin/python" "-m" "hermes_cli.main" "serve" ...
The backend was the installation's own venv interpreter; the check inferred the
import root from the process cwd, which the APP owns (the smoke's home), so a
correct backend read as "imports a different source tree".
A captured HERMES_PYTHON_SRC_ROOT stays authoritative (a launcher that bound a
tree still has to match). Without one, accept the launcher cd'ing into the tree
or a command that names it, and only then fail. Unreadable paths count as no
evidence instead of throwing ENOENT. Invariant test covers all three, including
the foreign interpreter that still fails.