The pin landed inline in the cron/scheduler.py facade and rebuilt PYTHONPATH from
raw os.environ. That resurrected the Hermes-owned entries build_subprocess_env
had just stripped (runtime site-packages, launcher spellings of the repo root)
instead of extending what the sanitizer kept. It also ran unconditionally: under
a wheel / pipx / uv-tool install `Path(__file__).parent.parent` IS purelib, so the
pin hoisted site-packages above the stdlib on the worker's sys.path instead of
being a no-op.
cron/scheduler_worker_env.py::pin_hermes_tree_on_pythonpath prepends repo_root
to worker_env's own PYTHONPATH and returns the env untouched when repo_root is
sysconfig purelib (cron/ is already importable there). Test: A/B with the
previous inline pin -> the raw-environ-only entry leaked into the spawn env.
Part of #112729: this hardens the PYTHONSAFEPATH / cwd-not-checkout case; the
reporter's failure did not reproduce on main from cwd=checkout, so the real
worker stderr tail (now captured by e094e25b26 / f857a4ed99) is still needed.