Desktop's in-process gateway runs on the user's OS. On a Windows host with an ssh/docker
terminal backend, os.path arithmetic in _dir_listing_items turned the search dir into a
backslash path (`ws` + `sub/` -> `ws\sub`, `/tmp/x/` -> `\tmp\x`) that the backend's POSIX
listing script cannot resolve, so every non-local completion came back empty. The non-local
branch now uses posixpath for join/normpath/dirname/basename/relpath — the backend always
speaks POSIX regardless of the host.
Also: complete.path takes params['cwd'] (the session cwd Desktop's composer sends) as the
backend root when supplied instead of ignoring it on non-local backends, and the per-keystroke
backend listing waits at most 3s instead of 10s so a slow remote does not pin a pool worker.
Review follow-up on #113144.