Round-2 pre-arm gate findings:
- A named ssh profile's cwd is checked before any host expansion:
_profile_workspace_cwd tries the declared remote cwd first, and
_completion_cwd returns an ssh-bound path raw before expanduser/isdir.
A `terminal.cwd: ~` (or ~/x) no longer resolves to THIS host's home
and gets pinned as the remote workspace.
- _terminal_task_cwd_with_source switches to ssh only for a named ssh
profile; other named backends keep main's process-backend branch, so a
named docker profile under a local launch keeps its "session" cwd
source (docker isolation mounts from it).
- Launch-profile heal/reconcile keeps main's env check and only adds the
config-says-ssh case, so a docker-in-config launch still heals dead
host worktrees as on main.
- _completion_cwd does not fail an explicit client cwd for a deleted
profile (main never resolved the profile on that path).
- One _workspace_cwd(profile_home, raw) validates a picked workspace for
both _set_session_cwd and session.workspace.move.
- The profile-policy helpers live beside their callers in
session_workdir; reuse hermes_cli.config._is_ssh_remote_tilde_cwd.
- session.create resolves the backend only when a cwd was sent.
- Tests write a real profile config.yaml instead of stubbing the backend
helper; pin the "~" case.