prepend_unset / client_env_with live beside resolve_passthrough_env so docker and ssh
post-process its output identically. The ssh tests build a real SSHEnvironment under
the existing connection stub instead of a half-initialised __new__ object, so the
production code no longer carries getattr fallbacks for it.
The allowlist → blocklist → .env → secret-scope → unset-names walk was inline in
DockerEnvironment; ssh needed the identical walk, so it lives in
remote_common.resolve_passthrough_env and docker calls it. Behaviour unchanged;
docker's _load_hermes_env_vars binding stays as the test seam.