26fb8f60e6
Follow-up to the salvaged #92689: - _profile_export_directory() now proves safety on the export dir's OWN ancestry (_inside_git_checkout) instead of walking Path.cwd(). The old heuristic missed the checkout whenever HERMES_HOME sat inside one but the process ran from elsewhere (cron, service manager) — the export landed back inside the source tree, the exact incident class. - When every candidate is inside a checkout, warn instead of silently violating the invariant. - CLI/TUI export callers: move get_profile_export_path() inside the try and catch OSError too — a bad profile name or read-only home printed a raw traceback instead of the clean error main previously gave. - Tests: bind module objects at call time (importlib) so sibling reload pollution in the tests/hermes_cli sweep can't divorce monkeypatches from the code under test; add regression tests for the cwd-independent topology and the clean-error path. - Docs: mention the ~/.hermes-profile-exports fallback store.