Ha! That was exactly it, only more so - thanks to a bug elsewhere, I’d managed to get my pid 1 systemd running with egid=1000, and that broke the groups of every service, snapd included. Not sure how the system worked at all like that, but…
Thanks for the help.