0aecadc17c
Phase 2 core slice of #91277: the updater now knows WHAT it is operating on before it mutates anything. - hermes_cli/update_inventory.py (new): side-effect-free runtime inventory — install kind via detect_install_method (git / docker / nix / apt, updatable-in-place or not, with the correct external update command for image/package-managed installs), all profiles, every live gateway with its supervisor (systemd / launchd / manual via the fleet-wide _get_service_pids), running code_sha/code_version from the #91283 gateway_state.json stamps, and the restart mechanism each runtime will get. - hermes update --plan: prints the plan and exits; runs BEFORE the docker/nix refusal gates so image-managed installs get a useful 'not updatable in place + right command' report instead of a bare refusal. Read-only, safe on a live fleet. - Every real update run now records the pre-update plan in its receipt ('plan' key) and prints a one-line fleet summary, so post-mortems can compare what the update SAW against what it did. - Docs: updating.md (--plan section + receipts/fleet-check section), cli-commands.md (flag row + receipts behavior bullet). - 11 tests: two-profile fleet classification, docker not-in-place, dead-PID exclusion, PID-file fallback dedupe, all-probes-fail never-raises, JSON round-trip for the receipt, print output shapes, receipt integration.