98470ae33b
A brew Python upgrade (original report) or an interrupted venv rebuild (v0.19.0 report in the same thread) can leave certifi importable while its bundled cacert.pem is missing or a dangling symlink. Every TLS connection then fails — Feishu/Telegram/WeChat/DingTalk all down — with an opaque 'Could not find a suitable TLS CA certificate bundle' from deep inside httpx/requests. The existing repair infrastructure only probed `hasattr(certifi, 'contents')`, which PASSES in exactly this failure state, so neither the early venv self-heal nor `hermes update`'s import-probe repair ever classified certifi as broken. Extended, not replaced: - hermes_cli/_early_recovery.py: the in-process probe now also validates that certifi.where() exists and is a plausible bundle (>=1KiB), so the pre-import self-heal repairs it like any other wiped core package. - hermes_cli/main.py (_detect_broken_lazy_refresh_imports): the subprocess probe script used by `hermes update`'s venv repair applies the same bundle-file check inside the target venv. - hermes_cli/doctor.py: `hermes doctor` already failed the cert check; `hermes doctor --fix` now repairs it (pip force-reinstall certifi + module-cache invalidation + re-verify), covering brew/manual venvs where no update marker exists. Failures funnel into the manual-action list with the exact command. - agent/ssl_guard.py: the startup SSLConfigurationError hint now leads with `hermes doctor --fix` instead of only the raw pip command. Fixes #29866