c476ad35ae
The managed uv is installed with UV_UNMANAGED_INSTALL, which disables 'uv self update' by design — the swallowed failure left its embedded python-build-standalone catalog frozen at bootstrap age forever. python-build-standalone re-releases existing patch versions with fixed SQLite (3.11.15 was re-cut with 3.53.1), so a stale catalog resolves the same version number to the OLD vulnerable build, the probe rejects it, and the patch-retry loop cannot recover because the fixed build carries no newer number to try. Result: 'hermes update' printed a guaranteed-failure provisioning warning on every run (issue #72093). - When provisioning fails, re-bootstrap the Hermes-managed uv binary via the official installer (the only supported refresh for unmanaged installs) and retry provisioning once — only when the binary version actually changed, so no wasted download cycles. - Never touch a caller-supplied uv outside the managed path. - Soften the failure report from alarming ⚠ to informational ℹ and say why it is safe to wait: the WAL gate keeps databases out of WAL on vulnerable builds, and the next update retries. Verified: 56 unit tests green; sabotage run (retry block removed) fails the 3 new retry tests; live E2E replaced a fake managed uv via the real astral installer and the refreshed binary resolved the 3.11 catalog. Fixes #72093