c9fa2bba45
The installer exports UV_NO_CONFIG=1 at script start (sudo -u hygiene, #21269). That export also hides the project's own [tool.uv] policy — exclude-newer and its package exemptions — from uv. The resolver then runs under a different policy than uv.lock was resolved under, and --locked makes that mismatch fatal: error: The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. Every fresh install hit this and fell through to the non-hash-verified PyPI fallback tiers, defeating the point of Tier 0. Strip the variable for this one invocation only; it stays exported for every other uv call. Runtime code already strips UV_NO_CONFIG before its own locked syncs for the same reason (hermes_cli/managed_uv.py).