ea4cd375f8
The fake Internet (bubblewrap + slirp4netns + MITM proxy + upload-pack shim, 883 lines across dev-sandbox.sh, stage2-run.sh, proxy.py, ssh-shim.sh, openssl.cnf, install-update-e2e.sh) existed to isolate install.sh's network. The GIT_CONFIG_GLOBAL insteadOf redirect the windows driver introduced does the same job with a gitconfig file and works on any OS, so: * install-e2e-run.yml now runs tests/install/installer-script-e2e.sh directly on the bare runner - no sandbox deps, no userns sysctls - and takes a runner input; * the macos matrix calls the SAME workflow on macos-latest, deleting install-e2e-macos-run.yml: installer-script -> installer-script / hermes-update flip from grey to live, app-update pairs stay TODO inside the shared gate; * install.sh is no longer curl'd through a fake CA - each leg runs the copy from the ref a user of that version actually executed; * scripts/dev-sandbox.sh becomes the minimal isolation sandbox from ab6b9492f (separate HERMES_HOME / Electron userData / app name, same CLI surface: --persistent, --from, --delete), keeping its .hermes-sandbox dir name so gitignore and docs hold; * nix/sandbox.nix drops the bwrap/proxy closure and keeps only the Electron runtime LD_LIBRARY_PATH the desktop app needs. Verified: nix build .#sandbox + smoke run (isolated HERMES_HOME created, ephemeral cleanup), shellcheck/bash -n on both scripts, actionlint on all three workflows, and the new driver ran the full v0.20.2 -> HEAD hermes-update pass locally before this commit.