e4d0e4c3d8
The Hermes-managed Node tree at %HERMES_HOME%\node is destructively rewritten while the desktop app's Node processes execute from it: the Node-26 heal did shutil.rmtree + move, the EBADENGINE repair ran npm install --global --prefix into the tree, and install.ps1's Test-Node did Remove-Item + Move-Item. Windows rejects those writes with PermissionError: [WinError 5] on npm.cmd. - _heal_managed_node_windows: stage the fully-downloaded tree in a sibling node.new-* dir, then rename-swap (live tree -> node.old-*, staged -> node). The live tree is never deleted before its replacement is ready, so an interrupted heal cannot gut it; a refused rename is the OS-level in-use signal and defers (returns None) instead of forcing the write. - heal_hermes_managed_node: an in-use deferral does not record the once-per-process attempt, so the heal retries once the tree is free. - managed_node_tree_in_use: cheap psutil pre-check (Windows only) that avoids pointless 30-50MB re-downloads in long-lived processes. - upgrade_managed_npm: defer the in-place npm self-upgrade while the tree is in use, with a notice. - install.ps1: Test-ManagedNodeInUse guard around Update-ManagedNpm and the Test-Node install branch, which now rename-swaps instead of delete-then-move. An in-use-but-outdated tree keeps serving the old runnable Node (old Node beats no Node), and every npm resolution re-evaluates the heal, so the upgrade applies automatically on the next update with the app closed.