f07f47fe7d
Salvage of #48637 (Fixes #48628). On a NixOS-style install the venv's site-packages lives in the read-only store, so ensure()'s uv -> pip -> ensurepip ladder spends ~15s bootstrapping ensurepip only to fail against a target it can never write. Fail fast with an actionable message pointing at the system package manager. Retargeted onto current main (the PR's base predates the durable-target subsystem by ~8.1K commits) with two corrections to the original: - Gate on _lazy_install_target() is None. The container deployment sets HERMES_MANAGED=true AND HERMES_LAZY_INSTALL_TARGET (a writable volume); the original guard would have blocked installs that path legitimately satisfies, breaking the NixOS-container mode. - Reason string starts with 'unsupported ' because refresh_active_features classifies FeatureUnavailable by that prefix; the original wording made 'hermes update' report a hard failure instead of a skip. Placed after _unsupported_feature_reason so a platform-specific reason (more actionable) wins, and so ensure() agrees with refresh_active_features, which pre-checks that same function.