pm.shell.bash() returned shutil.which("bash") first on Windows. On most
machines that is C:\Windows\System32\bash.exe, the WSL launcher stub
(exits 1, "no installed distributions"), so a source install without the
staged git package lost its shell — the #116818 regression main fixed in
0abc3b04. The System32 guard survived only in local._windows_bash_candidates,
which had no callers after _find_bash collapsed onto pm.shell.
Move the ladder into pm.shell as a pure function (Program Files Git first,
then PATH minus the System32/WindowsApps stubs) so it is testable on any
host, and delete the dead copy in tools.environments.local.
The fallback required a prior PATH hit, so a normal Git for Windows
installation could not satisfy an empty-PATH terminal. Check the
existing conventional locations independently. Keep the staged tool
and usable PATH precedence unchanged.
The native test calls the actual local resolver and executes the
selected shell with an empty PATH and an unusable WindowsApps alias.
The focused shell gate passed. Other hosts retain their existing path.
Introduce the pm store: a unified, hash-verified package store that
replaces lazy_deps and the old installer's ad-hoc tool downloads.
Store tools are provisioned on PATH (ffmpeg, node/npm via pinned uv),
with a resumable 8-way downloader, verify() returning failure reasons,
and adopt() made EPERM-safe. chromium ships in the payload for every
target. The 3600-line install.sh is replaced by a staged bootstrapper
(heavy deps are pm's job after this); setup-hermes.sh, Dockerfile and
nix pin tables are rewired onto the store. Old install-script tests,
lazy_deps/managed_uv/build_info, and the ps1/bash installer test
batteries are removed with the machinery they tested.
Rebuilt from ethie/pm onto upstream/main (ac6c8028e0) after the
utf-8-sig sweep. 16 hot files (main also churned them) hand-merged:
platform adapters, main.py, electron/main.ts, tui_gateway/server.py,
cua_backend, installer-tests workflow, install.sh (full rewrite),
setup-hermes.sh, plugins doc.