The FailedConfigRead save refusal always said "could not be read ... Try
again", including when the fallback came from a YAML parse error that no
retry fixes. The refusal now matches the cause: bad YAML gets the same
"has a formatting error ... `hermes config edit`" guidance as
require_readable_config_before_write; a PermissionError gets the
fix-permissions hint; only other read errors (EMFILE/EIO) say try again.
The parse-failure banner, the active-failure record, FailedConfigRead and the
write refusals are one topic; config.py had grown past 4,100 lines with this
PR. Pure move (no behaviour change): config.py drops to 3,999 lines, below
origin/main. Callers outside config.py now import from the new module.