After the deleted-WAL guard fires, every SessionDB open raises
DeletedWalGenerationError, yet `hermes doctor` printed "✓ state.db exists"
and "0 process(es) holding the DB open" with rc 0 (#110054). It only counted
holders of the CURRENT state.db inode; the processes wedging the store are
the ones holding the RETIRED -wal/-shm inodes, and nothing in-product named
them — while the chat explainer sends users to exactly this doctor.
Ask iter_deleted_sqlite_sidecar_holders (the helper the guard itself uses)
first. When it names holders: warn with their PIDs, record a stop-them issue
line pinned to the active profile, and return before the health/stats/WAL
probes — a read-only connect on the new generation is another opener, and
--fix must not checkpoint under them. No kill path, no new module.