pm.environment strips every ambient UV_* so a caller's uv settings cannot
select PM's project, interpreter or cache. That also dropped the knobs
mirrored and air-gapped networks depend on (UV_INDEX_URL/UV_DEFAULT_INDEX,
UV_NATIVE_TLS, UV_INSECURE_HOST, UV_HTTP_TIMEOUT, index credentials), and
uv never reads pip's configuration, so PIP_INDEX_URL / pip.conf mirrors
stalled against pypi.org (#88453, #94613, #95608 on main).
pm.index_config owns the allowlist and the pip→uv bridge with pip's own
precedence (PIP_INDEX_URL over pip.conf; any explicit uv index wins). Only
transport/index config crosses; the lockfile stays authoritative. A uv
timeout now raises InstallError naming those knobs instead of a raw
TimeoutExpired, so `hermes pm install` and the venv_sync status report
tell the user what to configure.