_shared_context imported truststore._ssl_constants unconditionally on the
ssl_ca_cert branch. truststore is a >=3.14 dependency, so a 3.11-3.13
bridge install with a provider ssl_ca_cert crashed client construction
with ModuleNotFoundError. Only reach for truststore's saved original
class when ssl.SSLContext has actually been replaced; otherwise the
stdlib class is right there and the private import is never needed.
Also pin the test env: the "missing bundle falls back to True" contract
inherits the host's SSL_CERT_FILE (NixOS shells export it), which flips
the return to the shared platform context — a host dependency, not an
order dependency. Add the SSL_CERT_FILE contract as its own test.