Return whether auto-update is enabled.
Editable installs are always disabled, before any layer is consulted.
Otherwise managed config decides first: [update].auto_update in
managed_config.toml outranks both layers below, and a managed file that
cannot be parsed forces False. Otherwise, opt out via the
DEEPAGENTS_CODE_AUTO_UPDATE=0 env var or [update].auto_update = false
in config.toml.
Defaults to True.
Unrecognized env values (neither truthy nor falsy) are ignored with a warning and fall through to the config read below.
If config.toml exists but cannot be parsed, returns False (fail-closed):
a corrupt file may hold an explicit opt-out, so it is not treated as the
permissive default. A genuinely absent config falls through to True.