Open opens (creating if needed) the database at path, enables WAL and a
5 s busy timeout, and applies migrations[user_version:] in order. Pending
migrations and the user_version bump run in one transaction, so a failed
migration leaves the database as it was. Migrations are append-only.