PM-managed checkouts retire the in-tree `venv` once a generation is committed,
so `findPythonForRoot` returns null there and the desktop Update button refused
every hand-off with:
state.db pre-flight failed: Python not found. Update cancelled before
backend shutdown. Update the selected installation with its hermes update
command, then retry.
The pre-flight was the only remaining update-path consumer of the checkout-venv
resolution — the source check (`readSourceUpdate`) and the hand-off script
(`scripts/desktop-update/runtime.ps1`) already resolve the installation
launcher for managed checkouts.
`preflightStateDb` now accepts the launcher and runs the emergency snapshot
through it (`--run-module hermes_cli.backup_sqlite`, mirroring the update
check), keeping the legacy `python -I -S <script>` shape for pre-PM installs
and the update check's fail-closed ComSpec wrapping for a `.cmd` launcher. The
composition resolves the launcher off the same `pm` marker as `readSourceUpdate`
and surfaces a repair message before the backend stops when it is missing.
Test: apps/desktop/electron/updater/state-db-preflight.test.ts gains a managed
case that drives the launcher shape end-to-end (shim launcher -> snapshot
published); the legacy-path cases are unchanged.