aa5a960675
Review finding on PR #83194 (egilewski): Install-Venv committed the venv transaction as soon as the replacement had a working interpreter, deleting the parked previous venv. Install-Dependencies is a separate later stage (a separate process under the stage-per-process bootstrap) and every dependency tier or the baseline-import gate can still fail after that point - a failed update could still leave Hermes and the blocker probe unusable with no rollback source. Now: - Install-Venv records the parked backup in venv.pending-backup instead of deleting it, and excludes it from the venv.stale.* sweep. - Install-Dependencies wraps the dependency tiers + baseline-import gate in the transaction: Restore-VenvBackup on failure (parks the failed replacement as venv.failed.*, renames the previous venv back), and Complete-VenvTransaction only after the imports prove the replacement usable. - Source-contract regression tests for the boundary (tests/test_install_ps1_venv_transaction_boundary.py).