Resolves and validates the one canonical PROJECT_ROOT for a service before any code is generated, and writes preflight_report.md. Use when a run starts, when a clone completes, or before the first file is written. Do NOT use for build-error triage or for editing application code.