Hmbown/CodeWhale · critical
; additionally failed to restore the Codewhale-owned legacy…
Error message
{error}; additionally failed to restore the Codewhale-owned legacy {slot} secret slot: {rollback} What it means
During a failed update or secret-slot migration in the CLI, the code attempts to roll back the Codewhale-owned legacy secret slot to its previous value. If the restore write via secrets.set(slot, &previous) itself fails, this error wraps both the original error and the rollback failure so no context is lost. It indicates the system is now in an unknown state for that secret slot.
Solutions
- Fix the underlying secret store access error reported in the {rollback} part (unlock the keychain, restore permissions).
- Re-run the migration/update command once the secret backend is reachable.
- Inspect the slot value manually with the CLI secret-show equivalent and restore the old value by hand if it was lost.
- Report the pair of errors ({error} and {rollback}) together — the original failure plus rollback failure are both needed to diagnose.
Defensive patterns
Strategy: try-catch
Validate before calling
// before migration: confirm the secret backend is writable
let probe = secrets.get(slot)?;
secrets.set(slot, probe.as_deref().unwrap_or(""))?; // dry-run write succeeds? Try / catch
match migration_result {
Err(original) => match secrets.set(slot, &previous) {
Ok(()) => return Err(original),
Err(rollback) => eprintln!("original: {original}; rollback failed: {rollback}"),
},
ok => ok,
} Prevention
- Unlock the keychain/secret service before running migrations.
- Take a manual backup of the slot value before any migration.
- Run migrations single-instance with a lock file.
- Test secret-store permissions after OS upgrades.
When it happens
Trigger: A migration/update step fails, rollback runs, and secrets.set(slot, &previous) returns Err — e.g. the secret store backend is unavailable, permission was revoked, or the store was locked between the read and the restore write.
Common situations: Keychain/secret-service daemon not running (Linux Secret Service, macOS Keychain locked), permission denied on the credential store after a system update, or a network-backed secrets provider timing out mid-migration.
Understand the failure class
Background: "failed to write file", "Could not save figure", "Error saving remote file" — file write failed: causes and fixes across languages and libraries — this error's family across 38 libraries.
Related errors
- ; additionally could not verify rollback of the…
- ; additionally could not verify secret-store rollback for
- ; additionally failed to restore prior secret-store state…
- ; additionally the Codewhale-owned legacy secret slot…
- bounded provider catalog cache exceeds its write limit
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/81509c80944ab4d7.
Report an issue: GitHub.
Appendix: source
Thrown at crates/cli/src/lib.rs:2720
if let Err(error) = secrets.delete(slot) {
store.config = original_config;
return Err(anyhow!(
"could not clear the Codewhale-owned legacy {slot} secret slot: {error}; config was not changed"
));
}
if let Err(error) = store.save() {
store.config = original_config;
if let Some(previous) = prior_secret {
let current = secrets.get(slot).map_err(|rollback| {
anyhow!(
"{error}; additionally could not verify rollback of the Codewhale-owned legacy {slot} secret slot: {rollback}"
)
})?;
match current {
None => secrets.set(slot, &previous).map_err(|rollback| {
anyhow!(
"{error}; additionally failed to restore the Codewhale-owned legacy {slot} secret slot: {rollback}"
)
})?,
Some(current) if current == previous => {}
Some(_) => {
return Err(anyhow!(
"{error}; additionally the Codewhale-owned legacy {slot} secret slot changed concurrently and was not overwritten during rollback"
));
}
}
}
return Err(error);
}
codewhale_config::scrub_plaintext_api_keys_from_config_backup(store.path())?;
codewhale_config::scrub_legacy_antigravity_from_config_backup(store.path())?;
println!(
"cleared Codewhale-owned legacy Antigravity config, consent, selection, fallback entries, and secret-store slot; Google and Antigravity sessions were not read, revoked, or changed. For Gemini, configure provider google and set GEMINI_API_KEY"View on GitHub (pinned to 73e0f67d83)