{"record":{"id":"b25f950251679499","repo":"Hmbown/CodeWhale","slug":"could-not-clear-the-codewhale-owned-legacy-slot-secret-slot","errorCode":null,"errorMessage":"could not clear the Codewhale-owned legacy {slot} secret slot: {error}; config was not changed","messagePattern":"could not clear the Codewhale-owned legacy (.+?) secret slot: (.+?); config was not changed","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/cli/src/lib.rs","lineNumber":2705,"sourceCode":"    let prior_secret = secrets.get(slot).map_err(|error| {\n        anyhow!(\n            \"could not snapshot the Codewhale-owned legacy {slot} secret slot before clearing it: {error}; config was not changed\"\n        )\n    })?;\n\n    store.config.providers.antigravity = Default::default();\n    store\n        .config\n        .fallback_providers\n        .retain(|fallback| *fallback != provider);\n    if store.config.provider == provider {\n        store.config.provider = ProviderKind::default();\n        store.config.selected_provider_id = None;\n    }\n\n    if let Err(error) = secrets.delete(slot) {\n        store.config = original_config;\n        return Err(anyhow!(\n            \"could not clear the Codewhale-owned legacy {slot} secret slot: {error}; config was not changed\"\n        ));\n    }\n\n    if let Err(error) = store.save() {\n        store.config = original_config;\n        if let Some(previous) = prior_secret {\n            let current = secrets.get(slot).map_err(|rollback| {\n                anyhow!(\n                    \"{error}; additionally could not verify rollback of the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                )\n            })?;\n            match current {\n                None => secrets.set(slot, &previous).map_err(|rollback| {\n                    anyhow!(\n                        \"{error}; additionally failed to restore the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                    )\n                })?,","sourceCodeStart":2687,"sourceCodeEnd":2723,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/lib.rs#L2687-L2723","documentation":"After successfully snapshotting the legacy Antigravity secret, the migration deletes the slot via secrets.delete(slot). If the delete fails, the in-memory config changes are rolled back and this error is returned; the message includes the backend error and the reassurance that the config was not changed.","triggerScenarios":"`secrets.delete(slot)` returns Err for the Antigravity slot — e.g. the secret backend refuses deletion (permissions, read-only store) or the backend connection drops between get and delete.","commonSituations":"A read-only or policy-restricted keyring, SELinux/permission issues on the secret store, or keychain items locked against modification during automated migration runs.","solutions":["Check permissions on the secret store entry and grant the CLI delete rights","Unlock the keychain/secret service before running the migration","Manually delete the legacy slot via the OS keyring tool, then re-run the migration","Retry; transient backend failures leave config untouched so the migration is idempotent"],"exampleFix":null,"handlingStrategy":"retry","validationCode":"// check the slot is readable AND writable-adjacent (delete rights) before migrating\nif secrets.get(slot).is_err() { eprintln!(\"cannot read slot; do not attempt clear\"); }","typeGuard":null,"tryCatchPattern":"loop {\n    match clear_legacy_antigravity_config(store, secrets) {\n        Ok(()) => break,\n        Err(e) if e.to_string().contains(\"could not clear\") && attempts < 3 => attempts += 1,\n        Err(e) => return Err(e),\n    }\n}","preventionTips":["Grant the CLI delete permission on its keyring items","Avoid read-only or policy-locked secret stores for accounts running migrations","Because failures roll back config, retries are safe — retry after unlocking the backend"],"tags":["secrets","migration","keyring"],"backgroundTag":"file-write-permission-denied","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}