{"record":{"id":"f07c55f7ee6361f9","repo":"Hmbown/CodeWhale","slug":"error-additionally-could-not-verify-rollback-of-the","errorCode":null,"errorMessage":"{error}; additionally could not verify rollback of the Codewhale-owned legacy {slot} secret slot: {rollback}","messagePattern":"(.+?); additionally could not verify rollback of the Codewhale-owned legacy (.+?) secret slot: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"crates/cli/src/lib.rs","lineNumber":2714,"sourceCode":"        .fallback_providers\n        .retain(|fallback| *fallback != provider);\n    if store.config.provider == provider {\n        store.config.provider = ProviderKind::default();\n        store.config.selected_provider_id = None;\n    }\n\n    if let Err(error) = secrets.delete(slot) {\n        store.config = original_config;\n        return Err(anyhow!(\n            \"could not clear the Codewhale-owned legacy {slot} secret slot: {error}; config was not changed\"\n        ));\n    }\n\n    if let Err(error) = store.save() {\n        store.config = original_config;\n        if let Some(previous) = prior_secret {\n            let current = secrets.get(slot).map_err(|rollback| {\n                anyhow!(\n                    \"{error}; additionally could not verify rollback of the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                )\n            })?;\n            match current {\n                None => secrets.set(slot, &previous).map_err(|rollback| {\n                    anyhow!(\n                        \"{error}; additionally failed to restore the Codewhale-owned legacy {slot} secret slot: {rollback}\"\n                    )\n                })?,\n                Some(current) if current == previous => {}\n                Some(_) => {\n                    return Err(anyhow!(\n                        \"{error}; additionally the Codewhale-owned legacy {slot} secret slot changed concurrently and was not overwritten during rollback\"\n                    ));\n                }\n            }\n        }\n        return Err(error);","sourceCodeStart":2696,"sourceCodeEnd":2732,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/lib.rs#L2696-L2732","documentation":"If store.save() fails after the legacy Antigravity slot was cleared, the code rolls back the in-memory config and tries to restore the previously snapshotted secret. When verifying the current secret (secrets.get) itself fails during that rollback, both the original save error and the rollback-verification error are combined into this compound message — a double failure during transactional cleanup.","triggerScenarios":"store.save() fails AND the subsequent secrets.get(slot) used to verify rollback state also returns Err — typically because the secret backend became unavailable mid-migration.","commonSituations":"Disk-full or permissions failure on the config save combined with a keyring service crash or lock, e.g. during system shutdown or an automated migration on a flaky headless host.","solutions":["Fix the secret backend first (restart/unlock the keyring) so rollback verification can proceed","Fix the underlying config save failure (disk space, file permissions on the config path)","Manually restore the snapshotted secret into the slot, then re-run the migration","Inspect both embedded errors ({error} and {rollback}) in the message to determine which subsystem to repair"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// preflight both subsystems before migration\nif secrets.get(slot).is_err() { eprintln!(\"secret backend unhealthy; abort migration\"); }\nif store.save_probe().is_err() { eprintln!(\"config path not writable; abort migration\"); }","typeGuard":null,"tryCatchPattern":"match result {\n    Err(e) if e.to_string().contains(\"additionally could not verify rollback\") => {\n        // both save and rollback-verify failed: restore from backup manually\n        eprintln!(\"double failure during legacy cleanup; restore secret from snapshot manually\");\n    }\n    other => other?,\n}","preventionTips":["Keep an external backup of the legacy secret slot before running the migration","Ensure both the config directory and the keyring are healthy before migrating","Run the migration on a stable system (not mid-shutdown, not on flaky headless hosts) so a save failure never meets a keyring failure"],"tags":["secrets","migration","rollback","config"],"backgroundTag":"internal-invariant-violation","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}