Observed behavior: A target topology assertion failure immediately after successful target COMMIT is masked by an unconditional ROLLBACK, which throws because no transaction remains active. The journal records a confusing SQLite error rather than the original topology diagnosis.
Expected behavior: Preserve the topology failure as the primary error when a transaction has already committed, including when rollback itself fails.
Root cause: Candidate a17e8a0d3cb309db818e0bbc9a0cd5e325621994, src/worktree-reconciliation.ts:1279-1281, 1337-1341, 1403-1406 and 1718-1722: newly added post-COMMIT assertions remain inside try blocks whose catches run unconditional ROLLBACK before rethrowing the original error.
How to reproduce safely: With a private synthetic reconciliation fixture, inject parent topology drift after the underlying COMMIT succeeds and before its wrapper returns. Assert reconciliation still fails closed and journal reason preserves private directory topology is not trusted. Independent synthesis confirmed in an in-memory SQLite check that ROLLBACK after COMMIT raises cannot rollback - no transaction is active. No live HOME or daemon is necessary.
Impact: P3 diagnostic defect. The operation still refuses subsequent pattern/metadata/archival/map mutation; no security bypass or data loss was demonstrated. Preserve the primary error using guarded rollback or an AggregateError cause.
Environment:
- Agent: Astra owner source question and Opus 5 Medium validation
- Connector: repository static review and disposable in-memory SQLite check
- OS: Fedora Linux
Independent follow-up from #974 candidate round1 under Epic #968; outside frozen S3. Originating PR: #1071. This issue is not resolved by that PR.
Observed behavior: A target topology assertion failure immediately after successful target COMMIT is masked by an unconditional ROLLBACK, which throws because no transaction remains active. The journal records a confusing SQLite error rather than the original topology diagnosis.
Expected behavior: Preserve the topology failure as the primary error when a transaction has already committed, including when rollback itself fails.
Root cause: Candidate
a17e8a0d3cb309db818e0bbc9a0cd5e325621994,src/worktree-reconciliation.ts:1279-1281, 1337-1341, 1403-1406 and 1718-1722: newly added post-COMMIT assertions remain inside try blocks whose catches run unconditional ROLLBACK before rethrowing the original error.How to reproduce safely: With a private synthetic reconciliation fixture, inject parent topology drift after the underlying COMMIT succeeds and before its wrapper returns. Assert reconciliation still fails closed and journal reason preserves
private directory topology is not trusted. Independent synthesis confirmed in an in-memory SQLite check that ROLLBACK after COMMIT raisescannot rollback - no transaction is active. No live HOME or daemon is necessary.Impact: P3 diagnostic defect. The operation still refuses subsequent pattern/metadata/archival/map mutation; no security bypass or data loss was demonstrated. Preserve the primary error using guarded rollback or an AggregateError cause.
Environment:
Independent follow-up from #974 candidate round1 under Epic #968; outside frozen S3. Originating PR: #1071. This issue is not resolved by that PR.