1.1 KiB
1.1 KiB
Phase 2B-only rollback
Do not remove Phase 1 identity/workspace, Phase 2A packages, kernels, snapshots, production resources, or unrelated nftables objects.
- Stop
user@1200.service; confirm UID 1200 has no processes. This is the only user-manager stop in scope. - Stop
le-app-codex-netns.service. ItsExecStopremoves onlylecodex-hostand/run/netns/le-app-codexand deletes only the twole_app_codex*nftables tables. - Remove only the Phase 2B files enumerated in
MANIFEST.sha256and/etc/le-app-codex-runtime/OPERATOR-INPUTS-APPROVED, preserving the pre-existing/srv/le-app-codexskeleton. - Run
systemctl daemon-reloadandsystemctl reset-failed le-app-codex-netns.service. - Confirm there is no UID 1200 process, socket, namespace, veth, project nftables table, containment/resource drop-in, launcher, Docker user unit, daemon/client config, or Phase 2B test copy.
- Confirm lingering is still disabled and production/rootful Docker remains healthy and unchanged.
If a file existed before Phase 2B, stop: this rollback package intentionally has no overwrite/restore path because installation must have failed closed on pre-existence.