# P23E R01 rollback / continuation Before `CORE_CHANGE_COMPLETE=true`, the target installer removes only the newly added `/opt/wg-access/backend/app/services/credential_service.py` and performs the same controlled backend recovery used by the apply path. The P23D production keyring is pre-existing state and is never deleted, regenerated, rotated, or replaced by P23E. After `CORE_CHANGE_COMPLETE=true`, do not automatically roll back for a late machine-close, publication, or archive failure. Such failures are continuation-only. No database rows or schema are changed by this STEP.