A read failure (partial-write race during user edit, SELinux denial, or any other IOException) used to fall through the runCatching and rewrite the file with only the global block, silently destroying every existing [pkg] override. Drop the runCatching so the failure bubbles to atomicWrite, where the M3 guard in updateTo logs and returns without applyToProps, leaving both file and props untouched.