fn rollback_committed(committed: &[CommittedStage])Expand description
Reverse-restore every committed stage from its .pre-import.bak.
Best-effort: each step swallows errors because a) we’re already in
a failure path and b) a failed individual rollback shouldn’t
abort the rest. Stale .bak files left by a catastrophic rollback
failure are picked up by the next import’s commit_stage (it
unlinks the stale .bak before parking).