19717954d6
syncBoundGroupsForTenant()'s rename write updates name and ldapDn in one call, so a P2002 there can come from either @@unique([tenantId, name]) or @@unique([tenantId, ldapDn]). The catch previously reported every P2002 as a name collision unconditionally; it now inspects err.meta.target the same way importGroupsByDn() already does for its own create() call, so a non-name unique violation is no longer mislabelled and sent the admin down the wrong troubleshooting path.