A popup already open when the stored profile became unreadable stayed on the last good profile until reopened. Every save already runs the check loadState() runs at open; a save refused by it now stops the ten-second refresh, runs the leave cleanup of the current screen, and raises the recovery screen. From then on showView() shows nothing else in that popup, so a transaction wait or a later save cannot take the user off it or clear an export or a typed confirmation. That is held in memory, never as the saved current view, so a popup opened after the record is erased elsewhere opens normally. Any other failed save keeps the "NOT SAVED" banner. The popup test harness now honours clearInterval(). Model: opus-5-5