A popup already open when the stored profile became unreadable stayed on the last good profile until reopened. Every save already reads the stored record and runs the same check loadState() runs at open; the popup now sends a save refused by that check to the recovery screen and stops its ten-second refresh, while any other failed save keeps the "NOT SAVED" banner and the screen it is on. The recovery screen ignores a second request to show it, so a save that was in flight does not clear an export or a typed confirmation. The test harness records the refresh loop so a test can run one tick of it. Model: opus-5-5