A popup already open when the stored profile became unreadable stayed on the last good profile until reopened. Every save already runs the check loadState() runs at open; a save refused by it now raises the recovery screen, stops the ten-second refresh, and passes the screen to showView(), which runs the leave cleanup of the screen it replaces and records it as the current view. From then on showView() shows nothing else, so a transaction wait or a later save cannot take the user off it or clear an export or a typed confirmation. Any other failed save keeps the "NOT SAVED" banner. The popup test harness now honours clearInterval(). Model: opus-5-5