aKeyThatLooksLikeAPathIsJustAKey

A key that looks like a path is a key, not a path: it round-trips, and it does not become some other key.

Three of the four in-tree backends put keys on a filesystem, so .. and a leading / are the two strings whose interpretation as structure rather than as a name would take a write outside the store's own storage area entirely. A caller deriving key names from anything it did not author is one string away from that.

What this cannot check, said plainly: that the bytes did not land outside the store's storage area. DurableStore exposes no path, no root and no listing, so from inside this suite a write that escaped and a write that was contained are indistinguishable — both read back correctly through the key that wrote them. What is checkable is the aliasing half, and it is the half a caller is actually hurt by: "../evil" must not resolve to the same entry as "evil", and "/etc/x" must not resolve to the same entry as "etc/x". Each backend's own tests are where containment is provable, because only they can look at the medium.